Security Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offs
Zhuoxiang Shen, Jiarun Dai, Yuan Zhang, Min Yang
Abstract
The advantages of large language models (LLMs) in content comprehension and question answering have led to the rapid emergence of LLM agent. Developers across diverse domains are actively building their own agent applications (apps), as these apps can streamline workflows, boost efficiency, or deliver innovative solutions, thereby enhancing the competitiveness of their products. Agent apps are playing an increasingly important role in our daily lives. However, numerous serious vulnerabilities and security issues have been identified in these apps. To effectively manage future security risks, it is essential to systematically understand the unique characteristics of agent app vulnerabilities and their mitigation. In this paper, we present the first comprehensive study on the vulnerabilities of agent apps, the mitigation practices of app developers, and the associated challenges and trade-offs. We identify 14 types of vulnerabilities and 16 root causes across 7 components, based on an analysis of 221 real-world vulnerabilities. Our study further investigates developer reactions, evaluates the effectiveness of various mitigation strategies, and explores the practical challenges and inevitable trade-offs in vulnerability mitigation. Finally, we distill 12 key findings, discuss their implications for agent app developers, maintainers, and security researchers, and offer suggestions for future research directions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 85ec46a9-9eba-46fc-9a3d-1456eba46ba1Builds on8
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia et al.USENIX Security 2024 · 308 citations
- Identifying the Risks of LM Agents with an LM-Emulated SandboxYangjun Ruan, Honghua Dong, Andrew Wang, Silviu Pitis et al.ICLR 2024 · 292 citations
- Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based AgentsWenkai Yang, Xiaohan Bi, Yankai Lin, Sishuo Chen et al.NeurIPS 2024 · 195 citations
- Demystifying RCE Vulnerabilities in LLM-Integrated AppsTong Liu, Zizhuang Deng, Guozhu Meng, Yuekang Li et al.CCS 2024 · 19 citations
- Prompt-to-SQL Injections in LLM-Integrated Web Applications: Risks and DefensesRodrigo Pedro, Miguel E. Coimbra, Daniel Castro, Paulo Carreira et al.ICSE 2025 · 14 citations
Related papers
- SoK: Attack and Defense Landscape of Agentic AI SystemsJuhee Kim, Wenbo Guo, Dawn SongUSENIX Security 2026
- Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based AgentsFengyu Liu, Yuan Zhang, Jiaqi Luo, Jiarun Dai et al.USENIX Security 2025
- Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction AmplificationBoyang Zhang, Yicong Tan, Yun Shen, Ahmed Salem et al.EMNLP 2025 · 4 citations
- Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM AgentsZichuan Li, Jian Cui, Xiaojing Liao, Luyi XingNDSS 2026 · 24 citations
- AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use AgentsHaitao Hu, Peng Chen, Yanpeng Zhao, Yuqi ChenCCS 2025
