Sapien represents permitted behavior as regular expressions over tool calls, allowing policies to specify ordering, alternatives and repetition.
Stateful policies block rogue agent actions while preserving task utility
Sapien constrains tool-call sequences using execution history, blocking substantially more benchmark attacks than static tool allowlists.
Big Tech
Corinn Tiffany · Wen Zhang · Eugene Bagdasarian · Lillian Tsai
Google · University of Massachusetts Amherst
Research Digest··2 min read
Thread:Agent Security & Attacks
Tiffany et al.
Why this paper
From Google and University of Massachusetts Amherst · Part of Agent Security & Attacks, now 46 papers
In one line
Sapien enforces stateful, task-specific tool-call policies that preserve near-unconstrained agent utility while ruling out most benchmark attacks under full hijacking.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ·No benchmark numbers found
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§