FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Tue 7 Jul 2026 14:30 - 14:40 at MB 3.270 - Agents Chair(s): Michael Pradel

Equipping LLM agents with real-world tools significantly boosts productivity. However, transferring tool-use autonomy to agents also implicitly transfers associated privilege to the agent and the underlying LLM. The improper usage of these privileges can pose severe risks, including information leakage and infrastructural damage. While several benchmarks have been built to study agents’ security, they often rely on pre-coded tools and restricted interaction patterns. Such crafted environments differ substantially from the real-world, making it hard to assess agents’ security capabilities in critical privilege control and usage. Therefore, we propose GrantBox, a security evaluation sandbox specifically designed for analyzing agent privilege usage. By automatically integrating real-world tools and allowing LLMs to invoke genuine privileges, GrantBox assesses agents’ privilege usage under prompt injection attacks. Our results indicate that while LLMs exhibit basic security awareness and can block some direct attacks, they remain vulnerable to more sophisticated attacks, resulting in an average attack success rate of 84.80% in carefully crafted scenarios.

Tue 7 Jul

Displayed time zone: Eastern Time (US & Canada) change

14:00 - 15:30
AgentsIdeas, Visions and Reflections / Industry Papers / Research Papers at MB 3.270
Chair(s): Michael Pradel CISPA Helmholtz Center for Information Security
14:00
20m
Talk
RocketMQ-A2A: Reliable Session-Level Replayable Event Streams for Large-Scale Multi-Agent Collaboration
Industry Papers
Li Zhou Alibaba Cloud Computing, Shuo Zhang Alibaba Cloud Computing, Juntao Ji Alibaba Cloud Computing Co. Ltd., Shijie Zhang Alibaba Cloud Computing, Ke Zhao Alibaba Cloud Computing, Yubao Fu Alibaba Cloud Computing Co. Ltd., Qingshan Lin Alibaba Cloud Computing Co. Ltd.
14:20
10m
Talk
AgentReputation: A Decentralized Agentic AI Reputation Framework
Ideas, Visions and Reflections
Mohd Sameen Chishti Norwegian University of Science and Technology NTNU, Damilare Peter Oyinloye Norwegian University of Science and Technology, Jingyue Li Norwegian University of Science and Technology (NTNU)
14:30
10m
Talk
Evaluating Privilege Usage of Agents on Real-World Tools
Ideas, Visions and Reflections
Quan Zhang East China Normal University, Lianhang Fu School of Software, Xinjiang University, Lvsi Lian East China Normal University, Gwihwan Go Tsinghua University, YujueWang Tsinghua University, Chijin Zhou East China Normal University, Yu Jiang Tsinghua University, Geguang Pu East China Normal University, China
14:40
20m
Talk
AgentBound: Securing Execution Boundaries of AI Agents
Research Papers
Christoph Buehler University of St. Gallen, Matteo Biagiola University of St. Gallen and Università della Svizzera italiana, Luca Di Grazia University of St. Gallen, Guido Salvaneschi University of St. Gallen
Link to publication DOI Media Attached
15:00
10m
Talk
AIMS: A Content-Aware Resource Management Approach for AI Assistant Systems
Ideas, Visions and Reflections
Chiming Duan Peking University, Tong Jia Institute for Artificial Intelligence, Peking University, Beijing, China, Minghua He Peking University, Pei Xiao Peking University, Lingzhe Zhang Peking University, China, Zhewei Zhong Bytedance, Xin Zhang Bytedance, Ying Li School of Software and Microelectronics, Peking University, Beijing, China
15:10
20m
Talk
Reducing Cost of LLM Agents with Trajectory Reduction
Research Papers
Yuan-An Xiao Peking University, Pengfei Gao ByteDance, Chao Peng Tencent, Yingfei Xiong Peking University
Pre-print