{"id":"https://openalex.org/W4416258150","doi":"https://doi.org/10.1109/icmla66185.2025.00213","title":"LLMZ+: Contextual Prompt Whitelist Principles for Agentic LLMs","display_name":"LLMZ+: Contextual Prompt Whitelist Principles for Agentic LLMs","publication_year":2025,"publication_date":"2025-12-03","ids":{"openalex":"https://openalex.org/W4416258150","doi":"https://doi.org/10.1109/icmla66185.2025.00213"},"language":"en","primary_location":{"id":"doi:10.1109/icmla66185.2025.00213","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icmla66185.2025.00213","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Conference on Machine Learning and Applications (ICMLA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2509.18557","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5120403683","display_name":"Tom Pawelek","orcid":null},"institutions":[{"id":"https://openalex.org/I99041443","display_name":"Mississippi State University","ror":"https://ror.org/0432jq872","country_code":"US","type":"education","lineage":["https://openalex.org/I4210141039","https://openalex.org/I99041443"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Tom Pawelek","raw_affiliation_strings":["Mississippi State University,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Mississippi State University,Department of Computer Science","institution_ids":["https://openalex.org/I99041443"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5104028266","display_name":"Raj Patel","orcid":null},"institutions":[{"id":"https://openalex.org/I17301866","display_name":"University of Alabama","ror":"https://ror.org/03xrrjk67","country_code":"US","type":"education","lineage":["https://openalex.org/I17301866"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Raj Patel","raw_affiliation_strings":["The University of Alabama,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Alabama,Department of Computer Science","institution_ids":["https://openalex.org/I17301866"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5120355002","display_name":"Charlotte Crowell","orcid":null},"institutions":[{"id":"https://openalex.org/I17301866","display_name":"University of Alabama","ror":"https://ror.org/03xrrjk67","country_code":"US","type":"education","lineage":["https://openalex.org/I17301866"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Charlotte Crowell","raw_affiliation_strings":["The University of Alabama,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Alabama,Department of Computer Science","institution_ids":["https://openalex.org/I17301866"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Noorbakhsh Amiri Golilarz","orcid":null},"institutions":[{"id":"https://openalex.org/I17301866","display_name":"University of Alabama","ror":"https://ror.org/03xrrjk67","country_code":"US","type":"education","lineage":["https://openalex.org/I17301866"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Noorbakhsh Amiri Golilarz","raw_affiliation_strings":["The University of Alabama,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Alabama,Department of Computer Science","institution_ids":["https://openalex.org/I17301866"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074949168","display_name":"Sudip Mittal","orcid":"https://orcid.org/0000-0001-9151-8347"},"institutions":[{"id":"https://openalex.org/I17301866","display_name":"University of Alabama","ror":"https://ror.org/03xrrjk67","country_code":"US","type":"education","lineage":["https://openalex.org/I17301866"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sudip Mittal","raw_affiliation_strings":["The University of Alabama,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Alabama,Department of Computer Science","institution_ids":["https://openalex.org/I17301866"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009452693","display_name":"Shahram Rahimi","orcid":"https://orcid.org/0000-0003-2779-0076"},"institutions":[{"id":"https://openalex.org/I17301866","display_name":"University of Alabama","ror":"https://ror.org/03xrrjk67","country_code":"US","type":"education","lineage":["https://openalex.org/I17301866"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shahram Rahimi","raw_affiliation_strings":["The University of Alabama,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Alabama,Department of Computer Science","institution_ids":["https://openalex.org/I17301866"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5120549894","display_name":"Andy Perkins","orcid":null},"institutions":[{"id":"https://openalex.org/I99041443","display_name":"Mississippi State University","ror":"https://ror.org/0432jq872","country_code":"US","type":"education","lineage":["https://openalex.org/I4210141039","https://openalex.org/I99041443"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Andy Perkins","raw_affiliation_strings":["Mississippi State University,Department of Computer Science"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Mississippi State University,Department of Computer Science","institution_ids":["https://openalex.org/I99041443"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5120403683"],"corresponding_institution_ids":["https://openalex.org/I99041443"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.17750888,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1396","last_page":"1402"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.1940000057220459,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.1940000057220459,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.15680000185966492,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.15049999952316284,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/counterintuitive","display_name":"Counterintuitive","score":0.42980000376701355},{"id":"https://openalex.org/keywords/empirical-evidence","display_name":"Empirical evidence","score":0.397599995136261},{"id":"https://openalex.org/keywords/selection","display_name":"Selection (genetic algorithm)","score":0.3896999955177307},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.3817000091075897},{"id":"https://openalex.org/keywords/silver-bullet","display_name":"Silver bullet","score":0.37770000100135803},{"id":"https://openalex.org/keywords/nondeterministic-algorithm","display_name":"Nondeterministic algorithm","score":0.3734000027179718},{"id":"https://openalex.org/keywords/cheating","display_name":"Cheating","score":0.3244999945163727},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.32420000433921814},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.31360000371932983}],"concepts":[{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7085999846458435},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.579200029373169},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.5543000102043152},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.5101000070571899},{"id":"https://openalex.org/C101097943","wikidata":"https://www.wikidata.org/wiki/Q5176983","display_name":"Counterintuitive","level":2,"score":0.42980000376701355},{"id":"https://openalex.org/C166052673","wikidata":"https://www.wikidata.org/wiki/Q83021","display_name":"Empirical evidence","level":2,"score":0.397599995136261},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.3896999955177307},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.3817000091075897},{"id":"https://openalex.org/C2776088982","wikidata":"https://www.wikidata.org/wiki/Q841402","display_name":"Silver bullet","level":2,"score":0.37770000100135803},{"id":"https://openalex.org/C176181172","wikidata":"https://www.wikidata.org/wiki/Q3490301","display_name":"Nondeterministic algorithm","level":2,"score":0.3734000027179718},{"id":"https://openalex.org/C2778024590","wikidata":"https://www.wikidata.org/wiki/Q2357432","display_name":"Cheating","level":2,"score":0.3244999945163727},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.32420000433921814},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.31360000371932983},{"id":"https://openalex.org/C32896092","wikidata":"https://www.wikidata.org/wiki/Q189447","display_name":"Risk management","level":2,"score":0.30730000138282776},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.30709999799728394},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3059000074863434},{"id":"https://openalex.org/C60643870","wikidata":"https://www.wikidata.org/wiki/Q1949683","display_name":"Deterrence theory","level":2,"score":0.2847000062465668},{"id":"https://openalex.org/C51110983","wikidata":"https://www.wikidata.org/wiki/Q16503490","display_name":"Overconfidence effect","level":2,"score":0.2824999988079071},{"id":"https://openalex.org/C154908896","wikidata":"https://www.wikidata.org/wiki/Q2167404","display_name":"Security policy","level":2,"score":0.2815000116825104},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.2800999879837036},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.2773999869823456},{"id":"https://openalex.org/C139807058","wikidata":"https://www.wikidata.org/wiki/Q352374","display_name":"Adaptation (eye)","level":2,"score":0.2743000090122223},{"id":"https://openalex.org/C114869243","wikidata":"https://www.wikidata.org/wiki/Q133735","display_name":"Security through obscurity","level":5,"score":0.2703999876976013},{"id":"https://openalex.org/C89611455","wikidata":"https://www.wikidata.org/wiki/Q6804646","display_name":"Mechanism (biology)","level":2,"score":0.26489999890327454},{"id":"https://openalex.org/C17520342","wikidata":"https://www.wikidata.org/wiki/Q7797190","display_name":"Threat","level":5,"score":0.263700008392334},{"id":"https://openalex.org/C2776788033","wikidata":"https://www.wikidata.org/wiki/Q320769","display_name":"Eavesdropping","level":2,"score":0.2632000148296356},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.25999999046325684},{"id":"https://openalex.org/C2777230681","wikidata":"https://www.wikidata.org/wiki/Q7923820","display_name":"Vetting","level":2,"score":0.257099986076355}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/icmla66185.2025.00213","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icmla66185.2025.00213","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Conference on Machine Learning and Applications (ICMLA)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2509.18557","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.18557","pdf_url":"https://arxiv.org/pdf/2509.18557","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2509.18557","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2509.18557","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2509.18557","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.18557","pdf_url":"https://arxiv.org/pdf/2509.18557","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Compared":[0],"to":[1,19,63,71,136,160,242],"traditional":[2,118],"models,":[3],"agentic":[4,44,140,221],"AI":[5,53],"represents":[6],"a":[7,34,40,56],"highly":[8],"valuable":[9],"target":[10],"for":[11,182],"potential":[12],"attackers":[13],"as":[14,103],"they":[15],"possess":[16],"privileged":[17],"access":[18],"data":[20],"sources":[21],"and":[22,75,89,131,156,164,177,212,219,232],"API":[23],"tools,":[24],"which":[25,115,238],"are":[26,134,209],"traditionally":[27],"not":[28,210],"incorporated":[29],"into":[30],"classical":[31],"agents.":[32],"Unlike":[33],"typical":[35],"software":[36],"application":[37],"residing":[38],"in":[39,244],"Demilitarized":[41],"Zone":[42],"(DMZ),":[43],"LLMs":[45],"consciously":[46],"rely":[47,83],"on":[48,84],"nondeterministic":[49],"behavior":[50],"of":[51,86,146,227,237],"the":[52,60,94,139,144,157,170,179,197,203,220,225],"(only":[54],"defining":[55],"final":[57],"goal,":[58],"leaving":[59],"path":[61],"selection":[62],"LLM).":[64],"This":[65],"characteristic":[66],"introduces":[67],"substantial":[68],"security":[69,74,171],"risk":[70],"both":[72,236],"operational":[73,165],"information":[76,185],"security.":[77,186],"Most":[78],"common":[79,199],"existing":[80],"defense":[81],"mechanism":[82],"detection":[85],"malicious":[87],"intent":[88],"preventing":[90],"it":[91],"from":[92],"reaching":[93],"LLM":[95,158,184],"agent,":[96],"thus":[97],"protecting":[98],"against":[99,196],"jailbreak":[100,200],"attacks":[101],"such":[102],"prompt":[104,123],"injection.":[105],"In":[106],"this":[107,126],"paper,":[108],"we":[109],"present":[110],"an":[111],"alternative":[112],"approach,":[113],"LLMZ+,":[114],"moves":[116],"beyond":[117],"detection-based":[119],"approaches":[120],"by":[121],"implementing":[122],"whitelisting.":[124],"Through":[125],"method,":[127],"only":[128],"contextually":[129],"appropriate":[130],"safe":[132],"messages":[133],"permitted":[135],"interact":[137],"with":[138],"LLM.":[141,222],"By":[142],"leveraging":[143],"specificity":[145],"context,":[147],"LLMZ+":[148,192],"guarantees":[149],"that":[150,191],"all":[151],"exchanges":[152],"between":[153,217],"external":[154],"users":[155,218],"conform":[159],"predefined":[161],"use":[162],"cases":[163],"boundaries.":[166],"Our":[167,187],"approach":[168,228],"streamlines":[169],"framework,":[172],"enhances":[173],"its":[174],"long-term":[175],"resilience,":[176],"reduces":[178],"resources":[180],"required":[181],"sustaining":[183],"empirical":[188],"evaluation":[189],"demonstrates":[190],"provides":[193],"strong":[194],"resilience":[195],"most":[198],"prompts.":[201],"At":[202],"same":[204],"time,":[205],"legitimate":[206],"business":[207],"communications":[208],"disrupted,":[211],"authorized":[213],"traffic":[214],"flows":[215],"seamlessly":[216],"We":[223],"measure":[224],"effectiveness":[226],"using":[229],"false":[230,233],"positive":[231],"negative":[234],"rates,":[235],"can":[239],"be":[240],"reduced":[241],"0":[243],"our":[245],"experimental":[246],"setting.":[247]},"counts_by_year":[],"updated_date":"2026-05-04T08:30:34.212998","created_date":"2025-10-10T00:00:00"}
