arXiv AI

Exploring Large Language Models for Access Control Policy Synthesis and Summarization

arXiv:2510. 20692v2 Announce Type: replace-cross Abstract: Cloud computing is ubiquitous, with a growing number of services being hosted on the cloud every day.

arXiv AI
Sep 23

ActGov: Governing LLM Agent Actions via Policy-Constrained Validation

ActGov is a runtime enforcement framework that validates each action proposed by a large language model (LLM) agent before it interacts with external tools, ensuring that actions stay within task‑scoped authorization boundaries and comply with dynamically constructed policies. It builds policies from tool specifications, benign tasks, and failure traces, verifying updates via SMT‑based counterexample checking. In evaluations on AgentDojo and AgentDyn benchmarks, ActGov consistently reduces indirect prompt‑injection attack success while maintaining task utility, outperforming existing defenses.

By Kaiyuan Zhang, Yuke Peng, Ke Jiang, Yinqian Zhang
arXiv AI
Jun 19

Deontic Policies for Runtime Governance of Agentic AI Systems

arXiv:2606. 19464v1 Announce Type: new Abstract: Autonomous agentic AI systems driven by Large Language Models (LLMs) introduce a new class of security, privacy, and compliance challenges: an agent that can invoke tools, manipulate data, install software, and coordinate with peer agents across organizational boundaries must be constrained not just by authentication and access control, but by the full structure of enterprise governance.

By Anupam Joshi, Tim Finin, Karuna Pande Joshi, Lalana Kagal
arXiv AI
Aug 26

Quasar: A Programming Language Specialized for LLM Code Actions

Quasar is a new programming language designed to improve large language model (LLM) code actions by separating internal program logic from external tool calls. It allows developers to annotate external calls with effect information and modify internal execution to track these effects, enabling easier implementation of new features. The authors demonstrate Quasar’s utility by adding access control, autoparallelization, and conformal prediction for uncertainty quantification.

By Stephen Mell, Botong Zhang, David Mell, Shuo Li, Ramya Ramalingam, Nathan Yu, Stephan Zdancewic, Osbert Bastani