{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:IJVOVGIJ7FXKLMSWPS3VVYKTO7","short_pith_number":"pith:IJVOVGIJ","schema_version":"1.0","canonical_sha256":"426aea9909f96ea5b2567cb75ae15377d5daae7220141c9f3f341695c848d2e1","source":{"kind":"arxiv","id":"2502.08966","version":2},"attestation_state":"computed","paper":{"title":"RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben L. Titzer, Heather Miller, McKenna McCall, Peter Yong Zhong, Phillip B. Gibbons, Ruiqi Wang, Siyuan Chen","submitted_at":"2025-02-13T05:06:22Z","abstract_excerpt":"Tool-Based Agent Systems (TBAS) allow Language Models (LMs) to use external tools for tasks beyond their standalone capabilities, such as searching websites, booking flights, or making financial transactions. However, these tools greatly increase the risks of prompt injection attacks, where malicious content hijacks the LM agent to leak confidential data or trigger harmful actions. Existing defenses (OpenAI GPTs) require user confirmation before every tool call, placing onerous burdens on users. We introduce Robust TBAS (RTBAS), which automatically detects and executes tool calls that preserve"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.08966","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-02-13T05:06:22Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"0f0de2c73c932b0c2bf3da779e9b3f7f4fcc4b4729ab2a1ba9159c43e9821e4a","abstract_canon_sha256":"7bd6e960ce881d1534202d737aaac79680d36c562c0741a4c4c6b0c063f226b9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:14:09.156294Z","signature_b64":"L+t4OXP0zePm5XoQ90p9oV7T/tg0rRMlPn1zzU7/3C394VizoKYZgPC0QyggTGfdqrMEoB5akxy8PtDFBpHSBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"426aea9909f96ea5b2567cb75ae15377d5daae7220141c9f3f341695c848d2e1","last_reissued_at":"2026-07-05T10:14:09.155796Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:14:09.155796Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben L. Titzer, Heather Miller, McKenna McCall, Peter Yong Zhong, Phillip B. Gibbons, Ruiqi Wang, Siyuan Chen","submitted_at":"2025-02-13T05:06:22Z","abstract_excerpt":"Tool-Based Agent Systems (TBAS) allow Language Models (LMs) to use external tools for tasks beyond their standalone capabilities, such as searching websites, booking flights, or making financial transactions. However, these tools greatly increase the risks of prompt injection attacks, where malicious content hijacks the LM agent to leak confidential data or trigger harmful actions. Existing defenses (OpenAI GPTs) require user confirmation before every tool call, placing onerous burdens on users. We introduce Robust TBAS (RTBAS), which automatically detects and executes tool calls that preserve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.08966","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.08966/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.08966","created_at":"2026-07-05T10:14:09.155858+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.08966v2","created_at":"2026-07-05T10:14:09.155858+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.08966","created_at":"2026-07-05T10:14:09.155858+00:00"},{"alias_kind":"pith_short_12","alias_value":"IJVOVGIJ7FXK","created_at":"2026-07-05T10:14:09.155858+00:00"},{"alias_kind":"pith_short_16","alias_value":"IJVOVGIJ7FXKLMSW","created_at":"2026-07-05T10:14:09.155858+00:00"},{"alias_kind":"pith_short_8","alias_value":"IJVOVGIJ","created_at":"2026-07-05T10:14:09.155858+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":26,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08147","citing_title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","ref_index":102,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":133,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26479","citing_title":"Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2606.23277","citing_title":"GIF: Locally Sound Geometric Information Flow Control for LLMs","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12341","citing_title":"OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2607.02357","citing_title":"Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10525","citing_title":"Assessing Automated Prompt Injection Attacks in Agentic Environments","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09549","citing_title":"SecureClaw: Clawing Back Control of LLM Agents","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2606.28061","citing_title":"ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24309","citing_title":"Reframing LLM Agent Security as an Agent-Human Interaction Problem","ref_index":66,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26497","citing_title":"Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28914","citing_title":"AIRGuard: Guarding Agent Actions with Runtime Authority Control","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2605.29224","citing_title":"Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents","ref_index":37,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02483","citing_title":"Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10749","citing_title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","ref_index":255,"is_internal_anchor":false},{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":208,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20472","citing_title":"Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2602.03117","citing_title":"AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04035","citing_title":"Causality Laundering: Denial-Feedback Leakage in Tool-Calling LLM Agents","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03213","citing_title":"When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI","ref_index":56,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00314","citing_title":"Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19657","citing_title":"An AI Agent Execution Environment to Safeguard User Data","ref_index":84,"is_internal_anchor":false},{"citing_arxiv_id":"2604.15579","citing_title":"Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents","ref_index":78,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03213","citing_title":"When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI","ref_index":56,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23374","citing_title":"Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents","ref_index":42,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7","json":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7.json","graph_json":"https://pith.science/api/pith-number/IJVOVGIJ7FXKLMSWPS3VVYKTO7/graph.json","events_json":"https://pith.science/api/pith-number/IJVOVGIJ7FXKLMSWPS3VVYKTO7/events.json","paper":"https://pith.science/paper/IJVOVGIJ"},"agent_actions":{"view_html":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7","download_json":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7.json","view_paper":"https://pith.science/paper/IJVOVGIJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.08966&json=true","fetch_graph":"https://pith.science/api/pith-number/IJVOVGIJ7FXKLMSWPS3VVYKTO7/graph.json","fetch_events":"https://pith.science/api/pith-number/IJVOVGIJ7FXKLMSWPS3VVYKTO7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7/action/storage_attestation","attest_author":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7/action/author_attestation","sign_citation":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7/action/citation_signature","submit_replication":"https://pith.science/pith/IJVOVGIJ7FXKLMSWPS3VVYKTO7/action/replication_record"}},"created_at":"2026-07-05T10:14:09.155858+00:00","updated_at":"2026-07-05T10:14:09.155858+00:00"}