Structured multi-agent workflows exchange intermediate messages whose content and form can reveal private state even when the final output is safe. We identify selection-channel leakage: after authorization fixes what may be released, a private-state-aware choice among semantically valid realizations creates an additio...
Jing-Heng Xu, Long-Ze Fan, Ze-Yuan Wang et al.· 0 citations
CapLease is introduced, an authorization-consumption layer that follows proposal- and authority-level defenses, binds an authenticated user confirmation to a canonical action, and enforces transactional Issue-Prepare-Commit transitions, which identifies durable authorization state, rather than token representation alon...
Jingheng Xu, Long-Ze Fan, Zeyuan Wang et al.· 2 citations
Minimum-Necessary Communication is introduced, a typed semantic-declassification protocol that selects a task-sufficient disclosure from an application-authored candidate family and binds it to explicit recipient, purpose, forwarding, lifetime, logging, and memory scopes.
Jingheng Xu, Longze Fan, Zeyuan Wang et al.· 0 citations
This work identifies memory provenance laundering: during LLM-based memory consolidation, an external observation may be rewritten as apparent user history or workflow support, preserving an action trigger while erasing the low-trust source that should limit its authority.
Jing Xu, Yiyong Xiao, Wanru Shao et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.