AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

ActGuard: Pre-execution Action Auditing against Indirect Prompt Injection in LLM Agents

arXiv · AI, language, vision and robotics · article · Sep 14, 2026 · UTC

Large language model (LLM) agents interact with external environments through tool invocation, but tool outputs can also expose them to indirect prompt injection (IPI) attacks. Existing defenses mainly rely on prompt hardening, content filtering, pre-generated plans, or permission constraints. These approaches often struggle with complex tasks or over-sanitize external content, making it difficult to balance security and utility. The key challenge is therefore to preserve execution flexibility while precisely identifying and removing the malicious content that actually induces unsafe actions.

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-20T11:41:07.830Z. This is not the publication date.