Execution-Time Checks Limit Malicious Tool Calls by LLM Agents

PACE traces untrusted influence and verifies each proposed tool effect against authority derived from the authenticated user request.

Research Lab
Fengpeng Li · Qizhou Wang · Yuke Hu · Kemou Li · Jun Liu · Haiwei Wu · +2 more

PRADA Lab · King Abdullah University of Science and Technology · Imperfect Information Learning Team · RIKEN Center for Advanced Intelligence Project · State Key Laboratory of Internet of Things for Smart City

Research Digest··3 min read
Li and colleagues address prompt injection in tool-using agents, where poisoned webpages, tool descriptions, memories or reusable skills can induce consequential actions.

The authors first formalize why admission-time screening is insufficient.

Why this paper

From RIKEN Center for Advanced Intelligence Project and 7 others

In one line

Provenance-Aware Capability Enforcement (PACE) prevents tool misuse by verifying capability and provenance at the point of execution.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.