The authors adapted AgentDojo's existing tasks, tool schemas, reference solutions and goal-state checks to generate candidate tool calls that each benign task does not need.
Agent defenses leave privileges unseen by standard security benchmarks
Ajar directly tests which unnecessary tool calls defenses permit, adding least privilege as a third evaluation axis alongside attack success and task utility.
Big Tech
Reshabh K Sharma · Linxi Jiang · Shuo Chen · Zhiqiang Lin
University of Washington · The Ohio State University · Microsoft Research
Research Digest··2 min read
Sharma et al.
Why this paper
From Microsoft Research and 2 others · Released code
In one line
Ajar measures open privilege in agent defenses by testing whether they would allow tool calls that a task does not need.
What it released
Code
What we could check
- ✓Code link in the paper (github.com)
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ·No benchmark numbers found
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§