papersTODAY 04:00 UTC
arXiv Paper Proposes Structural Tenant Isolation for Tool-Using LLM Agents
A new arXiv preprint examines how multi-tenant tools that check a caller-supplied tenant identifier can be exploited when the caller is an LLM agent, since attacker-controlled content may sit in the agent's context. The authors argue for enforcing isolation at the structural level rather than relying on the model to choose and self-report the correct resource. The proposed approach, called Stochastic Deputy, aims to prevent an agent's reasoning context from deciding which tenant's resources are accessed.