Pokee AI whitepaper maps enterprise agent security
Pokee AI collaborated with researchers from UIUC and the University of Chicago to publish a 36-page whitepaper defining a threat landscape and hardened architecture for enterprise AI agents. The paper maps critical vulnerabilities across agent trajectories—including indirect prompt injection and tool composition risks—while introducing benchmark evaluations on Pokee-Isaac 28B that balance attack defense against benign task completion.
Securing autonomous enterprise agents requires moving past static input-output guardrails toward trajectory-level security, because the real danger lies in multi-step tool composition where models convert untrusted data into persistent enterprise actions.
- –Trajectory Over Event Security: Traditional web application firewalls and LLM guardrails inspect discrete prompts in isolation, but agent exploits often unfold across chained tool calls and cumulative context pollution that only trajectory-aware monitors can intercept.
- –Balancing Safety with Utility: Defenses that drastically lower Attack Success Rates (ASR) frequently cripple Benign Task Success (BSR); evaluating agent security relative to task completion ensures models don't merely achieve safety by refusing valid workflows.
- –Tool Composition Vulnerabilities: Granting autonomous agents access to enterprise APIs creates compounding permission surfaces, where low-privilege reads can be weaponized into destructive writes without hardened architectural isolation boundaries.
- –Benchmark Rigor via Pokee-Isaac: Testing against 6,200 multi-domain tasks in the DecodingTrust-Agent benchmark establishes an empirical standard for evaluating enterprise agent robustness instead of relying on subjective red-teaming claims.
DISCOVERED
48m ago
2026-09-24
PUBLISHED
1h ago
2026-09-24
RELEVANCE
AUTHOR
ZheqingZhu