Fetching the paper…
Reading the bibliography…
Large Language Models (LLMs) are combined with tools to create powerful LLM agents that provide a wide range of services.
The protection of information in computer systems
Jerome H Saltzer and Michael D Schroeder · 1975
Earlier work this paper cites.
Language-based information-flow security
Andrei Sabelfeld and Andrew C Myers · 2003
Earlier work this paper cites.
Least privilege and more [computer security]
F.B. Schneider · 2003
Earlier work this paper cites.
Non-control-data attacks are realistic threats
Shuo Chen, Jun Xu, Emre Can Sezer, Prachi Gauriar, and Ravishankar K Iyer · 2005
Earlier work this paper cites.
A methodology for empirical analysis of permission-based security models and its application to android
David Barrera, H. Güneş Kayacik, Paul C. van Oorschot, and Anil Somayaji · 2010
Earlier work this paper cites.
Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones
William Enck, Peter Gilbert, Seungyeop Han, Vasant Tendulkar, Byung-Gon Chun, Landon P Cox, Jaeyeon Jung, Patrick McDaniel, and Anmol N Sheth · 2010
Earlier work this paper cites.
Android permissions: user attention, comprehension, and behavior
Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, and David Wagner · 2012
Earlier work this paper cites.
Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps
Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick McDaniel · 2014
Earlier work this paper cites.
iris: Vetting private api abuse in ios applications
Zhui Deng, Brendan Saltaformaggio, Xiangyu Zhang, and Dongyan Xu · 2015
Earlier work this paper cites.
Android permissions remystified: A field study on contextual integrity
Primal Wijesekera, Arjun Baokar, Ashkan Hosseini, Serge Egelman, David Wagner, and Konstantin Beznosov · 2015
Earlier work this paper cites.
Data-oriented programming: On the expressiveness of non-control data attacks
Hong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua, Prateek Saxena, and Zhenkai Liang · 2016
Earlier work this paper cites.
Quantifying attention flow in transformers
Samira Abnar and Willem Zuidema · 2020
Earlier work this paper cites.
Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz · 2023
Earlier work this paper cites.
Llama guard: Llm-based input-output safeguard for human-ai conversations
Hakan Inan, Kartikeya Upasani, Jianfeng Chi, Rashi Rungta, Krithika Iyer, Yuning Mao, Michael Tontchev, Qing Hu, Brian Fuller, Davide Testuggine, et al · 2023
Earlier work this paper cites.
Agentbench: Evaluating llms as agents
Xiao Liu, Hao Yu, Hanchen Zhang, Yifan Xu, Xuanyu Lei, Hanyu Lai, Yu Gu, Hangliang Ding, Kaiwen Men, Kejuan Yang, Shudan Zhang, Xiang Deng, Aohan Zeng, Zhengxiao Du, Chenhui Zhang, Sheng Shen, Tianjun Zhang, Yu Su, Huan Sun, Minlie Huang, Yuxiao Dong, and Jie Tang · 2023
Earlier work this paper cites.
Mohammad Tahaei, Ruba Abu-Salma, and Awais Rashid · 2023
Earlier work this paper cites.
Jailbreak and guard aligned language models with only few in-context demonstrations
Zeming Wei, Yifei Wang, and Yisen Wang · 2023
Earlier work this paper cites.
React: Synergizing reasoning and acting in language models
Shunyu Yao, Jeffrey Zhao, Dian Yu, Nan Du, Izhak Shafran, Karthik Narasimhan, and Yuan Cao · 2023
Earlier work this paper cites.
Benchmarking and defending against indirect prompt injection attacks on large language models
Jingwei Yi, Yueqi Xie, Bin Zhu, Emre Kiciman, Guangzhong Sun, Xing Xie, and Fangzhao Wu · 2023
Earlier work this paper cites.
Universal and transferable adversarial attacks on aligned language models
Andy Zou, Zifan Wang, Nicholas Carlini, Milad Nasr, J Zico Kolter, and Matt Fredrikson · 2023
Earlier work this paper cites.
Air gap: Protecting privacy-conscious conversational agents
Eugene Bagdasaryan, Ren Yi, Sahra Ghalebikesabi, Peter Kairouz, Marco Gruteser, Sewoong Oh, Borja Balle, and Daniel Ramage · 2024
Cited alongside, same era.
Stealing part of a production language model
Nicholas Carlini, Daniel Paleka, Krishnamurthy Dj Dvijotham, Thomas Steinke, Jonathan Hayase, A Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, et al · 2024
Cited alongside, same era.
Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents
Edoardo Debenedetti, Jie Zhang, Mislav Balunovic, Luca Beurer-Kellner, Marc Fischer, and Florian Tramèr · 2024
Cited alongside, same era.
React: Synergizing reasoning and acting in language models
Sebastian Farquhar, Jannik Kossen, Lorenz Kuhn, and Yarin Gal · 2024
Cited alongside, same era.
Imprompter: Tricking llm agents into improper tool use
Xiaohan Fu, Shuheng Li, Zihan Wang, Yihao Liu, Rajesh K Gupta, Taylor Berg-Kirkpatrick, and Earlence Fernandes · 2024
Cited alongside, same era.
The rule of 2, 2025
Google · 2025
Closest in time.
Using oauth 2.0 to access google apis, 2025
Google · 2025
Closest in time.
The oauth 2.0 authorization framework, 2012
Dick Hardt · 2025
Closest in time.
Prebuilt components, 2024
LangGraph · 2025
Closest in time.
Sok: Software compartmentalization
Hugo Lefeuvre, Nathan Dautenhahn, David Chisnall, and Pierre Olivier · 2025
Closest in time.
Prompt guard, 2025
Meta · 2025
Closest in time.
Data execution prevention, 2023
Microsoft · 2025
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Models, 2024
Gemini · 2024
Cited alongside, same era.
Parrot: Efficient serving of llm-based applications with semantic variable
Chaofan Lin, Zhenhua Han, Chengruidong Zhang, Yuqing Yang, Fan Yang, Chen Chen, and Lili Qiu · 2024
Cited alongside, same era.
Large language model supply chain: A research agenda
Shenao Wang, Yanjie Zhao, Xinyi Hou, and Haoyu Wang · 2024
Cited alongside, same era.
System-level defense rect prompt injection attacks: An information flow control perspective
Fangzhou Wu, Ethan Cecchetti, and Chaowei Xiao · 2024
Cited alongside, same era.
Parden, can you repeat that? defending against jailbreaks via repetition
Ziyang Zhang, Qizhen Zhang, and Jakob Foerster · 2024
Cited alongside, same era.
Overview of shared storage, 2023
Android · 2025
Cited alongside, same era.
Models, 2024
Anthropic · 2025
Cited alongside, same era.
Microsoft copilot for microsoft 365 overview, 2024
Microsoft · 2025
Closest in time.
Model context protocol, 2025
Model Context Protocol · 2025
Closest in time.
Nvidia nemo guardrails for developers, 2025
NVIDIA · 2025
Closest in time.
Introducing chatgpt, 2022
OpenAI · 2025
Closest in time.
Chatgpt plugins, 2024
OpenAI · 2025
Closest in time.
Models, 2024
OpenAI · 2025
Closest in time.
Using projects in chatgpt, 2025
OpenAI · 2025
Closest in time.
An approach to technical agi safety and security, 2025
Rohin Shah, Alex Irpan, Alexander Matt Turner, Anna Wang, Arthur Conmy, David Lindner, Jonah Brown-Cohen, Lewis Ho, Neel Nanda, Raluca Ada Popa, Rishub Jain, Rory Greig, Samuel Albanie, Scott Emmons, Sebastian Farquhar, Sébastien Krier, Senthooran Rajamanoharan, Sophie Bridgers, Tobi Ijitoye, Tom Everitt, Victoria Krakovna, Vikrant Varma, Vladimir Mikulik, Zachary Kenton, Dave Orr, Shane Legg, Noah Goodman, Allan Dafoe, Four Flynn, and Anca Dragan · 2025
Closest in time.
Shortwave, 2025
Shortwave · 2025
Closest in time.
Program policies, 2025
Chrome Web Store · 2025
Closest in time.
Warp, 2025
Warp · 2025
Closest in time.
IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems
Yuhao Wu, Franziska Roesner, Tadayoshi Kohno, Ning Zhang, and Umar Iqbal · 2025
Closest in time.
Adaptive attacks break defenses against indirect prompt injection attacks on llm agents
Qiusi Zhan, Richard Fang, Henil Shalin Panchal, and Daniel Kang · 2025
Closest in time.