The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wu, Baoyuan, Liu, Qingshan, Bibi, Adel, King, Irwin, Lyu, Siwei
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914555196604416
author Wu, Baoyuan
Liu, Qingshan
Bibi, Adel
King, Irwin
Lyu, Siwei
author_facet Wu, Baoyuan
Liu, Qingshan
Bibi, Adel
King, Irwin
Lyu, Siwei
contents This position paper argues that the Authorization-Execution Gap (AEG) is a major safety and security problem in open-world agents. The AEG is the divergence between what a principal intends to authorize and what an open-world agent ultimately executes. Because such agents act autonomously across tools, persistent state, and multi-agent handoffs, even small instances of authorization divergence can cause harm that is difficult or impossible to undo. We argue that many observed agent failures can be traced to three structural sources of AEG: delegation-level incompleteness, channel-level corruption, and composition-level fragmentation. The same observed failure may arise from any of these sources. Without identifying the source, a defense targeting the symptom alone cannot address the underlying cause. Agent safety and security should therefore emphasize source-oriented diagnosis and defense. Because the structural sources of AEG arise dynamically during execution, this approach necessarily requires authorization integrity checks applied during execution, rather than relying solely on one-shot upfront filtering or post-hoc audit. For NeurIPS, the implication is that papers on open-world agents should report not only outcome-level metrics such as task success or attack resistance, but also process-level evidence showing where AEG was detected, constrained, and attributed to a structural source during execution.
format Preprint
id arxiv_https___arxiv_org_abs_2605_11003
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents
Wu, Baoyuan
Liu, Qingshan
Bibi, Adel
King, Irwin
Lyu, Siwei
Cryptography and Security
Artificial Intelligence
This position paper argues that the Authorization-Execution Gap (AEG) is a major safety and security problem in open-world agents. The AEG is the divergence between what a principal intends to authorize and what an open-world agent ultimately executes. Because such agents act autonomously across tools, persistent state, and multi-agent handoffs, even small instances of authorization divergence can cause harm that is difficult or impossible to undo. We argue that many observed agent failures can be traced to three structural sources of AEG: delegation-level incompleteness, channel-level corruption, and composition-level fragmentation. The same observed failure may arise from any of these sources. Without identifying the source, a defense targeting the symptom alone cannot address the underlying cause. Agent safety and security should therefore emphasize source-oriented diagnosis and defense. Because the structural sources of AEG arise dynamically during execution, this approach necessarily requires authorization integrity checks applied during execution, rather than relying solely on one-shot upfront filtering or post-hoc audit. For NeurIPS, the implication is that papers on open-world agents should report not only outcome-level metrics such as task success or attack resistance, but also process-level evidence showing where AEG was detected, constrained, and attributed to a structural source during execution.
title The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2605.11003