PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 9, 2026ACM Transactions on Software Engineering and Methodology2 citations

Navigating the Risks: A Survey of Security and Privacy Threats in LLM-Based Agents

View Full Paper
YGYuyou GanYYYi YangZWZ W

Key Points

  • The aim is to systematize the security and privacy threat landscape for LLM-based agents in software engineering.
  • Proposed a taxonomy organized by threat sources and impacts across the software lifecycle.
  • Analyzed case studies from web search, gaming, navigation, and software development.
  • Synthesized current mitigation techniques and their limitations for agent features.
  • Identified distinct security and privacy risks at artifact, process, and socio-technical deployment levels.
  • Outlined six agent features influencing risk exposure based on information-flow and control-flow properties.
  • Provided practical examples of risks and failure modes across various domains.

Abstract

Large language models (LLMs) are increasingly embedded into software engineering workflows as autonomous or semi-autonomous agents for code generation, test synthesis, tool orchestration, and end-to-end task automation. While these agentic capabilities promise substantial productivity and quality gains, they also introduce distinct security and privacy risks at the levels of artifacts, processes, and socio-technical deployment pipelines. These risks threaten the trustworthiness of LLM-powered software and complicate core engineering activities such as specification, design, verification, maintenance, and governance. This survey systematizes the threat landscape for LLM-based agents from a software engineering perspective. We propose a taxonomy organized by threat sources and their impacts across the software lifecycle, explicitly capturing cross-module and cross-stage attack surfaces (e.g., tool-use mediation, memory management, and environment interaction). We further distill six agent features grounded in information-flow and control-flow properties that shape risk exposure. We synthesize current mitigation techniques and their limitations for each feature, and conduct four case studies on web search, gaming, navigation, and software development to illustrate practical risks and failure modes. Building on these analyses, we outline research directions in data, methodology, and policy to guide the development of secure and trustworthy LLM-based agents.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gan et al. (2026) studied this question.

synapsesocial.com/papers/69fed17eb9154b0b82878e48https://doi.org/10.1145/3807666
Ask AI
Helpful
Bookmark
Share
View Full Paper