Skip to content
Search
paperJuly 2026Unreviewed

Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents

Arseny Kravchenko, Vadim Liventsev, Innokentii Konstantinov, Ildar Iskhakov, Matvey Kukuy

Abstract

Autonomous LLM agents processing mixed-confidentiality data face severe security risks from prompt injection attacks and reasoning errors. While dynamic Information Flow Control (IFC) provides structural security guarantees, traditional taint tracking permanently taints an agent's context upon reading unvetted data, severely restricting downstream utility. We present APPA (Agentic Permissions Policy Algebra), an IFC framework that resolves this usability bottleneck through engine-managed context

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{kravchenko2026agentic,
  title = {{Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents}},
  author = {Arseny Kravchenko and Vadim Liventsev and Innokentii Konstantinov and Ildar Iskhakov and Matvey Kukuy},
  year = {2026},
  month = jul,
  eprint = {2607.24625},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.24625}
}