Related Work Notes

Deck use: tutorial notes for highlighted SoK refs

Real world refs

54: GitHub MCP 13: browser banking 112 and 117: exfiltration 115 and 98: logs chats keys credentials 88: RCE 127: package hallucination

Input trust refs

82: DataSentinel 17: StruQ 18: SecAlign 12: design patterns 46: allowlists

Runtime policy refs

122: Progent 132: Conseca 84: Agrail 146: GuardAgent 20: ShieldAgent 85 and 89: generated artifact checks

Flow control refs

32, 92, 95: classical IFC and taint tracking 60: PFI 29: CaMeL 26: FIDES 124: permissive IFC 160: MELON 69 and 142: related designs

Isolation and formal refs

11: AirGapAgent 144: IsolateGPT 113: RBAC 75: Formal LLM

Retrieval and monitoring refs

157: Honeybee 149: ControlNet 93: AgentMonitor 83: AgentAuditor 51: SentinelAgent 159: Guardian 140 and 152: distributed harm

Tool lifecycle ref

33: ETDI

Priority for deeper slides

  1. 29 CaMeL
  2. 26 FIDES
  3. 122 Progent and 132 Conseca
  4. 160 MELON
  5. 11 AirGapAgent and 144 IsolateGPT
  6. 82 DataSentinel, 17 StruQ, 18 SecAlign
  7. 20 ShieldAgent and 75 Formal LLM
  8. 157 Honeybee and 149 ControlNet

Teaching reminders

Use a running browser or email example Prefer action traces Mark trusted versus untrusted Mark secret versus public Mark allowed versus blocked Do not imply the SoK validates every defense experimentally