Skip to content
Search
paperJuly 2026Unreviewed

Agent Security Needs Redefinition through a Holistic Framework

Vincent Siu, Jingxuan He, Kyle Montgomery, Zhun Wang, Chenguang Wang, Dawn Song

Abstract

Agent security is widely treated as a question about action content. Defenses ask whether an instruction looks malicious. Benchmarks ask whether an agent performs a harmful sounding action. \textbf{We argue that agent security is fundamentally a contextual problem, and that the current content based framing systematically misdefines it.} A command to ``delete user data'' might be a routine administrative request or a prompt injection attacking production systems, and the content alone cannot dis

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{siu2026agent,
  title = {{Agent Security Needs Redefinition through a Holistic Framework}},
  author = {Vincent Siu and Jingxuan He and Kyle Montgomery and Zhun Wang and Chenguang Wang and Dawn Song},
  year = {2026},
  month = jul,
  eprint = {2607.22024},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.22024}
}