Chronicle/Defense & research

Researchers from labs and industry publish design patterns for provably injection-resistant agents

DefenseFrameworkSignificance assistant-drafted

Authors from Invariant Labs, IBM, ETH Zurich, Swisscom, Google, Microsoft and others propose six design patterns that limit what injected text can do, such as action-selector, plan-then-execute, dual LLM, LLM map-reduce, code-then-execute and context minimization. They discuss utility and security trade-offs and illustrate the patterns with ten application case studies.

Why it matters

It gives builders architecture-level mitigations that do not depend on the model detecting injections.

Key facts

As stated in the sources, with where to find them.

  • Six patterns defined; ten case studies including an SQL agent, email and calendar assistant, and software engineering agent.Section 3.1; Section 4

Findings that cite this record

Key questions this bears on

Sources

Related records