0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents
- 1.LLM 에이전트의 보안 취약 연산을 분석하는 Security-ADG 프레임워크 AgentSecGraph 제시
- 2.11개 생태계·3만7542개 소스 파일, 67개 실제 LLM 에이전트 저장소로 구성된 벤치마크 AgentSecBench 공개
- 3.2만3866개 보안 취약 연산 후보 중 41.15%에서 의존성 증거, 12.88%에서 가드 증거 복원, 분석 50.8분 소요
- 4.9개 보류 사례에서 참조 컨텍스트 91.1% 보존(sink-only 20.0%, 단순 ADG 40.0% 대비 우수)
왜 중요한가?
명령 실행·파일시스템·네트워크 접근 등 민감 연산의 정체성만으로는 실제 보안 함의를 판단할 수 없다는 점을 실증하며, 신뢰 경계·가드 증거까지 포함한 분석이 실제 취약점을 더 정확히 찾아낼 수 있음을 보여준다.
언급 프로젝트
본문 미리보기
arXiv:2610.03014v1 Announce Type: new Abstract: Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities such as command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations as anchors, but operation identity alone is insufficient to determine security implications. We present AgentSecGraph, a security-aware static analysis
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안

