September 2026Unreviewed
From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents
Yu Zheng, Qizhi Zhang
Abstract
Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this content and controls a reusable signing credential, prompt injection can cross the judgment boundary and reach execution authority. We present KITA, a review-to-authorization architecture that keeps the user's personal secret signing key and every threshold signing-key share outside all LLM processes. Under threshold signature unforgeability and our
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{zheng2026from,
title = {{From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents}},
author = {Yu Zheng and Qizhi Zhang},
year = {2026},
month = sep,
eprint = {2609.05901},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.05901}
}