{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:XITTF4EOM5EUKJEI4TGAQAXIJB","short_pith_number":"pith:XITTF4EO","schema_version":"1.0","canonical_sha256":"ba2732f08e6749452488e4cc0802e8484f94a976fa2aeac373cdfc2317210279","source":{"kind":"arxiv","id":"2403.04960","version":2},"attestation_state":"computed","paper":{"title":"IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CY","cs.LG"],"primary_cat":"cs.CR","authors_text":"Franziska Roesner, Ning Zhang, Tadayoshi Kohno, Umar Iqbal, Yuhao Wu","submitted_at":"2024-03-08T00:02:30Z","abstract_excerpt":"Large language models (LLMs) extended as systems, such as ChatGPT, have begun supporting third-party applications. These LLM apps leverage the de facto natural language-based automated execution paradigm of LLMs: that is, apps and their interactions are defined in natural language, provided access to user data, and allowed to freely interact with each other and the system. These LLM app ecosystems resemble the settings of earlier computing platforms, where there was insufficient isolation between apps and the system. Because third-party apps may not be trustworthy, and exacerbated by the impre"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2403.04960","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-03-08T00:02:30Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CY","cs.LG"],"title_canon_sha256":"9b6b3293bc62713ff0eabe22dc0b8a2297bee3ee055ed63a113d0e9d70892588","abstract_canon_sha256":"94f4d12c2279ab35b77cfe9bace5791beebc7269b21c34f732ed05410ab6d2e7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:07:39.732358Z","signature_b64":"xhL12kEs82aPjmFTughmbDg3hkG8WrBe46eF9KUe8oWavzwib51BL2Tl5wQ+LlXPIxW6oGwP/nK9y1nUfAKUAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ba2732f08e6749452488e4cc0802e8484f94a976fa2aeac373cdfc2317210279","last_reissued_at":"2026-07-05T10:07:39.731866Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:07:39.731866Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CY","cs.LG"],"primary_cat":"cs.CR","authors_text":"Franziska Roesner, Ning Zhang, Tadayoshi Kohno, Umar Iqbal, Yuhao Wu","submitted_at":"2024-03-08T00:02:30Z","abstract_excerpt":"Large language models (LLMs) extended as systems, such as ChatGPT, have begun supporting third-party applications. These LLM apps leverage the de facto natural language-based automated execution paradigm of LLMs: that is, apps and their interactions are defined in natural language, provided access to user data, and allowed to freely interact with each other and the system. These LLM app ecosystems resemble the settings of earlier computing platforms, where there was insufficient isolation between apps and the system. Because third-party apps may not be trustworthy, and exacerbated by the impre"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2403.04960","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2403.04960/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2403.04960","created_at":"2026-07-05T10:07:39.731925+00:00"},{"alias_kind":"arxiv_version","alias_value":"2403.04960v2","created_at":"2026-07-05T10:07:39.731925+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2403.04960","created_at":"2026-07-05T10:07:39.731925+00:00"},{"alias_kind":"pith_short_12","alias_value":"XITTF4EOM5EU","created_at":"2026-07-05T10:07:39.731925+00:00"},{"alias_kind":"pith_short_16","alias_value":"XITTF4EOM5EUKJEI","created_at":"2026-07-05T10:07:39.731925+00:00"},{"alias_kind":"pith_short_8","alias_value":"XITTF4EO","created_at":"2026-07-05T10:07:39.731925+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":23,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.05743","citing_title":"The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities","ref_index":15,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":120,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26479","citing_title":"Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2606.15549","citing_title":"One Goal, Many Commands: Characterizing Denylist Fragility in AI Agents","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2606.15057","citing_title":"AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12737","citing_title":"PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02668","citing_title":"What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24309","citing_title":"Reframing LLM Agent Security as an Agent-Human Interaction Problem","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26497","citing_title":"Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28071","citing_title":"AgentGuard: An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2402.06922","citing_title":"Whispers in the Machine: Confidentiality in Agentic Systems","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2410.20791","citing_title":"From Cool Demos to Production-Ready FMware: Core Challenges and a Technology Roadmap","ref_index":113,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16630","citing_title":"PrivScope: Task-scoped Disclosure Control for Hybrid Agentic Systems","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2506.04565","citing_title":"From Standalone LLMs to Integrated Intelligence: A Survey of Compound Al Systems","ref_index":198,"is_internal_anchor":false},{"citing_arxiv_id":"2512.01594","citing_title":"CAEC: Confidential, Attestable, and Efficient Inter-CVM Communication with Arm CCA","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2406.13352","citing_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","ref_index":66,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11770","citing_title":"Behavioral Integrity Verification for AI Agent Skills","ref_index":37,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11360","citing_title":"Options, Not Clicks: Lattice Refinement for Consent-Driven MCP Authorization","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03378","citing_title":"ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection","ref_index":149,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00314","citing_title":"Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12986","citing_title":"Parallax: Why AI Agents That Think Must Never Act","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2604.06284","citing_title":"ClawLess: A Security Model of AI Agents","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2604.18231","citing_title":"AgenTEE: Confidential LLM Agent Execution on Edge Devices","ref_index":58,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB","json":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB.json","graph_json":"https://pith.science/api/pith-number/XITTF4EOM5EUKJEI4TGAQAXIJB/graph.json","events_json":"https://pith.science/api/pith-number/XITTF4EOM5EUKJEI4TGAQAXIJB/events.json","paper":"https://pith.science/paper/XITTF4EO"},"agent_actions":{"view_html":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB","download_json":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB.json","view_paper":"https://pith.science/paper/XITTF4EO","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2403.04960&json=true","fetch_graph":"https://pith.science/api/pith-number/XITTF4EOM5EUKJEI4TGAQAXIJB/graph.json","fetch_events":"https://pith.science/api/pith-number/XITTF4EOM5EUKJEI4TGAQAXIJB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB/action/storage_attestation","attest_author":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB/action/author_attestation","sign_citation":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB/action/citation_signature","submit_replication":"https://pith.science/pith/XITTF4EOM5EUKJEI4TGAQAXIJB/action/replication_record"}},"created_at":"2026-07-05T10:07:39.731925+00:00","updated_at":"2026-07-05T10:07:39.731925+00:00"}