Skip to content
#edge computing Open access

dspy-security-bench: reproducible security, authorization, and mission assurance evidence for tool-using AI agents

Aug 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

A Python harness for measuring how well language-model agents resist indirect prompt injection. It wraps the AgentDojo task environments and adds a frozen, hashed measurement protocol, joint reporting of task utility alongside attack resistance, cluster-bootstrap confidence intervals over task pairs, and a confirmed/provisional criterion that decides when a result is stable enough to state as a claim. ImpactTwin adds controlled procurement pairs, functional side-effect evidence, repeated-execution uncertainty, and content-addressed community submissions. ProofRun adds a reusable trusted builder, GitHub/Sigstore provenance for exact evidence bytes, and an explicit evidence ladder. Native framework bridges connect OpenAI Agents SDK, LangChain, Pydantic AI, CrewAI, AutoGen, MCP, and custom loops to the same framework-neutral contract. Results are generated from committed evidence so rows and submissions can be audited offline. ControlTwin compares policy-off and policy-on functional outcomes, separates harm containment from safe mission recovery and clean utility, and binds the exact normalized policy to offline-verifiable evidence. RepeatControlTwin repeats the paired policy experiment with fresh agents and alternating condition order, then reports uncertainty bounds, functional transitions, recovery stability, clean-utility preservation, and separated condition-level usage. The Open Control Evidence Registry packages those policy-bound experiments for offline recomputation, public comparison, GitHub/Sigstore provenance, and independently reviewable contribution. IncidentTwin adds an inert cyber-response digital twin with functionally observed alert, secret, network, isolation, and critical-service outcomes. FederalProof binds verified repeated evidence to owner-supplied deployment context and exports OSCAL 1.2.2 assessment results, conditional POA&M inputs, an impact-assessment annex, a QASP scorecard, and a content-addressed manifest. MissionForge adds a strict data-only contract for agency- and company-owned mission evaluations. Its built-in SourceTwin protocol measures citation faithfulness, completeness, sufficiency, current-primary preference, clean utility, and injection resistance through structured claims and source IDs. AuthorityTwin adds a vendor-neutral delegated-authorization adapter contract, ten clean/adversarial identity and authority pairs, normalized request-bound decision receipts, simulated-effect containment, repeated uncertainty, content-addressed public evidence, ProofRun provenance, and FederalProof assessment export. InventoryForge turns bounded public AI-use-case inventories into contact-free, tamper-evident normalization reports and explicitly synthetic MissionPack drafts requiring accountable review. AgentGraphTwin traces six multi-agent authorization-path mutations, attributing first unsafe edge and synthetic blast radius. AuthorityBridge provides translation contracts for OPA, Cedar, OpenFGA, OAuth-bound MCP tools, and SPIFFE. ContinuousProof compares verified evidence identities and metrics using owner-supplied thresholds. AcquisitionProof exports vendor-neutral mission test plans, owner-defined QASP objective inputs, portability checks, cost-observation fields, and reevaluation triggers without automating a procurement decision. TraceProof converts operator-supplied OpenTelemetry JSON into privacy-bounded, pseudonymized evidence; applies deterministic authorization and external-effect rules; and exports synthetic replay twins, SARIF, and OSCAL observations. AgentGraphTwin v2 adds temporal ordering, token exchange, delegation continuity, step-up approval, revocation, parallel races, and multi-effect boundaries. ValueProof computes measured mission economics without forecasts or rankings. MissionPack Commons adds self-contained Ed25519 envelopes and a separately governed, content-addressed catalog for community mission protocols. The TraceProof Runtime Kit records metadata-only tool-boundary events across seven agent-framework profiles and tests sanitizer and MCP authorization evidence without retaining application content. ScheduleProof exhaustively explores bounded authorization-event interleavings, reports exact schedule coverage and minimal causal counterexamples, and exports offline-verifiable JSON and SARIF without executing a model or tool. CausalProof converts structural OpenTelemetry parentage into a provenance-separated ScheduleProof draft while keeping owner assertions, generic span links, and wall-clock candidates distinct. Native OpenAI Agents SDK and LangGraph bridges emit pseudonymized structural evidence and explicit atomic-event bindings without inspecting application content. CollectiveGuard analyzes content-free structural event records for autonomous agent collectives, detecting unapproved cross-run communication, indirect egress, peer-authority laundering, credential misuse, evaluator access, unsafe persistence, missed response windows, recovery approval failures, and non-independent or collapsed defenses with offline-verifiable JSON and SARIF.

View source

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

Agile - denoting "the quality of being agile, readiness for motion, nimbleness, activity, dexterity in motion" - software development methods are attempting to offer an answer to the eager business community asking for lighter weight along with faster and nimbler software development processes. This is especially the case with the rapidly growing and volatile Internet software industry as well as for the emerging mobile application environment. The new agile methods have evoked substantial amount of literature and debates. However, academic research on the subject is still scarce, as most of existing publications are written by practitioners or consultants. The aim of this publication is to begin filling this gap by systematically reviewing the existing literature on agile software development methodologies. This publication has three purposes. First, it proposes a definition and a classification of agile software development approaches. Second, it analyses ten software development methods that can be characterized as being "agile" against the defined criterion. Third, it compares these methods and highlights their similarities and differences. Based on this analysis, future research needs are identified and discussed.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 728 citations · ⚡54
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

Context: Software startups are newly created companies with no operating history and fast in producing cutting-edge technologies. These companies develop software under highly uncertain conditions, tackling fast-growing markets under severe lack of resources. Therefore, software startups present a unique combination of characteristics which pose several challenges to software development activities. Objective: This study aims to structure and analyze the literature on software development in startup companies, determining thereby the potential for technology transfer and identifying software development work practices reported by practitioners and researchers. Method: We conducted a systematic mapping study, developing a classification schema, ranking the selected primary studies according their rigor and relevance, and analyzing reported software development work practices in startups. Results: A total of 43 primary studies were identified and mapped, synthesizing the available evidence on software development in startups. Only 16 studies are entirely dedicated to software development in startups, of which 10 result in a weak contribution (advice and implications (6); lesson learned (3); tool (1)). Nineteen studies focus on managerial and organizational factors. Moreover, only 9 studies exhibit high scientific rigor and relevance. From the reviewed primary studies, 213 software engineering work practices were extracted, categorized and analyzed. Conclusion: This mapping study provides the first systematic exploration of the state-of-art on software startup research. The existing body of knowledge is limited to a few high quality studies. Furthermore, the results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54

Related blog posts

Microsoft Research Blog Aug 31, 2026

GigaPath-Flash and GigaTIME-Flash: Toward population-scale discovery with efficient pathology foundation models

What if pathology foundation models could do more with less? GigaPath-Flash and GigaTIME-Flash cut computational demands while maintaining strong performance, opening the door to larger studies and broader exploration. The post GigaPath-Flash and GigaTIME-Flash: Toward population-scale discovery with efficient pathology foundation models appeared first on Microsoft Research.

MIT News · Artificial Intelligence Aug 27, 2026

Looking beyond natural sequences

A new machine-learning framework aims to improve the success rate of computational protein design while moving away from results that reproduce sequences found in nature.