{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:WXQSAGIJAGWKX4XO5GUIWLAEFI","short_pith_number":"pith:WXQSAGIJ","schema_version":"1.0","canonical_sha256":"b5e120190901acabf2eee9a88b2c042a2606ce353f2450870a6158ab10c6d7e4","source":{"kind":"arxiv","id":"2505.24019","version":1},"attestation_state":"computed","paper":{"title":"LLM Agents Should Employ Security Principles","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Elisa Bertino, Kaiyuan Zhang, Ninghui Li, Pin-Yu Chen, Xiangyu Zhang, Zian Su","submitted_at":"2025-05-29T21:39:08Z","abstract_excerpt":"Large Language Model (LLM) agents show considerable promise for automating complex tasks using contextual reasoning; however, interactions involving multiple agents and the system's susceptibility to prompt injection and other forms of context manipulation introduce new vulnerabilities related to privacy leakage and system exploitation. This position paper argues that the well-established design principles in information security, which are commonly referred to as security principles, should be employed when deploying LLM agents at scale. Design principles such as defense-in-depth, least privi"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.24019","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-05-29T21:39:08Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"457252fa3fa8e31ee251e066883cc42e7df39c278a19d21adab0d8cfa24e5fc7","abstract_canon_sha256":"343a73bbb99496a85563795b534250f311cfc2ab44572e99ddc4104e9154c861"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:12:40.234943Z","signature_b64":"zv7jt/lrSTuElSJyauElKHL9WNN4erqjxB3d/DeCDsGVc8VjqxxftSyu6iUn3GmWb6zctQ4Ps73iGzGVtEcFDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b5e120190901acabf2eee9a88b2c042a2606ce353f2450870a6158ab10c6d7e4","last_reissued_at":"2026-07-05T11:12:40.234392Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:12:40.234392Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LLM Agents Should Employ Security Principles","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Elisa Bertino, Kaiyuan Zhang, Ninghui Li, Pin-Yu Chen, Xiangyu Zhang, Zian Su","submitted_at":"2025-05-29T21:39:08Z","abstract_excerpt":"Large Language Model (LLM) agents show considerable promise for automating complex tasks using contextual reasoning; however, interactions involving multiple agents and the system's susceptibility to prompt injection and other forms of context manipulation introduce new vulnerabilities related to privacy leakage and system exploitation. This position paper argues that the well-established design principles in information security, which are commonly referred to as security principles, should be employed when deploying LLM agents at scale. Design principles such as defense-in-depth, least privi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.24019","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.24019/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.24019","created_at":"2026-07-05T11:12:40.234455+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.24019v1","created_at":"2026-07-05T11:12:40.234455+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.24019","created_at":"2026-07-05T11:12:40.234455+00:00"},{"alias_kind":"pith_short_12","alias_value":"WXQSAGIJAGWK","created_at":"2026-07-05T11:12:40.234455+00:00"},{"alias_kind":"pith_short_16","alias_value":"WXQSAGIJAGWKX4XO","created_at":"2026-07-05T11:12:40.234455+00:00"},{"alias_kind":"pith_short_8","alias_value":"WXQSAGIJ","created_at":"2026-07-05T11:12:40.234455+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":14,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24245","citing_title":"AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26479","citing_title":"Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2607.01236","citing_title":"Safeguarding LLM Agents from Misalignment through Provenance Analysis","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12535","citing_title":"Ghost in the Context: Policy-Carriage Integrity in LLM Agents","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03518","citing_title":"Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10749","citing_title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","ref_index":244,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12535","citing_title":"Ghost in the Context: Policy-Carriage Integrity in LLM Agents","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2603.12230","citing_title":"Security Considerations for Artificial Intelligence Agents","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12535","citing_title":"Ghost in the Context: Policy-Carriage Integrity in LLM Agents","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03213","citing_title":"When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08460","citing_title":"When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks","ref_index":38,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01143","citing_title":"A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12986","citing_title":"Parallax: Why AI Agents That Think Must Never Act","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03213","citing_title":"When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI","json":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI.json","graph_json":"https://pith.science/api/pith-number/WXQSAGIJAGWKX4XO5GUIWLAEFI/graph.json","events_json":"https://pith.science/api/pith-number/WXQSAGIJAGWKX4XO5GUIWLAEFI/events.json","paper":"https://pith.science/paper/WXQSAGIJ"},"agent_actions":{"view_html":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI","download_json":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI.json","view_paper":"https://pith.science/paper/WXQSAGIJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.24019&json=true","fetch_graph":"https://pith.science/api/pith-number/WXQSAGIJAGWKX4XO5GUIWLAEFI/graph.json","fetch_events":"https://pith.science/api/pith-number/WXQSAGIJAGWKX4XO5GUIWLAEFI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI/action/storage_attestation","attest_author":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI/action/author_attestation","sign_citation":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI/action/citation_signature","submit_replication":"https://pith.science/pith/WXQSAGIJAGWKX4XO5GUIWLAEFI/action/replication_record"}},"created_at":"2026-07-05T11:12:40.234455+00:00","updated_at":"2026-07-05T11:12:40.234455+00:00"}