paper-with-me

홈 › Papers

IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

2024-03-08 · Yuhao Wu, Franziska Roesner, Tadayoshi Kohno, Ning Zhang, Umar Iqbal

Large language models (LLMs) extended as systems, such as ChatGPT, have begun supporting third-party applications. These LLM apps leverage the de facto natural language-based automated execution paradigm of LLMs: that is, apps and their interactions are defined in natural language, provided access to user data, and allowed to freely interact with each other and the system. These LLM app ecosystems resemble the settings of earlier computing platforms, where there was insufficient isolation between apps and the system. Because third-party apps may not be trustworthy, and exacerbated by the imprecision of natural language interfaces, the current designs pose security and privacy risks for users. In this paper, we evaluate whether these issues can be addressed through execution isolation and what that isolation might look like in the context of LLM-based systems, where there are arbitrary natural language-based interactions between system components, between LLM and apps, and between apps. To that end, we propose IsolateGPT, a design architecture that demonstrates the feasibility of execution isolation and provides a blueprint for implementing isolation, in LLM-based systems. We evaluate IsolateGPT against a number of attacks and demonstrate that it protects against many security, privacy, and safety issues that exist in non-isolated LLM-based systems, without any loss of functionality. The performance overhead incurred by IsolateGPT to improve security is under 30% for three-quarters of tested queries.

📄 PDF Abstract BibTeX arXiv:2403.04960

Code (1)

llm-platform-security/secgpt 공식 구현

Similar Papers 제목 키워드 기반

Sovereign Agentic Loops: Decoupling AI Reasoning from Execution in Real-World Systems

2026-04-24 · Jun He, Deying Yu arxiv

Large language model (LLM) agents increasingly issue API calls that mutate real systems, yet many current architectures pass stochastic model outputs directly to execution layers. We argue that this coupling creates a sa…

Agentic Transaction: Towards ACID-Compliant Agent Systems

2026-08-14 · Zhaoyan Sun, Xiaoxiao Wang, Guoliang Li arxiv

Large language model (LLM) agents are evolving from conversational assistants into autonomous systems that execute long-horizon tasks through reasoning, tool use, code generation, and workspace manipulation. As agents in…

Code Generation

ACE: A Security Architecture for LLM-Integrated App Systems

2025-04-29 · Evan Li, Tushin Mallick, Evan Rose, William Robertson 외

LLM-integrated app systems extend the utility of Large Language Models (LLMs) with third-party apps that are invoked by a system LLM using interleaved planning and execution phases to answer user queries. These systems i…

Securing the Agent: Vendor-Neutral, Multitenant Enterprise Retrieval and Tool Use

2026-05-06 · Francisco Javier Arceo, Varsha Prasad Narsing arxiv

Retrieval-Augmented Generation (RAG) and agentic AI systems are increasingly prevalent in enterprise AI deployments. However, real enterprise environments introduce challenges largely absent from academic treatments and …

Semantic Similarity

stratum: A System Infrastructure for Massive Agent-Centric ML Workloads

2026-03-03 · Arnab Phani, Elias Strauss, Sebastian Schelter arxiv

Recent advances in large language models (LLMs) transform how machine learning (ML) pipelines are developed and evaluated. LLMs enable a new type of workload, agentic pipeline search, in which autonomous or semi-autonomo…