Aletheia:编码智能体规则的权限最小化测试
Aletheia: Permission-Minimality Testing for Coding-Agent Rules
- Singapore Management University(新加坡管理大学)
- Nanjing University(南京大学)
- Adelaide University(阿德莱德大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
Aletheia通过权限最小化测试框架,将编码智能体规则请求的权限转换为类型化语言并合成沙箱配置,在独立限制下检测可疑请求,成功识别全部314个攻击输入,误报率仅3.75%。
AI中文摘要:
仓库指令文件引导编码智能体,但也使其面临提示注入攻击。恶意规则可能在智能体生成正确补丁的同时请求凭据访问或数据传输。我们提出Aletheia,一个用于权限最小化测试的框架。Aletheia将请求的权限转换为类型化语言,并合成可执行的沙箱配置。它在完全权限和每次移除一个权限的独立限制下运行未更改的规则和任务。在严格降低权限下通过独立功能测试提供了可豁免性证明,Aletheia结合任务上下文解释该证明以诊断可疑请求。我们形式化了合成过程以及将证明与强制限制联系起来条件。在一个共享重构任务上,Aletheia执行并检测到全部314个AIShellJack攻击输入,对五个良性模板无警报。在80条人工验证的良性GHAgentFiles规则中,它产生三个误报(3.75%)。
英文摘要:
Repository instruction files guide coding agents, but also expose them to prompt injection. Malicious rules can request credential access or data transfer while the agent produces a correct patch. We present Aletheia, a framework for permission-minimality testing. Aletheia translates requested authority into a typed language and synthesizes executable sandbox configurations. It runs the unchanged rule and task under full permissions and independent restrictions that remove one permission at a time. Passing independent functional tests under strictly reduced authority provides a dispensability witness, which Aletheia interprets against task context to diagnose suspicious requests. We formalize synthesis and the conditions connecting witnesses to enforced restrictions. On a shared refactoring task, Aletheia executes and detects all 314 AIShellJack attack inputs, with no alarms on five benign templates. Among 80 manually verified benign GHAgentFiles rules, it raises three false positives (3.75%).