arXiv Artificial Intelligence

Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents

Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents

Quick summary

arXiv:2610.03014v1 Announce Type: cross Abstract: Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities such as command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations as anchors, but operation identity alone is insufficient to determine security implications. We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) f

Key takeaways

  • arXiv:2610.03014v1 Announce Type: cross Abstract: Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities such as command execution, filesystem access, network communication, browser control, and external tools.
  • Existing analyses often use predefined sensitive operations as anchors, but operation identity alone is insufficient to determine security implications.
  • We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) f

Why it matters

“Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents” shows why AI risk cannot be reduced to answer accuracy. Access controls, logging, human approval and incident response need to be designed into the workflow from the start.

Kaynak sitede devamını oku: arXiv Artificial Intelligence ↗