CoSec: Benchmarking Agent Security in Communities

πŸ“… 2026-09-28
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the insufficient evaluation of privacy leakage and privilege escalation risks in LLM agents operating within collaborative communities. To this end, we introduce CoSec, a benchmark that pioneers executable test environments encompassing both static and dynamically evolving boundaries. By integrating persistent memory, file systems, and tool usage, it enables end-to-end security verification. Furthermore, leveraging execution tracing techniques, the framework automates detection across multiple attack surfaces, including dialogues, environmental content, memory states, and composite workflows. Experimental results demonstrate that high task completion rates frequently co-occur with recurrent policy violations, revealing a fundamental non-equivalence between utility and compliance. These findings underscore that community authorization mechanisms remain a critical unresolved challenge for deploying secure multi-agent systems.
πŸ“ Abstract
LLM agents operate in persistent collaborative environments involving multiple users, communities, memories, files, and tools. Community boundaries may remain fixed or evolve with changes in membership, roles, composition, and relationships. Agents must complete legitimate tasks and prevent unauthorized disclosure of protected information. Existing evaluations do not fully examine these risks in agent systems. We introduce \textbf{CoSec}, an executable benchmark for evaluating privacy and authorization enforcement in LLM agent systems operating within and across communities. CoSec contains 208 canonical scenarios spanning fixed and evolving boundaries, protected information belonging to the agent owner or other participants, and attacks through dialogue, environmental content, persistent memory, and composed workflows. CoSec executes complete agent systems with persistent sessions, memory, files and tools. It verifies information flows against the active authorization state using execution traces and artifacts. Across harness and model configurations, agents frequently complete benign tasks but violate privacy and authorization boundaries. Privacy behavior varies across harnesses, attack surfaces, and community states, revealing how memory, files, tools, and workflows can carry protected information beyond its authorized scope. These findings show that task utility does not imply privacy or authorization compliance and that authorization in community settings remains an unresolved security challenge for persistent LLM agents.
Problem

Research questions and friction points this paper is trying to address.

LLM agent security
privacy enforcement
authorization compliance
community boundaries
benchmarking
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM Agent Security
Executable Benchmark
Privacy Enforcement
Authorization
Community Boundaries
Hao Chen
Hao Chen
Nanjing University
Real-Time CommunicationsAdaptive Video StreamingDeep Reinforcement Learning
W
Wenhui Dong
Nanjing University
Y
Ye Chen
Xi’an Jiaotong University
J
Jiezhi Yao
Beihang University
C
Chenbo Xia
Zhejiang University
Y
Yuwen Qu
Nanjing University
R
Renxiang Wang
Zhejiang Sci-Tech University
F
Fudong Yuan
Zhejiang University
C
Camil Hamami
Tsinghua University
C
Chenglong Pan
Southeast University
X
Xinquan Yue
Nanjing University
Z
Ziyu Wang
Tongji University
F
Fengyu Ye
Sun Yat-sen University
C
Chenyang Si
Nanjing University
Caifeng Shan
Caifeng Shan
Philips Research
Computer VisionPattern RecognitionMachine LearningImage/Video Analysis