July 2026Unreviewed
Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents
Arseny Kravchenko, Vadim Liventsev, Innokentii Konstantinov, Ildar Iskhakov, Matvey Kukuy
Abstract
Autonomous LLM agents processing mixed-confidentiality data face severe security risks from prompt injection attacks and reasoning errors. While dynamic Information Flow Control (IFC) provides structural security guarantees, traditional taint tracking permanently taints an agent's context upon reading unvetted data, severely restricting downstream utility. We present APPA (Agentic Permissions Policy Algebra), an IFC framework that resolves this usability bottleneck through engine-managed context
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{kravchenko2026agentic,
title = {{Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents}},
author = {Arseny Kravchenko and Vadim Liventsev and Innokentii Konstantinov and Ildar Iskhakov and Matvey Kukuy},
year = {2026},
month = jul,
eprint = {2607.24625},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.24625}
}