{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:06:55Z","timestamp":1784300815838,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":22,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T00:00:00Z","timestamp":1783209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,7,5]]},"DOI":"10.1145\/3803437.3805554","type":"proceedings-article","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:27:39Z","timestamp":1784298459000},"page":"1192-1196","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating Privilege Usage of Agents with Real-World Tools"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7778-4243","authenticated-orcid":false,"given":"Quan","family":"Zhang","sequence":"first","affiliation":[{"name":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1618-1870","authenticated-orcid":false,"given":"Lianhang","family":"Fu","sequence":"additional","affiliation":[{"name":"School of Software, Xinjiang University, Urumqi, Xinjiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-8337-0506","authenticated-orcid":false,"given":"Lvsi","family":"Lian","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-0461-9674","authenticated-orcid":false,"given":"Gwihwan","family":"Go","sequence":"additional","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3892-9145","authenticated-orcid":false,"given":"Yujue","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6446-247X","authenticated-orcid":false,"given":"Chijin","family":"Zhou","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Trustworthy Computing, East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0955-503X","authenticated-orcid":false,"given":"Yu","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9750-8334","authenticated-orcid":false,"given":"Geguang","family":"Pu","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,17]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Aliyun. 2026. Alibaba-Cloud-OPS-MCP-Server. https:\/\/github.com\/aliyun\/alibaba-cloud-ops-mcp-server. Accessed: 2026-03-29."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.53"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 34th USENIX Conference on Security Symposium","author":"Chen Sizhe","year":"2025","unstructured":"Sizhe Chen, Julien Piet, Chawin Sitawarin, and David Wagner. 2025. StruQ: defending against prompt injection with structured queries. In Proceedings of the 34th USENIX Conference on Security Symposium (Seattle, WA, USA) (SEC '25). USENIX Association, USA, Article 123, 18 pages."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.acl-long.890"},{"key":"e_1_3_2_1_5_1","volume-title":"Defeating prompt injections by design. arXiv preprint arXiv:2503.18813","author":"Debenedetti Edoardo","year":"2025","unstructured":"Edoardo Debenedetti, Ilia Shumailov, Tianqi Fan, Jamie Hayes, Nicholas Carlini, Daniel Fabian, Christoph Kern, Chongyang Shi, Andreas Terzis, and Florian Tram\u00e8r. 2025. Defeating prompt injections by design. arXiv preprint arXiv:2503.18813 (2025)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2636"},{"key":"e_1_3_2_1_7_1","unstructured":"Google DeepMind. 2025. Gemini 3 Pro Model Card. https:\/\/storage.googleapis.com\/deepmind-media\/Model-Cards\/Gemini-3-Pro-Model-Card.pdf."},{"key":"e_1_3_2_1_8_1","volume-title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments. arXiv preprint arXiv:2506.15253","author":"Fu Yuchuan","year":"2025","unstructured":"Yuchuan Fu, Xiaohan Yuan, and Dongxia Wang. 2025. RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments. arXiv preprint arXiv:2506.15253 (2025)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3706598.3713218"},{"key":"e_1_3_2_1_11_1","volume-title":"Delegated Authorization for Agents Constrained to Semantic Task-to-Scope Matching. arXiv preprint arXiv:2510.26702","author":"Helou Majed El","year":"2025","unstructured":"Majed El Helou, Chiara Troiani, Benjamin Ryder, Jean Diaconu, Herv\u00e9 Muyal, and Marcelo Yannuzzi. 2025. Delegated Authorization for Agents Constrained to Semantic Task-to-Scope Matching. arXiv preprint arXiv:2510.26702 (2025)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.acl-long.1435"},{"key":"e_1_3_2_1_13_1","unstructured":"Aixin Liu Aoxue Mei Bangcai Lin Bing Xue Bingxuan Wang Bingzheng Xu Bochao Wu Bowei Zhang Chaofan Lin Chen Dong et al. 2025. Deepseek-v3. 2: Pushing the frontier of open large language models. arXiv preprint arXiv:2512.02556 (2025)."},{"key":"e_1_3_2_1_14_1","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng et al. 2023. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499 (2023)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2404.11584"},{"key":"e_1_3_2_1_16_1","unstructured":"Mirko Montanari Hamid Palangi Lesly Miculicich Mihir Parmar Tomas Pfister Long Le and Dj Dvijotham. 2025. VeriGuard: Enhancing LLM Agent Safety via Verified Code Generation. https:\/\/arxiv.org\/pdf\/2510.05156"},{"key":"e_1_3_2_1_17_1","unstructured":"Aaditya Singh Adam Fry Adam Perelman Adam Tart Adi Ganesh Ahmed El-Kishky Aidan McLaughlin Aiden Low AJ Ostrow Akhila Ananthram et al. 2025. Openai GPT-5 System Card. arXiv preprint arXiv:2601.03267 (2025)."},{"key":"e_1_3_2_1_18_1","unstructured":"An Yang Anfeng Li Baosong Yang Beichen Zhang Binyuan Hui Bo Zheng Bowen Yu Chang Gao Chengen Huang Chenxu Lv et al. 2025. Qwen3 technical report. arXiv preprint arXiv:2505.09388 (2025)."},{"key":"e_1_3_2_1_19_1","volume-title":"The Thirteenth International Conference on Learning Representations, ICLR 2025","author":"Zhang Hanrong","year":"2025","unstructured":"Hanrong Zhang, Jingyuan Huang, Kai Mei, Yifei Yao, Zhenting Wang, Chenlu Zhan, Hongwei Wang, and Yongfeng Zhang. 2025. Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents. In The Thirteenth International Conference on Learning Representations, ICLR 2025, Singapore, April 24\u201328, 2025. OpenReview.net. https:\/\/openreview.net\/forum?id=V4y0CpX4hK"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3663529.3663786"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695001"},{"key":"e_1_3_2_1_22_1","unstructured":"Quan Zhang Chijin Zhou Gwihwan Go Binqi Zeng Heyuan Shi Zichen Xu and Yu Jiang. 2026. Agent-GrantBox. https:\/\/github.com\/ZQ-Struggle\/Agent-GrantBox."}],"event":{"name":"FSE Companion '26: 34th ACM International Conference on the Foundations of Software Engineering","location":"Concordia University Montreal QC Canada","acronym":"FSE Companion '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803437.3805554","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:34:15Z","timestamp":1784298855000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803437.3805554"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,5]]},"references-count":22,"alternative-id":["10.1145\/3803437.3805554","10.1145\/3803437"],"URL":"https:\/\/doi.org\/10.1145\/3803437.3805554","relation":{},"subject":[],"published":{"date-parts":[[2026,7,5]]},"assertion":[{"value":"2026-07-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}