While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks. This paper proposes an open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions.
The paper introduces LLMLeak, a covert exfiltration technique that exploits Large‑Language‑Model (LLM) web‑fetching capabilities to transmit confidential data. By embedding a secret into a URL and presenting the corresponding website as part of a legitimate task, the malicious client tricks the LLM into fetching the URL, thereby leaking the secret to an attacker‑controlled server. Experiments on eleven open‑parameter models show a 79.7% success rate, and a real‑world case study confirms the attack’s practicality.
By Alessandro Pegoraro, Daryan Merx, Phillip Rieger, Ahmad-Reza Sadeghi
arXiv:2606. 14027v1 Announce Type: cross Abstract: Agentic browsers integrate autonomous AI agents into web browsers, enabling users to accomplish web tasks through natural-language instructions.
By Xilong Wang, Xiaoxing Chen, Patrick Li, Dawn Song, Neil Gong
arXiv:2607. 05277v1 Announce Type: cross Abstract: Defenses that provide security guarantees against prompt injection attacks rely on strict isolation between trusted instructions and untrusted data.
By Kristina Nikoli\'c, Egor Zverev, Javier Rando, Matthew Jagielski, Edoardo Debenedetti, Florian Tram\`er
arXiv:2505. 23847v4 Announce Type: replace-cross Abstract: Large language models (LLMs) are rapidly evolving into autonomous agents that cooperate across organizational boundaries, enabling joint disaster response, supply-chain optimization, and other tasks that demand decentralized expertise without surrendering data ownership.
By Ronny Ko, Jiseong Jeong, Shuyuan Zheng, Chuan Xiao, Tae-Wan Kim, Makoto Onizuka, Won-Yong Shin
arXiv:2505. 23847v5 Announce Type: replace-cross Abstract: Large language models (LLMs) are rapidly evolving into autonomous agents that cooperate across organizational boundaries, enabling joint disaster response, supply-chain optimization, and other tasks that demand decentralized expertise without surrendering data ownership.
By Ronny Ko, Jiseong Jeong, Shuyuan Zheng, Chuan Xiao, Tae-Wan Kim, Makoto Onizuka, Won-Yong Shin