MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the poor scalability of static policies and the security vulnerabilities to indirect prompt injection attacks inherent in LLM-based judgment during AI agent tool calling. To mitigate these issues, this work proposes a meta-attribute-based access control framework that decouples semantic reasoning from secure execution. By innovatively deriving a compact, task-agnostic set of meta-attributes, the approach combines LLM-inferred attribute values with deterministic rule evaluation to achieve dynamic authorization without enumerating intents. Experimental results demonstrate that the proposed framework improves decision consistency by 31% and increases task completion rates by up to 109%, while completely blocking malicious invocations. These findings indicate that the method significantly outperforms existing defense mechanisms, offering a robust and scalable solution for securing tool-calling behaviors in AI agents.
📝 Abstract
The rise of autonomous AI agents equipped with tools has introduced significant security risks, ranging from unintended tool misuse to adversarial manipulation through Indirect Prompt Injection (IPI) attacks. In practice, deployed agent systems such as OpenAI Codex and Claude Code protect tool invocations through a combination of coarse-grained permission rules and LLM-based judgments about individual proposed actions. Both components, however, have important limitations: static policies must anticipate possible user intents and therefore do not scale to open-ended tasks, while LLM-driven authorization supports dynamic decisions but produces inconsistent outcomes and remains vulnerable to targeted IPI attacks. To provide scalable and more consistent authorization, we propose MetaPermit, a policy-based tool access-control framework that decouples semantic inference from security enforcement. By analyzing agent-user interactions, we derive a compact, task-independent set of meta-attributes that capture the relationships among the user's intent, the execution context, and the proposed tool call. These meta-attributes allow MetaPermit to authorize tool use without enumerating user intents. At runtime, an LLM infers the meta-attribute values for each proposed tool call, while a fixed policy evaluates these values to allow or deny the call, making each decision auditable through the inferred values and the applied policy rule. We evaluate MetaPermit on the AgentDojo and AgentDyn benchmarks, across seven task suites and five attack methods, using two widely deployed open-weight LLMs. The results show that MetaPermit produces 31% more consistent authorization decisions than LLM-driven authorization and outperforms the state-of-the-art defenses CaMeL and IPIGuard in both task completion, with improvements of up to 109%, and robustness to IPI attacks, with no malicious tool calls executed.
Problem

Research questions and friction points this paper is trying to address.

AI agents
access control
indirect prompt injection
tool misuse
authorization
Innovation

Methods, ideas, or system contributions that make the work stand out.

Access Control
Meta-Attributes
Indirect Prompt Injection
AI Agents
Auditable Authorization
H
Hanzhang Ma
Paderborn University
Ali Hariri
Ali Hariri
Senior Researcher at Huawei
Access ControlUsage ControlIoT SecurityNetwork SecurityData Spaces
Tianxiang Shen
Tianxiang Shen
Huawei Technologies Ltd.
B
Bohua Zou
Huawei Hilbert Research Center (Dresden), Technical University of Munich
Q
Qianjun Zheng
Huawei Hilbert Research Center (Dresden), Technical University of Munich
J
Ji Wang
Huawei Technologies Ltd.
L
Li Yi
Huawei Technologies Ltd.
Ning Jia
Ning Jia
Tianjin University
Y
Yutao Liu
Huawei Technologies Ltd.
Haibo Chen
Haibo Chen
FACM & FIEEE, Distinguished Professor, Shanghai Jiao Tong University
Operating SystemsMLSysDistributed Systems
L
Lin Wang
Paderborn University
Debayan Roy
Debayan Roy
Principal OS kernel Researcher, Huawei
Cyber Physical SystemsEmbedded and Real-Time SystemsControl-Platform Co-DesignAutomotive