Defending AI Agents Against Indirect Prompt Injection: Dual-LLM Architectures, Privilege Boundaries, and Information Flow Control
Autonomous AI agents are increasingly entrusted with system privileges, including terminal execution, API invocation, internal database queries, and automated communications. As agents transition from isolated conversational sandboxes to interconnected tools, they encounter an inherent architectural vulnerability: indirect prompt injection (IPI). When an agent reads untrusted data from the web, an inbound email, an enterprise ticketing system, or a database record, any instructions embedded wit



















