LATIDIA · Ciberseguridad
Más allá de los sumideros predefinidos: análisis de dependencia consciente de la seguridad para agentes de LLM
arXiv: 2610.03014v1 Tipo de anuncio: nuevo Resumen: los agentes basados en el modelo de lenguaje grande (LLM) conectan cada vez más las decisiones generadas por el modelo con las capacidades de software sensibles a la seguridad, como la ejecución de comandos, la acreditación del sistema de archivos
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.03014v1 Announce Type: new Abstract: Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities such as command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations as anchors, but operation identity alone is insufficient to determine security implications. We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) for each security-sensitive operation. It augments operation identity with agent relevance, source and dependency evidence, trust-boundary context, guard evidence, and external-effect semantics. We further introduce AgentSecBench, a corpus of 67 real-world LLM-agent repositories spanning 11 ecosystems and 37,542 source files. The current analyzer