May 2026Unreviewed
Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
Peiran Wang, Ying Li, Yuan Tian
Abstract
LLM-based agents are increasingly deployed in high-stakes scenarios such as email management, financial transactions, and code execution, where they interact with the external world through tool calling. During execution, these agents must read external data sources (emails, webpages, files) that attackers can control; through indirect prompt injection, attackers embed malicious instructions in this data to manipulate agents into performing unauthorized operations such as transferring funds to a
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{wang2026aligning,
title = {{Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents}},
author = {Peiran Wang and Ying Li and Yuan Tian},
year = {2026},
month = may,
eprint = {2605.26497},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.26497}
}