Related Work Notes
Deck use: tutorial notes for highlighted SoK refs
Real world refs
54: GitHub MCP 13: browser banking 112 and 117: exfiltration 115 and 98: logs chats keys credentials 88: RCE 127: package hallucination
Input trust refs
82: DataSentinel 17: StruQ 18: SecAlign 12: design patterns 46: allowlists
Runtime policy refs
122: Progent 132: Conseca 84: Agrail 146: GuardAgent 20: ShieldAgent 85 and 89: generated artifact checks
Flow control refs
32, 92, 95: classical IFC and taint tracking 60: PFI 29: CaMeL 26: FIDES 124: permissive IFC 160: MELON 69 and 142: related designs
Isolation and formal refs
11: AirGapAgent 144: IsolateGPT 113: RBAC 75: Formal LLM
Retrieval and monitoring refs
157: Honeybee 149: ControlNet 93: AgentMonitor 83: AgentAuditor 51: SentinelAgent 159: Guardian 140 and 152: distributed harm
Tool lifecycle ref
33: ETDI
Priority for deeper slides
- 29 CaMeL
- 26 FIDES
- 122 Progent and 132 Conseca
- 160 MELON
- 11 AirGapAgent and 144 IsolateGPT
- 82 DataSentinel, 17 StruQ, 18 SecAlign
- 20 ShieldAgent and 75 Formal LLM
- 157 Honeybee and 149 ControlNet
Teaching reminders
Use a running browser or email example Prefer action traces Mark trusted versus untrusted Mark secret versus public Mark allowed versus blocked Do not imply the SoK validates every defense experimentally