April 2026Unreviewed
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
Zonghao Ying, Haozheng Wang, Jiangfan Liu, Quanchen Zou, Aishan Liu, Jian Yang, Yaodong Yang, Xianglong Liu
Abstract
Large Language Model (LLM) agents are increasingly used to automate complex workflows, but integrating untrusted external data with privileged execution exposes them to severe security risks, particularly direct and indirect prompt injection. Existing defenses face significant challenges in balancing security with utility, often encountering a trade-off where rigorous protection leads to over-defense, or where subtle indirect injections bypass detection. Drawing inspiration from operating system
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{ying2026agentvisor,
title = {{AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization}},
author = {Zonghao Ying and Haozheng Wang and Jiangfan Liu and Quanchen Zou and Aishan Liu and Jian Yang and Yaodong Yang and Xianglong Liu},
year = {2026},
month = apr,
eprint = {2604.24118},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.24118}
}