Evaluation shows dynamic runtime authorization prevents security exploits in autonomous multi-agent systems, demonstrating effective protection against prompt injections and privilege escalations.
Overview & Abstract Autonomous Multi-Agent Systems (MAS) powered by Large Language Models (LLMs) transition computing from deterministic execution paths to probabilistic, multi-hop reasoning loops. Contemporary access governance—including Role-Based (RBAC) and Attribute-Based Access Control (ABAC)—evaluates permissions atomically and statically, leaving multi-agent environments critically exposed to indirect prompt injection, confused deputy privilege escalations, and slow-velocity data scraping. This paper formalizes DynAuth-Agent, an authorization framework that augments standard Policy Decision Points (PDP) with three orthogonal, continuous metrics: Semantic Intent Alignment (Salign): Evaluates vector cosine similarity between the root human prompt and downstream tool dispatches using quantized local embeddings to detect indirect prompt injections. Transitive Trust Lineage (Tchain): Models cryptographic delegation degradation across non-homogeneous network boundaries and workload identities (SPIFFE) to prevent Confused Deputy privilege escalations. Cumulative Blast Radius (Bₛₑₛₛᵢₒₙ): Tracks continuous state across execution sessions using exponential time-decay (t1/2) to contain runaway reasoning loops and automated data scraping. Key Empirical Findings Defense Efficacy: Evaluated against 200 synthetic execution traces, the framework achieved a 98.0% block rate against Indirect Prompt Injection attacks, a 100.0% block rate against Confused Deputy delegations, and a 100.0% containment rate on runaway execution loops, with a 2.0% false-positive rate on benign tasks. Low-Latency Operational Feasibility: The end-to-end Policy Information Point (PIP) and Policy Decision Point (PDP) pipeline executes with deterministic runtime overhead, making dynamic mathematical access control viable for real-time agent tool dispatches. Declarative PDP Compatibility: Fully compatible with standard enterprise policy engines, evaluated directly via Open Policy Agent (OPA) executing compiled Rego policies. Keywords Autonomous Agents, Runtime Authorization, Zero Trust Architecture (ZTA), Policy Decision Point (PDP), Policy Enforcement Point (PEP), Non-Human Identities (NHI), Indirect Prompt Injection, Open Policy Agent (OPA), Delegation Lineage.
No takes yet. Share an insight, caveat, or question.
Manoharan et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: