AI Agents 相关度: 9/10

SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment

Xixun Lin, Yang Liu, Yancheng Chen, Yongxuan Wu, Yucheng Ning, Yilong Liu, Nan Sun, Shun Zhang, Bin Chong, Chuan Zhou, Yanan Cao, Li Guo
arXiv: 2604.13630v1 发布: 2026-04-15 更新: 2026-04-15

AI 摘要

SafeHarness提出了一种集成到LLM Agent生命周期的安全架构,提升其安全性。

主要贡献

  • 提出SafeHarness安全架构,包含四层防御
  • 设计跨层机制,增强安全防御能力
  • 实验证明SafeHarness有效降低UBR和ASR

方法论

设计四层防御架构,并结合跨层机制,通过实验评估其在不同攻击场景下的性能。

原文摘要

The performance of large language model (LLM) agents depends critically on the execution harness, the system layer that orchestrates tool use, context management, and state persistence. Yet this same architectural centrality makes the harness a high-value attack surface: a single compromise at the harness level can cascade through the entire execution pipeline. We observe that existing security approaches suffer from structural mismatch, leaving them blind to harness-internal state and unable to coordinate across the different phases of agent operation. In this paper, we introduce \safeharness{}, a security architecture in which four proposed defense layers are woven directly into the agent lifecycle to address above significant limitations: adversarial context filtering at input processing, tiered causal verification at decision making, privilege-separated tool control at action execution, and safe rollback with adaptive degradation at state update. The proposed cross-layer mechanisms tie these layers together, escalating verification rigor, triggering rollbacks, and tightening tool privileges whenever sustained anomalies are detected. We evaluate \safeharness{} on benchmark datasets across diverse harness configurations, comparing against four security baselines under five attack scenarios spanning six threat categories. Compared to the unprotected baseline, \safeharness{} achieves an average reduction of approximately 38\% in UBR and 42\% in ASR, substantially lowering both the unsafe behavior rate and the attack success rate while preserving core task utility.

标签

LLM Agent Security Adversarial Defense Lifecycle Security

arXiv 分类

cs.CR cs.AI