DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Hao, Liu, Xiaogeng, Chiu, Hung-Chun, Li, Dianqi, Zhang, Ning, Xiao, Chaowei
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915891317309440
author Li, Hao
Liu, Xiaogeng
Chiu, Hung-Chun
Li, Dianqi
Zhang, Ning
Xiao, Chaowei
author_facet Li, Hao
Liu, Xiaogeng
Chiu, Hung-Chun
Li, Dianqi
Zhang, Ning
Xiao, Chaowei
contents Large Language Models (LLMs) are increasingly central to agentic systems due to their strong reasoning and planning capabilities. By interacting with external environments through predefined tools, these agents can carry out complex user tasks. Nonetheless, this interaction also introduces the risk of prompt injection attacks, where malicious inputs from external sources can mislead the agent's behavior, potentially resulting in economic loss, privacy leakage, or system compromise. System-level defenses have recently shown promise by enforcing static or predefined policies, but they still face two key challenges: the ability to dynamically update security rules and the need for memory stream isolation. To address these challenges, we propose Dynamic Rule-based Isolation Framework for Trustworthy agentic systems (DRIFT), which enforces the dynamic security policy and injection isolation for securing LLM agents against prompt injection attacks. A Secure Planner first constructs a minimal function trajectory and a JSON-schema-style parameter checklist for each function node based on the user query. A Dynamic Validator then monitors deviations from the original plan, assessing whether changes comply with privilege limitations and the user's intent. Finally, an Injection Isolator detects and masks any instructions that may conflict with the user query from the memory stream to mitigate long-term risks. We empirically validate the effectiveness of DRIFT on the AgentDojo, ASB, and AgentDyn benchmark, demonstrating its strong security performance while maintaining high utility across diverse models, showcasing both its robustness and adaptability. The project website is available at https://safo-lab.github.io/DRIFT.
format Preprint
id arxiv_https___arxiv_org_abs_2506_12104
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
Li, Hao
Liu, Xiaogeng
Chiu, Hung-Chun
Li, Dianqi
Zhang, Ning
Xiao, Chaowei
Cryptography and Security
Artificial Intelligence
Large Language Models (LLMs) are increasingly central to agentic systems due to their strong reasoning and planning capabilities. By interacting with external environments through predefined tools, these agents can carry out complex user tasks. Nonetheless, this interaction also introduces the risk of prompt injection attacks, where malicious inputs from external sources can mislead the agent's behavior, potentially resulting in economic loss, privacy leakage, or system compromise. System-level defenses have recently shown promise by enforcing static or predefined policies, but they still face two key challenges: the ability to dynamically update security rules and the need for memory stream isolation. To address these challenges, we propose Dynamic Rule-based Isolation Framework for Trustworthy agentic systems (DRIFT), which enforces the dynamic security policy and injection isolation for securing LLM agents against prompt injection attacks. A Secure Planner first constructs a minimal function trajectory and a JSON-schema-style parameter checklist for each function node based on the user query. A Dynamic Validator then monitors deviations from the original plan, assessing whether changes comply with privilege limitations and the user's intent. Finally, an Injection Isolator detects and masks any instructions that may conflict with the user query from the memory stream to mitigate long-term risks. We empirically validate the effectiveness of DRIFT on the AgentDojo, ASB, and AgentDyn benchmark, demonstrating its strong security performance while maintaining high utility across diverse models, showcasing both its robustness and adaptability. The project website is available at https://safo-lab.github.io/DRIFT.
title DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.12104