paper-with-me

Papers

Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents

2026-07-09 · Puji Wang, Yingchen Zhang, Ruqing Zhang, Jiafeng Guo, Xueqi Cheng arxiv

Persistent AI agents extend large language models (LLMs) beyond single-turn interaction into long-lived software systems. Unlike traditional chat assistants, unsafe content in these agents can propagate through persistent state, reusable skills, and tool-mediated interactions, creating a substantially larger semantic attack surface. We observe that most security-critical interactions in such agents are transmitted through natural-language token flows, including memory updates, tool arguments, retrieved files, and inter-component communications. This observation enables a new security formulation: unsafe behavior can be intercepted as risky semantic flows before reaching privileged runtime sinks. Based on this insight, we propose TokenWall, a runtime defense framework that acts as a semantic firewall over agent token flows. TokenWall performs boundary-aware semantic auditing over these flows, constructing structured source-sink audit records, applying lightweight local inspection before execution, and selectively escalating ambiguous high-risk cases to stronger arbitration modules. Unlike prior approaches that rely on sparse auditing or remote large-model oversight, TokenWall enables full-coverage pre-execution mediation while reducing remote arbitration and latency. Experiments on CIK-Bench show that TokenWall reduces attack success rate to 12.5% while maintaining a 97.4% benign executable pass rate without human confirmation. TokenWall further introduces only 0.69 seconds of additional latency on benign cases, demonstrating that semantic runtime containment can achieve a practical security-utility trade-off for persistent AI agents.

📄 PDF Abstract BibTeX arXiv:2607.08395

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Auditing Chinese Web-scale Corpora via Sampled BPE Token Statistics

2026-08-11 · Qingjie Zhang, Ziqi Tang, Jie Zhang, Gelei Deng 외 arxiv

Chinese web pollution has surfaced in LLMs, motivating audits of upstream Chinese corpora. However, auditing such corpora faces three challenges: (1) their web-scale size makes full scan costly; (2) prior analyses are of…

Learning to Customize Network Security Rules

2017-12-28 · Michael Bargury, Roy Levin, Royi Ronen

Security is a major concern for organizations who wish to leverage cloud computing. In order to reduce security vulnerabilities, public cloud providers offer firewall functionalities. When properly configured, a firewall…

BlockingCloud Computing

DEMM-Bench: A Cross-Regime Benchmark for Agent-Runtime Governance-Evidence Sufficiency

2026-05-30 · Oleg Solozobov arxiv

Agent-runtime systems emit traces, ledgers, provenance graphs, policy logs, delegation tokens, cache events, and tool-firewall records, but those containers do not necessarily answer governance questions about a specific…

Enforcing Benign Trajectories: A Behavioral Firewall for Structured-Workflow AI Agents

2026-04-29 · Hung Dang arxiv

Structured-workflow agents driven by large language models execute tool calls against sensitive external environments. We propose \codename, a telemetry-driven behavioral anomaly detection firewall. Drawing on sequence-b…

Intrusion DetectionAnomaly Detection

Machine Learning Approach on Multiclass Classification of Internet Firewall Log Files

2023-06-12 · Md Habibur Rahman, Taminul Islam, Md Masum Rana, Rehnuma Tasnim 외

Firewalls are critical components in securing communication networks by screening all incoming (and occasionally exiting) data packets. Filtering is carried out by comparing incoming data packets to a set of rules design…