acceptodds
Under review as a conference paper at ICLR 2027

CallWitness: Post-Resolution Authorization for Secret-Bearing Agent Tool Calls

Abstract

A ticket read produces a secret-labeled handle, a trusted transformation produces a derived handle, and an upload wrapper resolves an alias to its final endpoint. The security-critical edge connects that derived value to that resolved sink; neither endpoint authorization nor value lineage alone expresses the flow. CallWitness delays credential release until a broker-derived value graph and wrapper-attested destination form one authorization record. Unforgeable handles, lineage-preserving transformations, and broker-owned credentials realize this record across nine tool schemas. The evaluation separates necessity, end-to-end effect, and causal attribution. On a paired factorial slice, literal-token seeded-run attack success is 1.4% with the joined record, compared with 29.8% for destination-scoped authority alone and 21.4% for lineage alone. Across 847 attacks, CallWitness records 11/847 successes (1.3%, 95% CI 0.7–2.2%) versus 43/847 (5.1%) for matched intent approval and 21.3–28.4% per channel for a DLP proxy. A browser attestation fork then reuses attack text, sampled calls, lineage, and policy while changing only sink visibility: any-of-five success rises from 5/320 (1.6%) to 75/320 (23.4%), or 15.0\(\times\). The effect recurs with GPT-5.4 and Claude Sonnet 5 integrations; for broker-mediated, destination-declaring calls, CallWitness delivers 94.3% benign completion at 4.2 ms median added latency.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.