[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81595-en":3,"doc-seo-81595-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},81595,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","The LLMbda Calculus: AI Agents, Conversations, and Information Flow","Large language models are increasingly deployed as agents that plan, call tools, and act on untrusted data, but this enables prompt injection when readable data is treated as instructions. The work proposes LLMbda, an untyped call-by-value lambda calculus that expressively supports provenance-based defenses. It implements agentic operations as first-class constructs, including forkable prompt-response conversations and dynamic information-flow control with value labels propagated by reduction. The authors prove a termination-insensitive probabilistic noninterference theorem in the full calculus and validate it on the AgentDojo benchmark using Lean-verified code.","arXiv :2602 .20064v2 [ cs .PL] 10 Jul 2026  \nThe LLMbda Calculus  \nAI Agents, Conversations, and Information Flow  \nZAC GARBY, University of Nottingham, UK  \nANDREW D. GORDON, University of Edinburgh, UK  \nDAVID SANDS, Chalmers University of Technology and University of Gothenburg, Sweden  \nLarge language models are increasingly deployed as agents: they plan, call tools, read untrusted data, and acton the results. This exposes them to prompt injection: data meant only to be read is obeyed as an instruction. The most principled defences replace content inspection with provenance—classifying data by source and keeping trusted and untrusted apart through a separation of duty (the dual-LLM pattern) and information-flow control. Yet the leading systems are hard to fully trust: flow tracking is easy to get wrong at its boundaries; deliberate relaxations are hard to audit; and hard-wiring the dual-LLM pattern bakes isolation into the architecture as a fixed design choice. We present LLMbda, an untyped call-by-value lambda calculus that makes provenance-based defence both expressible and provably sound, without committing to an architecture. It adds the operational core of agentic systems as first-class constructs: prompt-response conversations that can be forked and cleared, code generation, and dynamic information-flow control in which every value carries a label that every reduction propagates. Isolation becomes a policy a program expresses, and reclassification an explicit, auditable construct. Our central result is a termination-insensitive probabilistic noninterference theorem over the whole calculus, including code-generating agents, together with an insulated variant that holds even when the attacker chooses all untrusted inputs. The verified interpreter is itself the harness that calls the model—to our knowledge, the first LLM agent harness whose executable is the subject of machine-checked security theorems—so every agent inherits the guarantee. On the AgentDojo banking benchmark, an agent built within LLMbda (enforcement always on) matches, within confidence intervals, the utility of CaMeL, a leading dual-LLM defence, run without its policy checks (enabling them halves CaMeL’s utility), and resists all but two of 1296 attacked runs—on a provably sound foundation. Our agent harness and all our proofs are in Lean.  \n1 Introduction  \nLarge language models are increasingly deployed as agents: they plan, call tools, read untrusted data from the web or a user’s inbox, and act on the results. This exposes them to prompt injection, where data the agent meant only to read is obeyed as an instruction [71] . The obvious defence is an arms race: inspecting each prompt for malicious content—with a classifier, or by asking the model whether an input “looks like” an attack—invites a fresh evasion for every detector, and guarantees nothing.  \nA more principled line of work has emerged that abandons content inspection in favour of provenance [18, 20, 72]: inputs are classified by their source as trusted or untrusted, and two mechanisms keep them apart. A separation of duty blocks attacker-controlled control flow; in Willison’s dual-LLM pattern [72], a privileged model (the P-LLM) plans and issues tool calls but never reads untrusted data directly, while a quarantined model (the Q-LLM) reads untrusted data but only returns values, never issuing a tool call of its own. Instead of the AI agent relying on a single conversation, the idea is to have separate conversations to prevent untrusted prompt messages from affecting later actions.  \nAuthors’ Contact Information: Zac Garby, University of Nottingham, Nottingham, UK; Andrew D. Gordon, University of Edinburgh, Edinburgh, UK; David Sands, Chalmers University of Technology and University of Gothenburg, Gothenburg, Sweden.  \n2 Zac Garby, Andrew D. Gordon, and David Sands  \nInformation-flow control (IFC) [22] blocks attacker-controlled data flow—it labels data by provenance and refuses it at sensi","cbCaiqi2CgV0Kkf5","https://ap.wps.com/l/cbCaiqi2CgV0Kkf5","pdf",1116876,4,1,63,"English","en",105,"# Introduction\n## Prompt injection and limitations of content inspection\n## Provenance-based defenses and dual-LLM separation of duty\n## Information-flow control background\n## Motivation: correctness challenges at boundaries\n## Example leaks at flow-tracking boundaries","[{\"question\":\"What problem does the document address for LLM-based agents?\",\"answer\":\"It addresses prompt injection, where untrusted data that an agent should only read is instead obeyed as an instruction, enabling malicious behavior.\"},{\"question\":\"How does LLMbda aim to defend against prompt injection?\",\"answer\":\"It replaces content inspection with provenance-based defense expressed in a calculus, using separation of duty concepts and dynamic information-flow control where every value carries a label that propagates through reductions.\"},{\"question\":\"What is the main theorem established by the authors?\",\"answer\":\"The central result is a termination-insensitive probabilistic noninterference theorem over the whole calculus, including code-generating agents, with an insulated variant covering attackers that choose all untrusted inputs.\"}]",1784174600,159,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"the-llmbda-calculus-ai-agents-conversations-and-information-flow","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/the-llmbda-calculus-ai-agents-conversations-and-information-flow/81595/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the document address for LLM-based agents?","Question",{"text":75,"@type":76},"It addresses prompt injection, where untrusted data that an agent should only read is instead obeyed as an instruction, enabling malicious behavior.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does LLMbda aim to defend against prompt injection?",{"text":80,"@type":76},"It replaces content inspection with provenance-based defense expressed in a calculus, using separation of duty concepts and dynamic information-flow control where every value carries a label that propagates through reductions.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the main theorem established by the authors?",{"text":84,"@type":76},"The central result is a termination-insensitive probabilistic noninterference theorem over the whole calculus, including code-generating agents, with an insulated variant covering attackers that choose all untrusted inputs.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]