← Back to search
paper llmsec-2026-00072

The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck

Linfeng Fan, Ziwei Li, Yuan Tian, Yichen Wang, Rongsheng Li, Xiong Wang

2026-05

Abstract

Tool-using LLM agents must act on untrusted webpages, emails, files, and API outputs while issuing privileged tool calls. Existing defenses often mediate trust at the granularity of an entire tool invocation, forcing a brittle choice in mixed-trust workflows: allow external content to influence a call and risk hijacked destinations or commands, or quarantine the call and block benign retrieval-then-act behavior. The key observation behind this paper is that indirect prompt injection becomes dang

Cite This Resource

@article{llmsec202600072,
  title = {The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck},
  author = {Linfeng Fan and Ziwei Li and Yuan Tian and Yichen Wang and Rongsheng Li and Xiong Wang},
  year = {2026},
  url = {https://arxiv.org/abs/2605.11039},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.11039