跳到正文
arXiv:cs.AI· Jinhao Zhu, Xiao Huang, Kevin Tseng, Gil Vernik, Shishir G. Patil, Vivian Fang, Raluca Ada Popa·· 6 小时前AI 评分54

MiniScope:用最小权限授权 AI Agent 的端到端权限系统

MiniScope: Authorizing Agents with Least-Privilege Permissions

AI 导读

论文提出 MiniScope,一个面向 AI Agent 的端到端权限系统,采用任务中心的分层权限模型,把 Agent 视为在任务特定角色内运作的委托方,自动发现权限层级并在运行时执行上下文最小权限。

正文

View PDF HTML (experimental)

Abstract:AI agents are increasingly granted autonomous access to sensitive user data and third-party services, making effective permission management a critical security challenge. Existing permission models, however, typically rely on flat permission structures that fail to balance security with usability: fine-grained confirmation induces user fatigue, while coarse-grained or persistent approval leads to overprivileged agents. To address this tradeoff, we propose a task-centric, hierarchical permission model that treats an agent as a delegate operating within a task-specific role instead of requiring a separate permission decision for every tool call. Building on this model, we present MiniScope, an end-to-end permission system for agents that automates permission-hierarchy discovery and enforces contextual least privilege at runtime. Our evaluation shows that MiniScope reduces simulated permission confirmations by 43.4%-89.4% for cautious and typical personas relative to per-tool prompting and mitigates all privilege-escalation attacks with negligible impact on utility and runtime. Applied to real-world deployments, MiniScope further uncovers six overprivileged connector configurations in ChatGPT and Claude.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2512.11147 [cs.CR]
  (or arXiv:2512.11147v2 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2512.11147

arXiv-issued DOI via DataCite

Submission history

From: Jinhao Zhu [view email]
[v1] Thu, 11 Dec 2025 22:10:39 UTC (2,269 KB)
[v2] Tue, 6 Oct 2026 07:56:06 UTC (2,011 KB)

来源:arXiv:cs.AI · arxiv.org