Developer 3s Key Decision Metrics
Researchers from Southern University of Science and Technology (SUSTech) unveiled ActGov (arXiv:2609.24446), a runtime policy-constrained governance framework designed to enforce strict authorization boundaries over LLM agent tool executions. When agents execute multi-step workflows, untrusted web outputs or file contents often trigger indirect prompt injection attacks, exceeding user intent. Rather than relying on fragile LLM-based self-policing, ActGov pairs an iterative SMT-verified policy compiler (ActGov-Policy) with a lightweight runtime validator (ActGov-Runtime). In evaluations across AgentDojo and AgentDyn benchmarks, ActGov near-completely neutralizes prompt injection threats while preserving full task utility, outperforming static guardrails without latency penalties.
Key Takeaways
- ✓SMT-verified policy synthesis: ActGov-Policy generates conflict-free authorization policies verified through SMT counterexample checking
- ✓Pre-execution runtime interception: abstracts tool calls into finite policy records, blocking unauthorized side effects before external impact
- ✓Model-agnostic determinism: eliminates reliance on LLMs to self-detect malicious instructions, enforcing external formal guarantees
- ✓Superior safety benchmarks: reduces indirect prompt-injection success rates by over 92% across AgentDojo and AgentDyn with zero utility loss
- ✓Long-horizon resilience: maintains dynamic task-scoped authorization boundaries across deep multi-step agent execution branches
Finished reading? Explore benchmark rankings & pricing
Real-world SWE-bench scores & $20/mo vs API cost break-even calculator
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.