cs.CROct 1, 2026

OverAct: Measuring and Mitigating Proactive Over-Authorization in LLM Tool-Calling Agents

Authors: Taolin Zhang, Jiuheng Wan, Hanyu Wang, Tingyuan Hu, Chengyu Wang

Organizations: Hefei University of Technology · East China Normal University · Alibaba Cloud Computing

Abstract

LLM agents with tool-calling capabilities can access external services and private user data, but they may retrieve more information than a user's request explicitly requires. We study this behavior in structured tool-calling agents and term it proactive over-authorization. This setting differs from filesystem-level coding agents because the main risk is unnecessary access to private data. We introduce OverAct, a controlled benchmark spanning eight privacy-sensitive domains with deterministic, judge-free scoring, together with an interpretive decision-theoretic framework that yields three testable predictions. Across seven models from four families, all models significantly exceed authorized scope. Request specificity is the strongest predictor of severity, over-authorization grows sublinearly with tool-pool size, and decoding temperature has little effect. These patterns are consistent with a cost-asymmetry account, suggesting that over-authorization arises more from structural decision tendencies than from decoding randomness. We also propose SelfAudit, a zero-shot inference-time method that generates request-grounded justifications and filters unjustified calls before execution. Ablation shows that explicit filtering is the main driver of scope reduction. SelfAudit reduces privacy-oriented excess by 43% without oracle knowledge.

Figures & tables

Appendix figures & tables6 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents

    Jun 26, 2026Shijing Hu, Liang Liu, Zhu Meng +1Language-Model AgentsPrivacy

  2. PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say

    May 29, 2026Mingxuan Zhang, Jiahui Han, Dadi Guo +5PrivacyAttacker Large Language Model

  3. When Lower Privileges Suffice: Investigating Over-Privileged Tool Selection in LLM Agents

    Jun 18, 2026Kaiyue Yang, Yuyan Bu, Jingwei Yi +5Controlling Tool UseLarge Language Model Agents