%PDF-1.7
%
1 0 obj
<< /Metadata 3 0 R /Names 4 0 R /OpenAction 5 0 R /Outlines 6 0 R /PageMode /UseOutlines /Pages 7 0 R /Type /Catalog >>
endobj
2 0 obj
<< /Author (Aashish Kolluri; Rishi Sharma; Manuel Costa; Boris Kpf; Tobias Nieen; Mark Russinovich; Shruti Tople; Santiago Zanella-Bguelin) /Creator (arXiv GenPDF \(tex2pdf:57610bf\)) /DOI (https://doi.org/10.48550/arXiv.2602.11416) /License (http://creativecommons.org/licenses/by/4.0/) /PTEX.Fullbanner (This is pdfTeX, Version 3.141592653-2.6-1.40.28 \(TeX Live 2025\) kpathsea version 6.4.1) /Producer (pikepdf 8.15.1) /Title (Optimizing Agent Planning for Security and Autonomy) /Trapped /False /arXivID (https://arxiv.org/abs/2602.11416v1) >>
endobj
3 0 obj
<< /Subtype /XML /Type /Metadata /Length 1797 >>
stream
Optimizing Agent Planning for Security and AutonomyAashish KolluriRishi SharmaManuel CostaBoris KöpfTobias NießenMark RussinovichShruti TopleSantiago Zanella-Béguelinhttp://creativecommons.org/licenses/by/4.0/cs.CRcs.LG
endstream
endobj
4 0 obj
<< /Dests 8 0 R >>
endobj
5 0 obj
<< /D [ 9 0 R /Fit ] /S /GoTo >>
endobj
6 0 obj
<< /Count 14 /First 10 0 R /Last 11 0 R /Type /Outlines >>
endobj
7 0 obj
<< /Count 33 /Kids [ 12 0 R 13 0 R 14 0 R 15 0 R 16 0 R 17 0 R ] /Type /Pages >>
endobj
8 0 obj
<< /Kids [ 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R ] /Limits [ (Doc-Start) (table.7) ] >>
endobj
9 0 obj
<< /Annots [ 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R 29 0 R 30 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R 37 0 R 38 0 R 39 0 R 40 0 R 41 0 R 42 0 R 43 0 R 44 0 R 45 0 R 46 0 R 47 0 R 48 0 R 49 0 R 50 0 R 51 0 R 52 0 R 53 0 R 54 0 R 55 0 R 56 0 R 57 0 R 58 0 R 59 0 R 60 0 R 61 0 R 62 0 R ] /Contents [ 63 0 R 64 0 R 65 0 R 66 0 R ] /MediaBox [ 0 0 612 792 ] /Parent 12 0 R /Resources 67 0 R /Type /Page >>
endobj
10 0 obj
<< /A 68 0 R /Next 69 0 R /Parent 6 0 R /Title 70 0 R >>
endobj
11 0 obj
<< /A 71 0 R /Parent 6 0 R /Prev 72 0 R /Title 73 0 R >>
endobj
12 0 obj
<< /Count 6 /Kids [ 9 0 R 74 0 R 75 0 R 76 0 R 77 0 R 78 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
13 0 obj
<< /Count 6 /Kids [ 79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
14 0 obj
<< /Count 6 /Kids [ 85 0 R 86 0 R 87 0 R 88 0 R 89 0 R 90 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
15 0 obj
<< /Count 6 /Kids [ 91 0 R 92 0 R 93 0 R 94 0 R 95 0 R 96 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
16 0 obj
<< /Count 6 /Kids [ 97 0 R 98 0 R 99 0 R 100 0 R 101 0 R 102 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
17 0 obj
<< /Count 3 /Kids [ 103 0 R 104 0 R 105 0 R ] /Parent 7 0 R /Type /Pages >>
endobj
18 0 obj
<< /Kids [ 106 0 R 107 0 R 108 0 R 109 0 R 110 0 R 111 0 R ] /Limits [ (Doc-Start) (cite.denning1976lattice) ] >>
endobj
19 0 obj
<< /Kids [ 112 0 R 113 0 R 114 0 R 115 0 R 116 0 R 117 0 R ] /Limits [ (cite.dualLLM2023) (page.1) ] >>
endobj
20 0 obj
<< /Kids [ 118 0 R 119 0 R 120 0 R 121 0 R 122 0 R 123 0 R ] /Limits [ (page.10) (section*.12) ] >>
endobj
21 0 obj
<< /Kids [ 124 0 R 125 0 R 126 0 R 127 0 R 128 0 R 129 0 R ] /Limits [ (section*.13) (table.6) ] >>
endobj
22 0 obj
<< /Kids [ 130 0 R ] /Limits [ (table.7) (table.7) ] >>
endobj
23 0 obj
<< /A << /D (cite.anthropic2025research) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 403.382 258.514 445.773 269.458 ] /Subtype /Link /Type /Annot >>
endobj
24 0 obj
<< /A << /D (cite.anthropic2025research) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 448.865 258.514 470.783 269.458 ] /Subtype /Link /Type /Annot >>
endobj
25 0 obj
<< /A << /D (cite.openai2025deep) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 474.154 258.514 508.236 269.458 ] /Subtype /Link /Type /Annot >>
endobj
26 0 obj
<< /A << /D (cite.openai2025deep) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 511.328 258.514 538.227 269.458 ] /Subtype /Link /Type /Annot >>
endobj
27 0 obj
<< /A << /D (cite.perplexity2025deep) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 71.004 245.423 113.803 256.367 ] /Subtype /Link /Type /Annot >>
endobj
28 0 obj
<< /A << /D (cite.perplexity2025deep) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 117.197 245.423 144.096 256.367 ] /Subtype /Link /Type /Annot >>
endobj
29 0 obj
<< /A << /D (cite.openai2025agent) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 271.225 245.423 305.307 256.367 ] /Subtype /Link /Type /Annot >>
endobj
30 0 obj
<< /A << /D (cite.openai2025agent) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 308.701 245.423 335.042 256.367 ] /Subtype /Link /Type /Annot >>
endobj
31 0 obj
<< /A << /D (cite.perplexity2025comet) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 338.716 245.423 381.515 256.367 ] /Subtype /Link /Type /Annot >>
endobj
32 0 obj
<< /A << /D (cite.perplexity2025comet) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 384.909 245.423 411.25 256.367 ] /Subtype /Link /Type /Annot >>
endobj
33 0 obj
<< /A << /D (cite.openai2025operator) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 414.924 245.423 449.006 256.367 ] /Subtype /Link /Type /Annot >>
endobj
34 0 obj
<< /A << /D (cite.openai2025operator) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 452.4 245.423 478.741 256.367 ] /Subtype /Link /Type /Annot >>
endobj
35 0 obj
<< /A << /D (cite.greshake2023youve) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 389.639 219.242 450.389 230.185 ] /Subtype /Link /Type /Annot >>
endobj
36 0 obj
<< /A << /D (cite.greshake2023youve) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 453.069 219.242 474.987 230.185 ] /Subtype /Link /Type /Annot >>
endobj
37 0 obj
<< /A << /D (cite.yi2023benchmarking) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 477.945 219.242 510.591 230.185 ] /Subtype /Link /Type /Annot >>
endobj
38 0 obj
<< /A << /D (cite.yi2023benchmarking) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 513.27 219.242 535.188 230.185 ] /Subtype /Link /Type /Annot >>
endobj
39 0 obj
<< /A << /D (cite.wallace2024hierarchy) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 433.959 161.399 489.724 172.342 ] /Subtype /Link /Type /Annot >>
endobj
40 0 obj
<< /A << /D (cite.wallace2024hierarchy) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 492.75 161.399 514.668 172.342 ] /Subtype /Link /Type /Annot >>
endobj
41 0 obj
<< /A << /D (cite.chen2025struq) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 517.973 161.399 540.996 172.342 ] /Subtype /Link /Type /Annot >>
endobj
42 0 obj
<< /A << /D (cite.chen2025struq) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 71.004 148.308 93.311 159.252 ] /Subtype /Link /Type /Annot >>
endobj
43 0 obj
<< /A << /D (cite.chen2025struq) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 97.248 148.308 123.589 159.252 ] /Subtype /Link /Type /Annot >>
endobj
44 0 obj
<< /A << /D (cite.yi2023benchmarking) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 242.823 148.308 277.983 159.252 ] /Subtype /Link /Type /Annot >>
endobj
45 0 obj
<< /A << /D (cite.yi2023benchmarking) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 281.92 148.308 303.838 159.252 ] /Subtype /Link /Type /Annot >>
endobj
46 0 obj
<< /A << /D (cite.TaskTracker) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 375.201 148.308 442.45 159.252 ] /Subtype /Link /Type /Annot >>
endobj
47 0 obj
<< /A << /D (cite.TaskTracker) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 446.387 148.308 468.305 159.252 ] /Subtype /Link /Type /Annot >>
endobj
48 0 obj
<< /A << /D (cite.jia2024taskshield) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 472.52 148.308 509.334 159.252 ] /Subtype /Link /Type /Annot >>
endobj
49 0 obj
<< /A << /D (cite.jia2024taskshield) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 513.27 148.308 535.188 159.252 ] /Subtype /Link /Type /Annot >>
endobj
50 0 obj
<< /A << /D (cite.zhan2025adaptive) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 351.303 135.217 395.466 146.161 ] /Subtype /Link /Type /Annot >>
endobj
51 0 obj
<< /A << /D (cite.zhan2025adaptive) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 398.375 135.217 420.292 146.161 ] /Subtype /Link /Type /Annot >>
endobj
52 0 obj
<< /A << /D (cite.nasr2025attackermovessecondstronger) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 423.48 135.217 465.979 146.161 ] /Subtype /Link /Type /Annot >>
endobj
53 0 obj
<< /A << /D (cite.nasr2025attackermovessecondstronger) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 468.888 135.217 490.806 146.161 ] /Subtype /Link /Type /Annot >>
endobj
54 0 obj
<< /A << /D (cite.fides2025) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 129.109 90.465 175.099 101.409 ] /Subtype /Link /Type /Annot >>
endobj
55 0 obj
<< /A << /D (cite.fides2025) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 177.81 90.465 199.728 101.409 ] /Subtype /Link /Type /Annot >>
endobj
56 0 obj
<< /A << /D (cite.zhong2025rtbas) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 202.718 90.465 252.027 101.409 ] /Subtype /Link /Type /Annot >>
endobj
57 0 obj
<< /A << /D (cite.zhong2025rtbas) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 254.738 90.465 276.656 101.409 ] /Subtype /Link /Type /Annot >>
endobj
58 0 obj
<< /A << /D (cite.debenedetti2025caml) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 279.646 90.465 351.081 101.409 ] /Subtype /Link /Type /Annot >>
endobj
59 0 obj
<< /A << /D (cite.debenedetti2025caml) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 353.792 90.465 375.71 101.409 ] /Subtype /Link /Type /Annot >>
endobj
60 0 obj
<< /A << /D (cite.wu2024systemleveldefenseindirectprompt) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 378.701 90.465 415.884 101.409 ] /Subtype /Link /Type /Annot >>
endobj
61 0 obj
<< /A << /D (cite.wu2024systemleveldefenseindirectprompt) /S /GoTo >> /Border [ 0 0 0 ] /C [ 0 1 0 ] /H /I /Rect [ 418.596 90.465 440.513 101.409 ] /Subtype /Link /Type /Annot >>
endobj
62 0 obj
<< /A << /S /URI /URI (https://arxiv.org/abs/2602.11416v1) >> /BS << /W 0 >> /NM (fitz-L0) /Rect [ 12 222.12 32 569.88 ] /Subtype /Link >>
endobj
63 0 obj
<< /Length 10 /Filter /FlateDecode >>
stream
x+ |
endstream
endobj
64 0 obj
<< /Filter /FlateDecode /Length 2855 >>
stream
xڽZIw8W6{{M~:N
P%n
RCQ:K
dZĽ|Z+\'qc+X%礩o5ڜɿ'Ŏؠ;YQ9Xk~Wl,|\Fv<}ۯ4~Gn_8d^.EڧBh3͌\{}NvzfK?F}7'KNRN걒;F ?Xd_O5 GyeDaɳ=)±#iG0
_SE/"t,Dhe7.8i'>;bo:H 'u#k9!{K8e3 n~$
6;P].cϾG֝px%^,IvRS'H8)AiXa*L"S&I=DH>\Iӄ! 0/U!ͮ^Ǫ3Пѵ9nu۶_,'Cr7}g/՜Q},
Y{Yچp0o
ͩyW̩wa{z0QJMpz'E)Yt3=҄nA|goEN3 Xѿ/.&PhEx'E`#@Y{Qc#H
|4ڻABdWT[.6rZuUvE6QhmvKĔ^MbKYց0,9LV܀2h9`U^h`:}ʍ=wVUզn;|p]f/57Ӫ6f;"+HM"JBvop+
lRGyN'fl6jgl28B
n玡^W"$},!t/45{E^Kp,g'D;و nFF/*{F9Ʈh[@=JUq0ݼŰh=c55@VY5yNVf]5m;h!Z46ޜ]Y$NuM{X?+6f4 ǓD'6= -˘:D楡`ca WE>@khYTKiY?K|=O×LU^ jUБ'] Pyz3*ďvW77?lG7ɟAR
5DMh
s0tG܇YspT0Rf7:0pd Z4vؾq@E٫˹ŠA-|cQ̰5D&4hSc ٱJn;js7 n)
F%<ݯI*;C0bgvUqȖD8ɖT=
~p`rFtȧff/<9n"v)^|U6dgUSL6E'Q:fǘ3"ƯUL! `fL-BfMA-5B o9\N^
ᩞLCO=Tr*rEScQe$8hЄ4v{k՚,S\1HՖ
<``6z#ĝZWP⍯ƻ'
UGL;L