Skip to content

Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models

Jul 2026 · arXiv.org · Vol abs/2607.08282 · 0 citations · 30 references
Computer Science

TL;DR

An open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions and its layered architecture enables deployment across heterogeneous environments, allowing organizations to balance computational cost, detection depth and latency.

Abstract

While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks. This paper proposes an open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions. The architecture combines a browser extension and a proxy for total traffic interception across both HTTP(S) and WebSocket communications. At its core, a flexible multi-agent pipeline delivers data leakage prevention through a hybrid approach combining deterministic detectors with LLM-driven semantic analysis, proprietary code leakage prevention, and extensible components designed for future security enhancements such as prompt injection evasion. The framework's layered architecture enables deployment across heterogeneous environments, allowing organizations to balance computational cost, detection depth and latency. Evaluation results demonstrate it achieves F1 scores of up to 94.93% on optimal configurations.

View source

Similar papers

Open access Aug 2026

A Privacy-Preserving Middleware Architecture for Detecting Prompt Injection and Sensitive Data Exposure in Large-Language-Model Interactions

A privacy-preserving hybrid middleware architecture that enforces a local trust boundary as its primary design constraint that is model-agnostic, requires no retraining of the underlying LLM, and is compatible with black-box API deployments is proposed and evaluated.

Adam Ait Hsine, A. Arabo · 0 citations
Open access Jul 2026

Tool Calling Behind the Curtain: Secure Function Execution for Agentic LLMs Inside Confidential VMs

Confidential MCP is presented, a set of backward-compatible extensions to MCP that enable standardized, auditable tool calling within and across TEE boundaries and introduces a three-zone enclave-partitioned server topology, a programmable Anonymization Transform Layer (ATL) with formal parameter classification and ent...

Ankur Aggarwal · 0 citations
Jul 2026

Hybrid Analysis for Secure MCP Tool Use in LLM Agents

MTGuard is proposed, a hybrid analysis-based defense framework designed to safeguard the use of MCP tools in LLM agents by leveraging lifecycle-aware static-dynamic co-analysis and effectively mitigates multiple categories of harmful tool use across different LLM agents while maintaining performance on benign user task...

Ping He, Yuexiang Xie, Yaliang Li et al. · 0 citations
Open access Aug 2026

Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection

This study designs a comprehensive testbed and a layered defense, Spotlight-Guard, that combines spotlighting-based input isolation, an LLM detection-and-quarantine pipeline, and instruction integrity based on a Hash-based Message Authentication Code into a single framework, and it is evaluated jointly along two axes:...

Doygun Demirol, Murat Aydoğan · 0 citations
Conference Open access Jun 2026

AEGIS: Preventing Cross-Domain Resource Abuse in MCP

AEGIS is presented, a policy enforcement component that enables administrators to define fine-grained safeguards against resource abuse across heterogeneous MCP tools and modalities and detects and mitigates abusive behaviors while preserving the flexibility of MCP-based agent ecosystems.

S. Priya, Teryl Taylor, Frederico Araujo · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.