Skip to content
Search
paperMay 2026Unreviewed

Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents

Peiran Wang, Ying Li, Yuan Tian

Abstract

LLM-based agents are increasingly deployed in high-stakes scenarios such as email management, financial transactions, and code execution, where they interact with the external world through tool calling. During execution, these agents must read external data sources (emails, webpages, files) that attackers can control; through indirect prompt injection, attackers embed malicious instructions in this data to manipulate agents into performing unauthorized operations such as transferring funds to a

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{wang2026aligning,
  title = {{Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents}},
  author = {Peiran Wang and Ying Li and Yuan Tian},
  year = {2026},
  month = may,
  eprint = {2605.26497},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.26497}
}