AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the security threat of compositional attacks launched by LLM agents through conventional operation sequences. We propose a runtime gating mechanism grounded in authorization and data provenance, which binds precise parameters, validity periods, and usage limits to decision paths. Employing a deterministic architecture that operates independently of LLMs, this approach provides a unified gating interface across diverse production environments. Furthermore, it integrates operator declarations, host approvals, delegation constraints, and effect ledgers to ensure execution auditability. Experimental results validate the feasibility of the proposed mechanism, demonstrating perfect consistency between replay outcomes and real-time graph projections. However, limitations regarding content transformation and observation coverage are also identified.
📝 Abstract
LLM agents can produce harmful effects through sequences of ordinary operations. Judging such actions requires establishing both the authority that permits them and the origin of the data they carry. We present AGATE, an authorization and data-provenance gate at instrumented agent-harness boundaries. Operator declarations and host approval events ground authorization; delegated actions are constrained by grants that bind to exact parameters, expire, and permit a limited number of uses. Source registration connects observed inputs to subsequent transfers, while an effect ledger tracks repeated requests. Deterministic checks make decisions without an LLM in the decision path and retain their grounds with execution evidence for forensic replay. Adapters integrate three production harnesses -- DeepSeek Harness, OpenCode, and OpenClaw -- without modifying host code, translating each host's native observation and veto points into a single shared gate interface; the judgment core is identical in all three, and only enforcement depth differs. Our evaluation combines 153 exercised attack-chain records with deployment, utility, and reconstruction experiments. The deployment observations expose how tool declarations and data checks govern business actions, including a bypass through parameter rewriting. Six of eleven benign file-processing scenarios contain denial events, revealing the utility cost of content-based provenance policies. Across 252 runs on 63 sanitized scenarios, replay agrees with live graph projections for all 63 scenarios on each of two platforms. These results establish the feasibility of provenance-based runtime judgment and identify content transformation, legitimate reuse, and observation coverage as concrete limits.
Problem

Research questions and friction points this paper is trying to address.

LLM agents
compositional attacks
data provenance
authorization
runtime defense
Innovation

Methods, ideas, or system contributions that make the work stand out.

Data Provenance
Runtime Defense
LLM Agents
Deterministic Authorization
Compositional Attacks
X
Xiaorui Zhang
Huazhong University of Science and Technology, Wuhan, China
Z
Zhuoran Cheng
Huazhong University of Science and Technology, Wuhan, China
K
Kailin Liu
Huazhong University of Science and Technology, Wuhan, China
Z
Zhaoxi Sun
Huazhong University of Science and Technology, Wuhan, China
Shiyu Fan
Shiyu Fan
University of Glasgow
Computer Graphics
T
Tongyu Yuan
Huazhong University of Science and Technology, Wuhan, China
B
Bin Yuan
Huazhong University of Science and Technology, Wuhan, China
W
Weizhong Qiang
Huazhong University of Science and Technology, Wuhan, China
D
Deqing Zou
Huazhong University of Science and Technology, Wuhan, China