Authors: Ravindra Babu Annam
Abstract: The growing deployment of Large Language Model (LLM) agents coupled with third-party tools, APIs, databases, and cloud computing resources creates additional security issues due to the potential of an autonomous agent invoking a tool request which could be unauthorized, insecure, or unsuitable for the context. Current access control solutions are concentrated on static data authorization, fine-grain resource protection, and general AI security, but fail to address dynamic authorization of LLM-agent tool invocation. This paper proposes the development of a Context-aware Secure Tool Invocation Framework (CASTIF), which introduces a security enforcement mechanism for LLM agents during external tool invocation. The proposed framework considers agent identity, operation invoked, sensitivity of the target resource, user authorization, security policies applicable to this situation, context, and invocation history prior to executing any requested tool. In addition to this, the framework also conducts secondary verification on medium-risk requests, sanitizes tool parameters, verifies tool responses, maintains an audit log, and updates the contextual risk profile after each call. The evaluation is done by comparison of CASTIF with Al-Zahrani Model (AZM) and PEHR in terms of authorization accuracy, prevention of unauthorized invocation, context-awareness, false authorizations, decision latencies, and completeness of audits. An example-based evaluation suggests that CASTIF can offer better authorization accuracy, prevent unauthorized invocations, minimize false authorization, and conduct complete auditing.
International Journal of Science, Engineering and Technology