arXiv AI

Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models

arXiv:2607. 08282v1 Announce Type: cross Abstract: While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks.

arXiv Machine Learning
1d ago

The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching

The paper introduces LLMLeak, a covert exfiltration technique that exploits Large‑Language‑Model (LLM) web‑fetching capabilities to transmit confidential data. By embedding a secret into a URL and presenting the corresponding website as part of a legitimate task, the malicious client tricks the LLM into fetching the URL, thereby leaking the secret to an attacker‑controlled server. Experiments on eleven open‑parameter models show a 79.7% success rate, and a real‑world case study confirms the attack’s practicality.

By Alessandro Pegoraro, Daryan Merx, Phillip Rieger, Ahmad-Reza Sadeghi
arXiv AI
Jun 29

Seven Security Challenges That Must be Solved in Cross-domain Multi-agent LLM Systems

arXiv:2505. 23847v4 Announce Type: replace-cross Abstract: Large language models (LLMs) are rapidly evolving into autonomous agents that cooperate across organizational boundaries, enabling joint disaster response, supply-chain optimization, and other tasks that demand decentralized expertise without surrendering data ownership.

By Ronny Ko, Jiseong Jeong, Shuyuan Zheng, Chuan Xiao, Tae-Wan Kim, Makoto Onizuka, Won-Yong Shin
arXiv AI
Jul 7

Seven Security Challenges in Cross-domain Multi-agent LLM Systems

arXiv:2505. 23847v5 Announce Type: replace-cross Abstract: Large language models (LLMs) are rapidly evolving into autonomous agents that cooperate across organizational boundaries, enabling joint disaster response, supply-chain optimization, and other tasks that demand decentralized expertise without surrendering data ownership.

By Ronny Ko, Jiseong Jeong, Shuyuan Zheng, Chuan Xiao, Tae-Wan Kim, Makoto Onizuka, Won-Yong Shin
arXiv AI
Jun 16

MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks

arXiv:2602. 09222v2 Announce Type: replace-cross Abstract: Large language model (LLM) based web agents are increasingly deployed to automate complex online tasks by directly interacting with web sites and performing actions on users' behalf.

By Georgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer, William Robertson, Cristina Nita-Rotaru, Alina Oprea
arXiv AI
Aug 26

WebMCP-Phalanx: Enforcing and Characterizing Trust Boundaries for Browser-Integrated LLM Agents

WebMCP-Phalanx introduces a dual‑layer runtime for browser‑integrated LLM agents that enforces trust boundaries on web‑exposed tools. The first layer uses cryptographic capability credentials to bind tools to their registering principals and propagate provenance labels, while the second layer separates semantic inspection from privileged tool use via a Quarantine Agent that validates tool metadata before a Privileged Agent can execute it. Empirical results show the approach eliminates revocation and overwrite attacks, blocks most prompt‑injection attempts, and maintains task utility comparable to a no‑attack baseline.

By Lin-Fa Lee, YI-YU Chang, Kuo-Hui Yeh