LATIDIA · Ciberseguridad
Separación de funciones para agentes de LLM privilegiados: una arquitectura de ejecución gobernada con compensaciones de seguridad-utilidad medidas
arXiv: 2609.38224v1Tipo de anuncio: nuevo Resumen: A los agentes de modelos de lenguaje grandes se les otorgan cada vez más privilegios reales (ejecución de comandos, modificación de archivos, llamadas a API), por lo que un agente que se equivoca ya ha actuado.
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.38224v1 Announce Type: new Abstract: Large language model agents are increasingly granted real privileges (executing commands, modifying files, calling APIs), so an agent that errs has already acted. Existing defences concentrate on the agent's inputs, while the path from a candidate action to privileged side effects remains less directly studied. We argue that this path must be governed outside the model, and study an architecture interposing four roles (planner, policy gate, executor, auditor) between agent and operating system. Two choices are central: actions arrive as structured intents, so adjudication never parses shell syntax; and approval is a one-shot credential bound to the exact bytes that will run. We evaluate on