Stateful policies block rogue agent actions while preserving task utility

Sapien constrains tool-call sequences using execution history, blocking substantially more benchmark attacks than static tool allowlists.

Big Tech
Corinn Tiffany · Wen Zhang · Eugene Bagdasarian · Lillian Tsai

Google · University of Massachusetts Amherst

Research Digest··2 min read
Tiffany et al.

Sapien represents permitted behavior as regular expressions over tool calls, allowing policies to specify ordering, alternatives and repetition.

Why this paper

From Google and University of Massachusetts Amherst · Part of Agent Security & Attacks, now 46 papers

In one line

Sapien enforces stateful, task-specific tool-call policies that preserve near-unconstrained agent utility while ruling out most benchmark attacks under full hijacking.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.