cs.CRSep 29, 2026

ToolFence: Fine-Grained Authorization for Secure Tool-Using LLM Agents

Authors: Yanjie Li, Xiangyu He, Xuelong Dai, Bin Xiao

Organizations: Hong Kong Polytechnic University · Shandong University

Abstract

Tool-using LLM agents remain vulnerable to indirect prompt injection because trusted instructions and untrusted observations share one context, allowing malicious content to steer consequential input-filtering defenses. Multi-path consensus defenses still leave a high attack success rate because they examine content or aggregated outputs rather than authorizing effects, especially for the within-tool attack, which preserves the intended tool but manipulates its arguments. Data-Flow Control such as CaMeL provides stronger guarantees, but incurs substantial time latency that limits practical deployment. We introduce ToolFence, which compiles a typed authorization blueprint before execution, enforces it through a deterministic monitor, and when the blueprint is incomplete asks a judge to grant new capabilities rather than adjudicate each concrete call. ToolFence provides two key advantages. First, its fine-grained provenance-aware authorization enables the system to distinguish user-authorized values from untrusted observations, effectively addressing the within-tool attack. Second, its deterministic fast path and capability-level runtime grants substantially reduce the frequency of expensive judge calls, improving runtime efficiency. On AgentDojo with Qwen3-max, ToolFence reduces overall ASR to near zero with only a 3.80 percentage-point clean-utility drop and practical runtime overhead.

Figures & tables

Appendix figures & tables2 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. ToolGuardian: Declarative Security for AI Agent-Tool Interactions

    Jul 23, 2026Arun Ravindran, Saurabh DeochakeAuthorizationAgentic Deployments

  2. ActGov: Governing LLM Agent Actions via Policy-Constrained Validation

    Sep 21, 2026Kaiyuan Zhang, Yuke Peng, Ke Jiang +1AuthorizationRuntime Enforcement

  3. PACE: Provenance-Aware Capability Enforcement for Tool-Using LLM Agents

    Oct 1, 2026Fengpeng Li, Qizhou Wang, Yuke Hu +5Language-Model AgentsAttack-Success Rate