TraceGrant: A Contract-Governed Security Framework for the Task-Effect Lifecycle of Networked LLM Agents

📅 2026-08-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出TraceGrant框架,通过合同治理网络化大语言模型代理的任务-效果生命周期,有效防止间接提示注入攻击,确保任务完成的正确性和安全性。
📝 Abstract
Networked large language model (LLM) agents retrieve information from email, cloud storage, calendars, transaction platforms, and Web services to complete multistep tasks that produce persistent external effects. The same content needed for legitimate execution may also contain indirect prompt injections that redirect tool use, alter sensitive arguments, or disrupt task completion. Existing defenses mainly constrain untrusted content or individual tool calls, leaving user intent, runtime evidence, realized effects, and task completion insufficiently connected. We present TraceGrant, a security framework that governs the task-effect lifecycle of networked LLM agents through an explicit Contract. Before execution, TraceGrant establishes a task-effect boundary from the trusted user request. During execution, admitted evidence can instantiate only authority already established by the Contract. After execution, task completion is verified against actual tool results. Across 949 AgentDojo and 400 Agent Security Bench attack cases under fixed benchmark settings, TraceGrant recorded no attack successes while retaining utility under attack rates of 77.32% and 83.00%, respectively. We further evaluate TraceGrant through white-box defense-aware attacks, Contract quality analysis, stage ablations, targeted stress tests, and runtime overhead measurements. The results show that TraceGrant provides a unified governance layer that connects trusted user intent, runtime evidence, concrete tool execution, and verified task completion.
Problem

Research questions and friction points this paper is trying to address.

Large Language Model
Networked Agents
Prompt Injection
Task Completion
Security Framework
Innovation

Methods, ideas, or system contributions that make the work stand out.

Contract-Governed Security
Task-Effect Lifecycle
Networked LLM Agents
Runtime Evidence
Verified Task Completion
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
B
Bohao Liao
School of Telecommunication Engineering, Xidian University, Xi’an, Shaanxi 710071, China
Jingchao Wang
Jingchao Wang
East China Normal University
AI
Qipeng Song
Qipeng Song
Xidian University
Stochastic geometryIoTM2MNFVnetwork security
J
Jin Cao
School of Cyber Engineering, Xidian University, Xi’an, Shaanxi 710071, China
J
Jieling Wang
School of Telecommunication Engineering, Xidian University, Xi’an, Shaanxi 710071, China
B
Boyu Deng
National Key Laboratory of Multi-domain Data Collaborative Processing and Control, Beijing 100141, China