Do Coding Agents Understand Least-Privilege Authorization?
Fuente:
arXiv
Saved in:
| Main Authors: | Yan, Zheng, Weng, Jingxiang, Chen, Charles, Peng, Dengyun, Qin, Ethan, Guan, Jiannan, Liu, Jinhao, Yu, Qiming, Yuan, Yixin, Meng, Fanqing, Che, Carl, Hu, Mengkang |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents
by: Zhu, Jinhao, et al.
Published: (2025)
by: Zhu, Jinhao, et al.
Published: (2025)
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
The Fundamental Limits of Least-Privilege Learning
by: Stadler, Theresa, et al.
Published: (2024)
by: Stadler, Theresa, et al.
Published: (2024)
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
by: Shin, Changhee, et al.
Published: (2026)
by: Shin, Changhee, et al.
Published: (2026)
No More, No Less: Least-Privilege Language Models
by: Rauba, Paulius, et al.
Published: (2026)
by: Rauba, Paulius, et al.
Published: (2026)
Making 'syscall' a Privilege not a Right
by: Yang, Fangfei, et al.
Published: (2024)
by: Yang, Fangfei, et al.
Published: (2024)
Hybrid Privilege Escalation and Remote Code Execution Exploit Chains
by: Tulla, Miguel, et al.
Published: (2025)
by: Tulla, Miguel, et al.
Published: (2025)
Progent: Securing AI Agents with Privilege Control
by: Shi, Tianneng, et al.
Published: (2025)
by: Shi, Tianneng, et al.
Published: (2025)
Evaluating Privilege Usage of Agents with Real-World Tools
by: Zhang, Quan, et al.
Published: (2026)
by: Zhang, Quan, et al.
Published: (2026)
The Data Enclave Advantage: A New Paradigm for Least-Privileged Data Access in a Zero-Trust World
by: Bistolfi, Nico, et al.
Published: (2025)
by: Bistolfi, Nico, et al.
Published: (2025)
Taming Various Privilege Escalation in LLM-Based Agent Systems: A Mandatory Access Control Framework
by: Ji, Zimo, et al.
Published: (2026)
by: Ji, Zimo, et al.
Published: (2026)
Detecting Privilege Escalation with Temporal Braid Groups
by: Parisel, Christophe
Published: (2026)
by: Parisel, Christophe
Published: (2026)
Code Agent can be an End-to-end System Hacker: Benchmarking Real-world Threats of Computer-use Agent
by: Luo, Weidi, et al.
Published: (2025)
by: Luo, Weidi, et al.
Published: (2025)
BashArena: A Control Setting for Highly Privileged AI Agents
by: Kaufman, Adam, et al.
Published: (2025)
by: Kaufman, Adam, et al.
Published: (2025)
Enhancing Linux Privilege Escalation Attack Capabilities of Local LLM Agents
by: Probst, Benjamin, et al.
Published: (2026)
by: Probst, Benjamin, et al.
Published: (2026)
FP-Agent: Fingerprinting AI Browsing Agents
by: Wang, Ethan, et al.
Published: (2026)
by: Wang, Ethan, et al.
Published: (2026)
GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
by: Lin, Chris S., et al.
Published: (2026)
by: Lin, Chris S., et al.
Published: (2026)
AIRGuard: Guarding Agent Actions with Runtime Authority Control
by: Qin, Suliu, et al.
Published: (2026)
by: Qin, Suliu, et al.
Published: (2026)
The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
by: Wallace, Eric, et al.
Published: (2024)
by: Wallace, Eric, et al.
Published: (2024)
Dorami: Privilege Separating Security Monitor on RISC-V TEEs
by: Kuhne, Mark, et al.
Published: (2024)
by: Kuhne, Mark, et al.
Published: (2024)
Post-Training Local LLM Agents for Linux Privilege Escalation with Verifiable Rewards
by: Normann, Philipp, et al.
Published: (2026)
by: Normann, Philipp, et al.
Published: (2026)
SoK: Trust-Authorization Mismatch in LLM Agent Interactions
by: Shi, Guanquan, et al.
Published: (2025)
by: Shi, Guanquan, et al.
Published: (2025)
Dynamic Authorization for Knowledge-Base Agents in 6G
by: Abdelrazek, Loay, et al.
Published: (2026)
by: Abdelrazek, Loay, et al.
Published: (2026)
Agent Privilege Separation in OpenClaw: A Structural Defense Against Prompt Injection
by: Cheng, Darren, et al.
Published: (2026)
by: Cheng, Darren, et al.
Published: (2026)
Authorization of Knowledge-base Agents in an Intent-based Management Function
by: Abdelrazek, Loay, et al.
Published: (2025)
by: Abdelrazek, Loay, et al.
Published: (2025)
PINA: Prompt Injection Attack against Navigation Agents
by: Liu, Jiani, et al.
Published: (2026)
by: Liu, Jiani, et al.
Published: (2026)
Security Risks in Tool-Enabled AI Agents: A Systematic Analysis of Privileged Execution Environments
by: Goel, Hardik
Published: (2026)
by: Goel, Hardik
Published: (2026)
Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
by: Kim, Juhee, et al.
Published: (2025)
by: Kim, Juhee, et al.
Published: (2025)
PenTest2.0: Towards Autonomous Privilege Escalation Using GenAI
by: Al-Sinani, Haitham S., et al.
Published: (2025)
by: Al-Sinani, Haitham S., et al.
Published: (2025)
Scalable Privilege Analysis for Multi-Cloud Big Data Platforms: A Hypergraph Approach
by: Sitharaman, Sai, et al.
Published: (2025)
by: Sitharaman, Sai, et al.
Published: (2025)
TAC: Hybrid IAM Privilege Escalation Detection
by: Hu, Yang, et al.
Published: (2023)
by: Hu, Yang, et al.
Published: (2023)
DualTAP: A Dual-Task Adversarial Protector for Mobile MLLM Agents
by: Zhang, Fuyao, et al.
Published: (2025)
by: Zhang, Fuyao, et al.
Published: (2025)
LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks
by: Happe, Andreas, et al.
Published: (2023)
by: Happe, Andreas, et al.
Published: (2023)
Preventing Prompt Injection with Type-Directed Privilege Separation
by: Jacob, Dennis, et al.
Published: (2025)
by: Jacob, Dennis, et al.
Published: (2025)
Auditing MCP Servers for Over-Privileged Tool Capabilities
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
At Least Factor-of-Two Optimization for RWLE-Based Homomorphic Encryption
by: Ly, Jonathan
Published: (2024)
by: Ly, Jonathan
Published: (2024)
Least Squares Estimation For Hierarchical Data
by: Cumings-Menon, Ryan, et al.
Published: (2024)
by: Cumings-Menon, Ryan, et al.
Published: (2024)
Takedown: How It's Done in Modern Coding Agent Exploits
by: Lee, Eunkyu, et al.
Published: (2025)
by: Lee, Eunkyu, et al.
Published: (2025)
Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents
by: Cai, Yuandao, et al.
Published: (2026)
by: Cai, Yuandao, et al.
Published: (2026)
Similar Items
-
MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents
by: Zhu, Jinhao, et al.
Published: (2025) -
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
by: Wu, Jiangrong, et al.
Published: (2026) -
The Fundamental Limits of Least-Privilege Learning
by: Stadler, Theresa, et al.
Published: (2024) -
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024) -
ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
by: Shin, Changhee, et al.
Published: (2026)