Agent defenses leave privileges unseen by standard security benchmarks

Ajar directly tests which unnecessary tool calls defenses permit, adding least privilege as a third evaluation axis alongside attack success and task utility.

Big Tech
Reshabh K Sharma · Linxi Jiang · Shuo Chen · Zhiqiang Lin

University of Washington · The Ohio State University · Microsoft Research

Research Digest··2 min read
Sharma et al.

The authors adapted AgentDojo's existing tasks, tool schemas, reference solutions and goal-state checks to generate candidate tool calls that each benign task does not need.

Why this paper

From Microsoft Research and 2 others · Released code

In one line

Ajar measures open privilege in agent defenses by testing whether they would allow tool calls that a task does not need.

What it released

Code

What we could check

  • ✓Code link in the paper (github.com)
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.