Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Cai, Yuandao, Tang, Wensheng, Wen, Cheng, Qin, Shengchao |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Push Your Agent: Measuring and Enforcing Quantitative Goal Persistence in Long-Horizon LLM Agents
by: Cai, Yuandao, et al.
Published: (2026)
by: Cai, Yuandao, et al.
Published: (2026)
LLM-IFT: LLM-Powered Information Flow Tracking for Secure Hardware
by: Mashnoor, Nowfel, et al.
Published: (2025)
by: Mashnoor, Nowfel, et al.
Published: (2025)
From Storage to Steering: Memory Control Flow Attacks on LLM Agents
by: Xu, Zhenlin, et al.
Published: (2026)
by: Xu, Zhenlin, et al.
Published: (2026)
Reframing LLM Agent Security as an Agent-Human Interaction Problem
by: Wang, Peiran, et al.
Published: (2026)
by: Wang, Peiran, et al.
Published: (2026)
PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
by: Shen, Xiangmin, et al.
Published: (2024)
by: Shen, Xiangmin, et al.
Published: (2024)
Argus: Reorchestrating Static Analysis via a Multi-Agent Ensemble for Full-Chain Security Vulnerability Detection
by: Liang, Zi, et al.
Published: (2026)
by: Liang, Zi, et al.
Published: (2026)
Securing AI Agents with Information-Flow Control
by: Costa, Manuel, et al.
Published: (2025)
by: Costa, Manuel, et al.
Published: (2025)
Automated Penetration Testing with LLM Agents and Classical Planning
by: Wang, Lingzhi, et al.
Published: (2025)
by: Wang, Lingzhi, et al.
Published: (2025)
To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems
by: He, Pengfei, et al.
Published: (2025)
by: He, Pengfei, et al.
Published: (2025)
AgentSys: Secure and Dynamic LLM Agents Through Explicit Hierarchical Memory Management
by: Wen, Ruoyao, et al.
Published: (2026)
by: Wen, Ruoyao, et al.
Published: (2026)
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
by: Liu, Hanzhi, et al.
Published: (2026)
by: Liu, Hanzhi, et al.
Published: (2026)
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
by: Ying, Zonghao, et al.
Published: (2026)
by: Ying, Zonghao, et al.
Published: (2026)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
by: Wang, Yihan, et al.
Published: (2025)
by: Wang, Yihan, et al.
Published: (2025)
FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems
by: Li, Fanxiao, et al.
Published: (2026)
by: Li, Fanxiao, et al.
Published: (2026)
ConCovUp: Effective Agent-Based Test Driver Generation for Concurrency Testing
by: Cai, Yuandao, et al.
Published: (2026)
by: Cai, Yuandao, et al.
Published: (2026)
GhostEI-Bench: Do Mobile Agents Resilience to Environmental Injection in Dynamic On-Device Environments?
by: Chen, Chiyu, et al.
Published: (2025)
by: Chen, Chiyu, et al.
Published: (2025)
An LLM Agent-based Framework for Whaling Countermeasures
by: Miyamoto, Daisuke, et al.
Published: (2026)
by: Miyamoto, Daisuke, et al.
Published: (2026)
Auto-Stega: An Agent-Driven System for Lifelong Strategy Evolution in LLM-Based Text Steganography
by: Zhou, Jiuan, et al.
Published: (2025)
by: Zhou, Jiuan, et al.
Published: (2025)
AgentDID: Trustless Identity Authentication for AI Agents
by: Xu, Minghui, et al.
Published: (2026)
by: Xu, Minghui, et al.
Published: (2026)
MemoPhishAgent: Memory-Augmented Multi-Modal LLM Agent for Phishing URL Detection
by: Chen, Xuan, et al.
Published: (2026)
by: Chen, Xuan, et al.
Published: (2026)
AgentGuard: An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
by: Luo, Jiaqi, et al.
Published: (2026)
by: Luo, Jiaqi, et al.
Published: (2026)
Stateful Agent Backdoor
by: Dai, Zhengchunmin, et al.
Published: (2026)
by: Dai, Zhengchunmin, et al.
Published: (2026)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
by: He, Yu, et al.
Published: (2026)
by: He, Yu, et al.
Published: (2026)
Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools
by: Mohammadi, Bardia, et al.
Published: (2026)
by: Mohammadi, Bardia, et al.
Published: (2026)
Unveiling Privacy Risks in LLM Agent Memory
by: Wang, Bo, et al.
Published: (2025)
by: Wang, Bo, et al.
Published: (2025)
Securing LLM Agents Need Intent-to-Execution Integrity
by: Qu, Wenjie, et al.
Published: (2026)
by: Qu, Wenjie, et al.
Published: (2026)
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026)
by: Hu, Yuepeng, et al.
Published: (2026)
Profiling for Pennies: Unveiling the Privacy Iceberg of LLM Agents
by: Chen, Jiahao, et al.
Published: (2026)
by: Chen, Jiahao, et al.
Published: (2026)
Imprompter: Tricking LLM Agents into Improper Tool Use
by: Fu, Xiaohan, et al.
Published: (2024)
by: Fu, Xiaohan, et al.
Published: (2024)
Prompt Injection Attack to Tool Selection in LLM Agents
by: Shi, Jiawen, et al.
Published: (2025)
by: Shi, Jiawen, et al.
Published: (2025)
A Biosecurity Agent for Lifecycle LLM Biosecurity Alignment
by: Meng, Meiyin, et al.
Published: (2025)
by: Meng, Meiyin, et al.
Published: (2025)
Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels
by: Du, Chenghao, et al.
Published: (2025)
by: Du, Chenghao, et al.
Published: (2025)
MindGuard: Intrinsic Decision Inspection for Securing LLM Agents Against Metadata Poisoning
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
by: Li, Hao, et al.
Published: (2026)
by: Li, Hao, et al.
Published: (2026)
CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM Agent
by: Ning, Liang-bo, et al.
Published: (2025)
by: Ning, Liang-bo, et al.
Published: (2025)
TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs
by: Zhang, Ting, et al.
Published: (2026)
by: Zhang, Ting, et al.
Published: (2026)
Targeted Bit-Flip Attacks on LLM-Based Agents
by: Wang, Jialai, et al.
Published: (2026)
by: Wang, Jialai, et al.
Published: (2026)
When Skills Lie: Hidden-Comment Injection in LLM Agents
by: Wang, Qianli, et al.
Published: (2026)
by: Wang, Qianli, et al.
Published: (2026)
PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability Repair
by: Kim, Wonyoung, et al.
Published: (2026)
by: Kim, Wonyoung, et al.
Published: (2026)
Investigating the Impact of Dark Patterns on LLM-Based Web Agents
by: Ersoy, Devin, et al.
Published: (2025)
by: Ersoy, Devin, et al.
Published: (2025)
Similar Items
-
Push Your Agent: Measuring and Enforcing Quantitative Goal Persistence in Long-Horizon LLM Agents
by: Cai, Yuandao, et al.
Published: (2026) -
LLM-IFT: LLM-Powered Information Flow Tracking for Secure Hardware
by: Mashnoor, Nowfel, et al.
Published: (2025) -
From Storage to Steering: Memory Control Flow Attacks on LLM Agents
by: Xu, Zhenlin, et al.
Published: (2026) -
Reframing LLM Agent Security as an Agent-Human Interaction Problem
by: Wang, Peiran, et al.
Published: (2026) -
PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
by: Shen, Xiangmin, et al.
Published: (2024)