{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:RCACBCA77QLGWFJC4VXM5QJQDH","short_pith_number":"pith:RCACBCA7","schema_version":"1.0","canonical_sha256":"888020881ffc166b1522e56ecec13019da56f1093fc979ba2bc6bfde69d030be","source":{"kind":"arxiv","id":"2503.15547","version":2},"attestation_state":"computed","paper":{"title":"Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.MA"],"primary_cat":"cs.CR","authors_text":"Byoungyoung Lee, Juhee Kim, Woohyuk Choi","submitted_at":"2025-03-17T05:27:57Z","abstract_excerpt":"Large Language Models (LLMs) are combined with tools to create powerful LLM agents that provide a wide range of services. Unlike traditional software, LLM agent's behavior is determined at runtime by natural language prompts from either user or tool's data. This flexibility enables a new computing paradigm with unlimited capabilities and programmability, but also introduces new security risks, vulnerable to privilege escalation attacks. Moreover, user prompts are prone to be interpreted in an insecure way by LLM agents, creating non-deterministic behaviors that can be exploited by attackers. T"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.15547","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-17T05:27:57Z","cross_cats_sorted":["cs.AI","cs.MA"],"title_canon_sha256":"824f5d829e92ce973b13c046ab893ece98aa25efcb5357afd0332c096c240c12","abstract_canon_sha256":"a8d97254e9bbcdc324580acfcf013f06065b9c87844fa9e2f0a71bd46ce14403"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:51:34.706453Z","signature_b64":"NzRedxqyGylkdiEtimk9awzmAfbHSu9qhGAnaPc/qGtig1PDMua2YaLLQGL6d8tIXxpuPRg6nB1I2zxs+BvJDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"888020881ffc166b1522e56ecec13019da56f1093fc979ba2bc6bfde69d030be","last_reissued_at":"2026-07-05T10:51:34.705980Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:51:34.705980Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.MA"],"primary_cat":"cs.CR","authors_text":"Byoungyoung Lee, Juhee Kim, Woohyuk Choi","submitted_at":"2025-03-17T05:27:57Z","abstract_excerpt":"Large Language Models (LLMs) are combined with tools to create powerful LLM agents that provide a wide range of services. Unlike traditional software, LLM agent's behavior is determined at runtime by natural language prompts from either user or tool's data. This flexibility enables a new computing paradigm with unlimited capabilities and programmability, but also introduces new security risks, vulnerable to privilege escalation attacks. Moreover, user prompts are prone to be interpreted in an insecure way by LLM agents, creating non-deterministic behaviors that can be exploited by attackers. T"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.15547","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.15547/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.15547","created_at":"2026-07-05T10:51:34.706046+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.15547v2","created_at":"2026-07-05T10:51:34.706046+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.15547","created_at":"2026-07-05T10:51:34.706046+00:00"},{"alias_kind":"pith_short_12","alias_value":"RCACBCA77QLG","created_at":"2026-07-05T10:51:34.706046+00:00"},{"alias_kind":"pith_short_16","alias_value":"RCACBCA77QLGWFJC","created_at":"2026-07-05T10:51:34.706046+00:00"},{"alias_kind":"pith_short_8","alias_value":"RCACBCA7","created_at":"2026-07-05T10:51:34.706046+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":24,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.06000","citing_title":"Context-to-Execution Integrity for LLM Agents","ref_index":17,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26479","citing_title":"Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2606.22504","citing_title":"Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2606.15057","citing_title":"AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10525","citing_title":"Assessing Automated Prompt Injection Attacks in Agentic Environments","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26542","citing_title":"ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02302","citing_title":"SeClaw: Spec-Driven Security Task Synthesis for Evaluating Autonomous Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02668","citing_title":"What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26542","citing_title":"ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24309","citing_title":"Reframing LLM Agent Security as an Agent-Human Interaction Problem","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26542","citing_title":"ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26497","citing_title":"Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26542","citing_title":"ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.29082","citing_title":"The Importance of Out-of-Band Metadata for Safe Autonomous Agents: The Redpanda Agentic Data Plane","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28999","citing_title":"Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2606.00497","citing_title":"\"I Strongly Suspect This Website Is a Scam\": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents","ref_index":137,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10749","citing_title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","ref_index":84,"is_internal_anchor":false},{"citing_arxiv_id":"2506.23978","citing_title":"LLM Agents Are the Antidote to Walled Gardens","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11770","citing_title":"Behavioral Integrity Verification for AI Agent Skills","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24026","citing_title":"From Skill Text to Skill Structure: The Scheduling-Structural-Logical Representation for Agent Skills","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05868","citing_title":"SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08499","citing_title":"PIArena: A Platform for Prompt Injection Evaluation","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07536","citing_title":"TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2604.15579","citing_title":"Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents","ref_index":34,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH","json":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH.json","graph_json":"https://pith.science/api/pith-number/RCACBCA77QLGWFJC4VXM5QJQDH/graph.json","events_json":"https://pith.science/api/pith-number/RCACBCA77QLGWFJC4VXM5QJQDH/events.json","paper":"https://pith.science/paper/RCACBCA7"},"agent_actions":{"view_html":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH","download_json":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH.json","view_paper":"https://pith.science/paper/RCACBCA7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.15547&json=true","fetch_graph":"https://pith.science/api/pith-number/RCACBCA77QLGWFJC4VXM5QJQDH/graph.json","fetch_events":"https://pith.science/api/pith-number/RCACBCA77QLGWFJC4VXM5QJQDH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH/action/storage_attestation","attest_author":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH/action/author_attestation","sign_citation":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH/action/citation_signature","submit_replication":"https://pith.science/pith/RCACBCA77QLGWFJC4VXM5QJQDH/action/replication_record"}},"created_at":"2026-07-05T10:51:34.706046+00:00","updated_at":"2026-07-05T10:51:34.706046+00:00"}