Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cai, Yifeng, Wang, Ziming, Deng, Zhaomeng, Yao, Mengyu, Liu, Junlin, Hu, Yutao, Zhang, Ziqi, Guo, Yao, Li, Ding
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911240463319040
author Cai, Yifeng
Wang, Ziming
Deng, Zhaomeng
Yao, Mengyu
Liu, Junlin
Hu, Yutao
Zhang, Ziqi
Guo, Yao
Li, Ding
author_facet Cai, Yifeng
Wang, Ziming
Deng, Zhaomeng
Yao, Mengyu
Liu, Junlin
Hu, Yutao
Zhang, Ziqi
Guo, Yao
Li, Ding
contents AI agents capable of GUI understanding and Model Context Protocol are increasingly deployed to automate mobile tasks. However, their reliance on over-privileged, static permissions creates a critical vulnerability: instruction injection. Malicious instructions, embedded in otherwise benign content like emails, can hijack the agent to perform unauthorized actions. We present AgentSentry, a lightweight runtime task-centric access control framework that enforces dynamic, task-scoped permissions. Instead of granting broad, persistent permissions, AgentSentry dynamically generates and enforces minimal, temporary policies aligned with the user's specific task (e.g., register for an app), revoking them upon completion. We demonstrate that AgentSentry successfully prevents an instruction injection attack, where an agent is tricked into forwarding private emails, while allowing the legitimate task to complete. Our approach highlights the urgent need for intent-aligned security models to safely govern the next generation of autonomous agents.
format Preprint
id arxiv_https___arxiv_org_abs_2510_26212
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control
Cai, Yifeng
Wang, Ziming
Deng, Zhaomeng
Yao, Mengyu
Liu, Junlin
Hu, Yutao
Zhang, Ziqi
Guo, Yao
Li, Ding
Cryptography and Security
AI agents capable of GUI understanding and Model Context Protocol are increasingly deployed to automate mobile tasks. However, their reliance on over-privileged, static permissions creates a critical vulnerability: instruction injection. Malicious instructions, embedded in otherwise benign content like emails, can hijack the agent to perform unauthorized actions. We present AgentSentry, a lightweight runtime task-centric access control framework that enforces dynamic, task-scoped permissions. Instead of granting broad, persistent permissions, AgentSentry dynamically generates and enforces minimal, temporary policies aligned with the user's specific task (e.g., register for an app), revoking them upon completion. We demonstrate that AgentSentry successfully prevents an instruction injection attack, where an agent is tricked into forwarding private emails, while allowing the legitimate task to complete. Our approach highlights the urgent need for intent-aligned security models to safely govern the next generation of autonomous agents.
title Who Grants the Agent Power? Defending Against Instruction Injection via Task-Centric Access Control
topic Cryptography and Security
url https://arxiv.org/abs/2510.26212