ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
Fuente:
arXiv
Saved in:
| Main Authors: | Shin, Changhee, Kim, Bom, Lee, Seungsoo |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
The Fundamental Limits of Least-Privilege Learning
by: Stadler, Theresa, et al.
Published: (2024)
by: Stadler, Theresa, et al.
Published: (2024)
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
Ambusher: Exploring the Security of Distributed SDN Controllers Through Protocol State Fuzzing
by: Kim, Jinwoo, et al.
Published: (2025)
by: Kim, Jinwoo, et al.
Published: (2025)
No More, No Less: Least-Privilege Language Models
by: Rauba, Paulius, et al.
Published: (2026)
by: Rauba, Paulius, et al.
Published: (2026)
Do Coding Agents Understand Least-Privilege Authorization?
by: Yan, Zheng, et al.
Published: (2026)
by: Yan, Zheng, et al.
Published: (2026)
The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
by: Marin, Eduard, et al.
Published: (2025)
by: Marin, Eduard, et al.
Published: (2025)
TRUCE: TRUsted Compliance Enforcement Service for Secure Health Data Exchange
by: Kim, Dae-young, et al.
Published: (2025)
by: Kim, Dae-young, et al.
Published: (2025)
Dorami: Privilege Separating Security Monitor on RISC-V TEEs
by: Kuhne, Mark, et al.
Published: (2024)
by: Kuhne, Mark, et al.
Published: (2024)
MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents
by: Zhu, Jinhao, et al.
Published: (2025)
by: Zhu, Jinhao, et al.
Published: (2025)
Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement
by: Hansen, Malte, et al.
Published: (2024)
by: Hansen, Malte, et al.
Published: (2024)
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
by: Cornelissen, Eric, et al.
Published: (2025)
by: Cornelissen, Eric, et al.
Published: (2025)
Progent: Securing AI Agents with Privilege Control
by: Shi, Tianneng, et al.
Published: (2025)
by: Shi, Tianneng, et al.
Published: (2025)
UC-Secure Star DKG for Non-Exportable Key Shares with VSS-Free Enforcement
by: Sehrawat, Vipin Singh
Published: (2026)
by: Sehrawat, Vipin Singh
Published: (2026)
Automating Function-Level TARA for Automotive Full-Lifecycle Security
by: Yang, Yuqiao, et al.
Published: (2025)
by: Yang, Yuqiao, et al.
Published: (2025)
Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control Traffic
by: Seo, Minjae, et al.
Published: (2025)
by: Seo, Minjae, et al.
Published: (2025)
Acurast: Decentralized Serverless Cloud
by: Killer, Christian, et al.
Published: (2025)
by: Killer, Christian, et al.
Published: (2025)
The Data Enclave Advantage: A New Paradigm for Least-Privileged Data Access in a Zero-Trust World
by: Bistolfi, Nico, et al.
Published: (2025)
by: Bistolfi, Nico, et al.
Published: (2025)
Detection of Compromised Functions in a Serverless Cloud Environment
by: Lavi, Danielle, et al.
Published: (2024)
by: Lavi, Danielle, et al.
Published: (2024)
Lightweight, Secure and Stateful Serverless Computing with PSL
by: Thomas, Alexander, et al.
Published: (2024)
by: Thomas, Alexander, et al.
Published: (2024)
Detecting Privilege Escalation with Temporal Braid Groups
by: Parisel, Christophe
Published: (2026)
by: Parisel, Christophe
Published: (2026)
Making 'syscall' a Privilege not a Right
by: Yang, Fangfei, et al.
Published: (2024)
by: Yang, Fangfei, et al.
Published: (2024)
Demoting Security via Exploitation of Cache Demote Operation in Intel's Latest ISA Extension
by: Kim, Taehun, et al.
Published: (2025)
by: Kim, Taehun, et al.
Published: (2025)
SecTracer: A Framework for Uncovering the Root Causes of Network Intrusions via Security Provenance
by: Lee, Seunghyeon, et al.
Published: (2025)
by: Lee, Seunghyeon, et al.
Published: (2025)
Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
by: Kim, Juhee, et al.
Published: (2025)
by: Kim, Juhee, et al.
Published: (2025)
GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
by: Lin, Chris S., et al.
Published: (2026)
by: Lin, Chris S., et al.
Published: (2026)
Kumo: A Security-Focused Serverless Cloud Simulator
by: Shao, Wei, et al.
Published: (2026)
by: Shao, Wei, et al.
Published: (2026)
Security Risks in Tool-Enabled AI Agents: A Systematic Analysis of Privileged Execution Environments
by: Goel, Hardik
Published: (2026)
by: Goel, Hardik
Published: (2026)
Hybrid Privilege Escalation and Remote Code Execution Exploit Chains
by: Tulla, Miguel, et al.
Published: (2025)
by: Tulla, Miguel, et al.
Published: (2025)
Specification and Enforcement of Activity Dependency Policies using XACML
by: Mawla, Tanjila, et al.
Published: (2024)
by: Mawla, Tanjila, et al.
Published: (2024)
Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
by: Cui, Jian, et al.
Published: (2024)
by: Cui, Jian, et al.
Published: (2024)
Confidential Serverless Computing
by: Sabanic, Patrick, et al.
Published: (2025)
by: Sabanic, Patrick, et al.
Published: (2025)
A Comprehensive Review of Denial of Wallet Attacks in Serverless Architectures
by: Dorsett, Mark, et al.
Published: (2025)
by: Dorsett, Mark, et al.
Published: (2025)
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
by: Moazen, Mojtaba, et al.
Published: (2025)
by: Moazen, Mojtaba, et al.
Published: (2025)
Adaptive t Design Dummy-Gate Obfuscation for Cryogenic Scale Enforcement
by: Punch, Samuel, et al.
Published: (2025)
by: Punch, Samuel, et al.
Published: (2025)
Picachv: Formally Verified Data Use Policy Enforcement for Secure Data Analytics
by: Chen, Haobin Hiroki, et al.
Published: (2025)
by: Chen, Haobin Hiroki, et al.
Published: (2025)
Serverless AI Security: Attack Surface Analysis and Runtime Protection Mechanisms for FaaS-Based Machine Learning
by: Pathade, Chetan, et al.
Published: (2026)
by: Pathade, Chetan, et al.
Published: (2026)
The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck
by: Fan, Linfeng, et al.
Published: (2026)
by: Fan, Linfeng, et al.
Published: (2026)
SeSeMI: Secure Serverless Model Inference on Sensitive Data
by: Hu, Guoyu, et al.
Published: (2024)
by: Hu, Guoyu, et al.
Published: (2024)
Securing Automated Insulin Delivery Systems: A Review of Security Threats and Protective Strategies
by: Niu, Yuchen, et al.
Published: (2025)
by: Niu, Yuchen, et al.
Published: (2025)
Similar Items
-
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
by: Wu, Jiangrong, et al.
Published: (2026) -
The Fundamental Limits of Least-Privilege Learning
by: Stadler, Theresa, et al.
Published: (2024) -
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024) -
Ambusher: Exploring the Security of Distributed SDN Controllers Through Protocol State Fuzzing
by: Kim, Jinwoo, et al.
Published: (2025) -
No More, No Less: Least-Privilege Language Models
by: Rauba, Paulius, et al.
Published: (2026)