Skip to content
Search
paperApril 2026Unreviewed

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Zonghao Ying, Haozheng Wang, Jiangfan Liu, Quanchen Zou, Aishan Liu, Jian Yang, Yaodong Yang, Xianglong Liu

Abstract

Large Language Model (LLM) agents are increasingly used to automate complex workflows, but integrating untrusted external data with privileged execution exposes them to severe security risks, particularly direct and indirect prompt injection. Existing defenses face significant challenges in balancing security with utility, often encountering a trade-off where rigorous protection leads to over-defense, or where subtle indirect injections bypass detection. Drawing inspiration from operating system

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{ying2026agentvisor,
  title = {{AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization}},
  author = {Zonghao Ying and Haozheng Wang and Jiangfan Liu and Quanchen Zou and Aishan Liu and Jian Yang and Yaodong Yang and Xianglong Liu},
  year = {2026},
  month = apr,
  eprint = {2604.24118},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.24118}
}