{"id":"https://openalex.org/W7131379833","doi":"https://doi.org/10.48550/arxiv.2602.20064","title":"The LLMbda Calculus: AI Agents, Conversations, and Information Flow","display_name":"The LLMbda Calculus: AI Agents, Conversations, and Information Flow","publication_year":2026,"publication_date":"2026-02-23","ids":{"openalex":"https://openalex.org/W7131379833","doi":"https://doi.org/10.48550/arxiv.2602.20064"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2602.20064","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.20064","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2602.20064","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5106801627","display_name":"Zac Garby","orcid":"https://orcid.org/0009-0007-3441-3646"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Garby, Zac","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126801569","display_name":"Andrew D. Gordon","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gordon, Andrew D.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5126785009","display_name":"David Sands","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sands, David","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5106801627"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.3240000009536743,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.3240000009536743,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10126","display_name":"Logic, programming, and type systems","score":0.10289999842643738,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10142","display_name":"Formal Methods in Verification","score":0.09269999712705612,"subfield":{"id":"https://openalex.org/subfields/1703","display_name":"Computational Theory and Mathematics"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/conversation","display_name":"Conversation","score":0.6078000068664551},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.5716999769210815},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.47859999537467957},{"id":"https://openalex.org/keywords/planner","display_name":"Planner","score":0.4708999991416931},{"id":"https://openalex.org/keywords/confidentiality","display_name":"Confidentiality","score":0.4219000041484833},{"id":"https://openalex.org/keywords/operational-semantics","display_name":"Operational semantics","score":0.4099000096321106},{"id":"https://openalex.org/keywords/isolation","display_name":"Isolation (microbiology)","score":0.40860000252723694},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.39910000562667847},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.384799987077713},{"id":"https://openalex.org/keywords/formal-semantics","display_name":"Formal semantics (linguistics)","score":0.37119999527931213}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7351999878883362},{"id":"https://openalex.org/C2777200299","wikidata":"https://www.wikidata.org/wiki/Q52943","display_name":"Conversation","level":2,"score":0.6078000068664551},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.5716999769210815},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.47859999537467957},{"id":"https://openalex.org/C2776999362","wikidata":"https://www.wikidata.org/wiki/Q2349274","display_name":"Planner","level":2,"score":0.4708999991416931},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.4487999975681305},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.4219000041484833},{"id":"https://openalex.org/C156325763","wikidata":"https://www.wikidata.org/wiki/Q1930895","display_name":"Operational semantics","level":3,"score":0.4099000096321106},{"id":"https://openalex.org/C2775941552","wikidata":"https://www.wikidata.org/wiki/Q25212305","display_name":"Isolation (microbiology)","level":2,"score":0.40860000252723694},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.39910000562667847},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.38830000162124634},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.384799987077713},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3804999887943268},{"id":"https://openalex.org/C146499914","wikidata":"https://www.wikidata.org/wiki/Q5469969","display_name":"Formal semantics (linguistics)","level":2,"score":0.37119999527931213},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.367900013923645},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.34049999713897705},{"id":"https://openalex.org/C126042441","wikidata":"https://www.wikidata.org/wiki/Q1324888","display_name":"Frame (networking)","level":2,"score":0.3345000147819519},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.33000001311302185},{"id":"https://openalex.org/C2779136372","wikidata":"https://www.wikidata.org/wiki/Q10283002","display_name":"Information flow","level":2,"score":0.319599986076355},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.3176000118255615},{"id":"https://openalex.org/C53811970","wikidata":"https://www.wikidata.org/wiki/Q5062194","display_name":"Centrality","level":2,"score":0.3052999973297119},{"id":"https://openalex.org/C110251889","wikidata":"https://www.wikidata.org/wiki/Q1569697","display_name":"Model checking","level":2,"score":0.30309998989105225},{"id":"https://openalex.org/C2776240099","wikidata":"https://www.wikidata.org/wiki/Q327018","display_name":"Interrogation","level":2,"score":0.29660001397132874},{"id":"https://openalex.org/C2778029271","wikidata":"https://www.wikidata.org/wiki/Q5421931","display_name":"Extension (predicate logic)","level":2,"score":0.2921000123023987},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2782000005245209},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.272599995136261},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.2689000070095062},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.26739999651908875},{"id":"https://openalex.org/C161301231","wikidata":"https://www.wikidata.org/wiki/Q3478658","display_name":"Knowledge representation and reasoning","level":2,"score":0.2635999917984009},{"id":"https://openalex.org/C48859967","wikidata":"https://www.wikidata.org/wiki/Q6486712","display_name":"Language construct","level":2,"score":0.2624000012874603},{"id":"https://openalex.org/C195344581","wikidata":"https://www.wikidata.org/wiki/Q2555318","display_name":"Automated reasoning","level":2,"score":0.26030001044273376},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.2590999901294708},{"id":"https://openalex.org/C111498074","wikidata":"https://www.wikidata.org/wiki/Q173326","display_name":"Formal verification","level":2,"score":0.25760000944137573},{"id":"https://openalex.org/C207648694","wikidata":"https://www.wikidata.org/wiki/Q1189746","display_name":"Denotational semantics","level":4,"score":0.2558000087738037}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2602.20064","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.20064","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2602.20064","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.20064","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.7602631449699402}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"A":[0,57,199],"conversation":[1,63],"with":[2,15,40,108],"a":[3,9,34,50,62,85,113,125,133,141,148,210],"large":[4],"language":[5,123],"model":[6,139],"(LLM)":[7],"is":[8],"sequence":[10],"of":[11,79,116,186],"prompts":[12],"and":[13,43,52,94,112,143,157,175,189,205],"responses,":[14],"each":[16],"response":[17,146],"generated":[18,187],"from":[19],"the":[20,77,138,145,161],"preceding":[21],"conversation.":[22],"AI":[23],"agents":[24],"build":[25],"such":[26,80,181],"conversations":[27],"automatically:":[28],"given":[29],"an":[30,102,129,196],"initial":[31],"human":[32],"prompt,":[33,142],"planner":[35,155],"loop":[36],"interleaves":[37],"LLM":[38,197],"calls":[39],"tool":[41,70],"invocations":[42],"code":[44],"execution.":[45],"This":[46,151],"tight":[47],"coupling":[48],"creates":[49],"new":[51,149],"poorly":[53],"understood":[54],"attack":[55],"surface.":[56],"malicious":[58],"prompt":[59,165],"injected":[60],"into":[61],"can":[64,213],"compromise":[65],"later":[66],"reasoning,":[67],"trigger":[68],"dangerous":[69],"calls,":[71],"or":[72],"distort":[73],"final":[74],"outputs.":[75],"Despite":[76],"centrality":[78],"systems,":[81],"we":[82],"currently":[83],"lack":[84],"principled":[86],"semantic":[87],"foundation":[88],"for":[89,118,217],"reasoning":[90,178],"about":[91,179],"their":[92,158],"behaviour":[93],"safety.":[95],"We":[96],"address":[97],"this":[98],"gap":[99],"by":[100,163],"introducing":[101],"untyped":[103],"call-by-value":[104],"lambda":[105],"calculus":[106,152,212],"enriched":[107],"dynamic":[109],"information-flow":[110,190],"control":[111],"small":[114],"number":[115],"primitives":[117],"constructing":[119],"prompt-response":[120],"conversations.":[121],"Our":[122],"includes":[124],"primitive":[126],"that":[127,209],"invokes":[128],"LLM:":[130],"it":[131,136],"serializes":[132],"value,":[134],"sends":[135],"to":[137],"as":[140,147,182],"parses":[144],"term.":[150],"faithfully":[153],"represents":[154],"loops":[156],"vulnerabilities,":[159],"including":[160],"mechanisms":[162],"which":[164],"injection":[166],"alters":[167],"subsequent":[168],"computation.":[169],"The":[170],"semantics":[171],"explicitly":[172],"captures":[173],"conversations,":[174],"so":[176],"supports":[177],"defenses":[180],"quarantined":[183],"sub-conversations,":[184],"isolation":[185],"code,":[188],"restrictions":[191],"on":[192],"what":[193],"may":[194],"influence":[195],"call.":[198],"termination-insensitive":[200],"noninterference":[201],"theorem":[202],"establishes":[203],"integrity":[204],"confidentiality":[206],"guarantees,":[207],"demonstrating":[208],"formal":[211],"provide":[214],"rigorous":[215],"foundations":[216],"safe":[218],"agentic":[219],"programming.":[220]},"counts_by_year":[],"updated_date":"2026-02-26T06:34:08.959763","created_date":"2026-02-26T00:00:00"}
