acceptodds
Under review as a conference paper at ICLR 2027

SPILLWAY: Separating Target Admission from Sanitization to Defend Tool-Using Agents against Prompt Injection

Abstract

Tool-using agents act on email, files, and payments, so an instruction hidden in a web page or a shared document can make an agent send data or money to an attacker. Many runtime defenses put a language model on the decision that lets an action through, so the decision depends on a model that may read the attacker's text and adds model calls to every step; provenance defenses keep the model off the final check but need a model to plan or route each task first. Where an action goes can instead be read from the tools' typed returns: an email's sender or a payment's account arrives in a typed field, while injected instructions arrive as free text. SPILLWAY turns this observation into a deterministic check with no per-task plan. The check admits a call when each target was named by the user, directly or through a fixed delegation rule, or returned by a read-only tool in a typed field; a deterministic sanitizer removes instruction-like regions its fixed rules match before the model reads them and retains the removed spans as evidence, and a local judge may restore a refused call, never one whose target lies in the removed text. Across three backbones, and seven task suites on one of them, SPILLWAY is the only defense we evaluate under which no templated injection redirects an action to an attacker's target, it also holds under chat-template forging, and it requires no defense-triggered backbone re-run while keeping the highest observed mean utility under the basic attack. As personal AI agents take over users' email, files, and payments, this separation gives them a deterministic, auditable guard on where their actions go, one that keeps them useful and does not change with the backbone.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.