Score
Designs and evaluates mechanisms that govern and enforce how information propagates among system components and across semantic boundaries, including static and dynamic information‑flow analyses and policy-based enforcement (information‑flow control, IFC). Builds runtime flow mediators, semantic gateways, and auditing tools to monitor, mediate, and prevent unauthorized cross‑boundary data movements and exfiltration.
Existing language-level information-flow control (IFC) frameworks struggle to model asymmetric security assumptions—such as semi-honest agents—due to their inherent symmetry in confidentiality and integrity guarantees. Method: This paper introduces a lattice-based algebraic semantic framework that formally captures *asymmetric delegation*: the independent and partial delegation of confidentiality and integrity policies. The framework uniformly supports secure downgrading, non-malleable information flow (NMIF) guarantees, and static inference of bounded-label polymorphism. It innovatively incorporates NMIF constraints to preserve security during downgrading and designs an efficient label inference algorithm alongside a sound NMIF static verifier. Results: The framework enables writing label-agnostic, generic secure code, achieving a balanced trade-off among expressiveness, security, and practicality. Empirical evaluation on real-world programs demonstrates its feasibility, effectiveness, and scalability in enforcing fine-grained, asymmetric IFC policies.
As AI agents gain increasing autonomy, security threats—particularly prompt injection—pose growing risks to agent integrity and confidentiality. Method: This paper introduces Fides, the first information-flow control (IFC) framework specifically designed for AI agent planners. It integrates dynamic taint tracking, confidentiality/integrity labels, and policy-enforcement mechanisms. Its core innovations include: (1) a formal IFC model tailored to planning processes; (2) security primitives enabling selective information hiding; and (3) a task taxonomy jointly optimizing security guarantees and functional utility. Contribution/Results: Implemented as an open-source secure planner, Fides significantly expands the set of tasks safely executable under strong, formal security guarantees—demonstrated via rigorous evaluation on the AgentDojo benchmark—while maintaining practical performance and usability.
Existing information flow control mechanisms predominantly rely on static policies, which struggle to accommodate dynamic confidentiality requirements at runtime. This work proposes the first statically verifiable type system that supports dynamic declassification policies, enabling secure downgrading or upgrading of information flow restrictions during execution. It formally establishes and implements a sound static enforcement mechanism for dynamic release policies, unifying previously disparate approaches such as declassification, endorsement, and caller-specified policies, while introducing novel proof techniques. Through formal modeling and program logic verification, we implement a prototype in Rust and demonstrate the effectiveness and practicality of our approach in real-world scenarios, including conference paper reviewing and the Civitas electronic voting system.
This work addresses the critical gap that while AI-generated SQL queries may be semantically correct, they often violate data privacy and security policies, and current database systems lack fine-grained data flow control. The paper proposes Data Flow Control (DFC), a framework that embeds tuple-level security policies directly into the database infrastructure for the first time. DFC employs a declarative policy language to specify constraints and formalizes the security of aggregate predicates using provenance monomials. Through the Passant query rewriting layer, DFC enables optimizer-agnostic, cross-DBMS-compatible policy enforcement with zero runtime overhead, without materializing provenance data. Experiments demonstrate that Passant incurs near 0% performance overhead across DuckDB, Umbra, PostgreSQL, DataFusion, and SQL Server, outperforming existing approaches by several orders of magnitude, thereby shifting data security from prompt engineering to native infrastructure guarantees.
To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.
Traditional enterprise security models, reliant on static perimeters, struggle to address the dynamic risks introduced by production-grade AI agents operating within authorized workflows. This work proposes the first five-plane reference architecture for runtime governance of AI agents—spanning inference, network, identity, endpoint, and data—and introduces core primitives including arbitrary-point interception, composite subjects with capability decay, and structured audit evidence. By extending policy enforcement from atomic subjects to decay-aware composite subjects, the framework defines six interruption primitives and four correctness invariants. Evaluated across five real-world workflows, it successfully mitigates seven threat classes, achieves microsecond-scale policy decisions, and validates correctness of capability decay, audit reconstructability, and tamper resistance, thereby filling a critical gap in dynamic governance for agent-driven workflows.
This work addresses the challenge of ensuring information-flow security when dynamically extending security lattices in concurrent systems. By extending an existing type system, it introduces—for the first time within the π-calculus—a scalable security lattice mechanism that supports runtime insertion of new security levels. The authors rigorously establish non-interference through reduction semantics and bisimulation equivalence. This approach overcomes the limitations of traditional static, binary security lattices by providing a formal verification framework that guarantees strict information isolation between high- and low-security levels, even as security policies are dynamically adjusted at runtime.
Current AI agent authorization mechanisms rely on static credentials, which struggle to ensure that tool invocations align with the user’s current intent and may lead to privilege escalation. This work proposes Intent-Governed Access Control (IGAC), the first framework to treat user intent as a monotonic and auditable authorization dimension. IGAC dynamically constrains agent behavior without expanding baseline permissions by introducing intent certificates, session-level permission narrowing, and consistency checks across intent, tool, and payload. Integrated into the OpenPort framework—which supports attribute-based access control (ABAC), pre-flight binding, and auditability—IGAC enables intent-driven, fine-grained authorization. This approach significantly enhances the controllability and compliance of AI agent actions while preserving existing security mechanisms.