ViqusViqus
Navigate
Company
Blog
About Us
Contact
System Status
Enter Viqus Hub

New OpenAPPA Engine Achieves Zero Attacks in Agent Security Benchmarks

Agent Security Prompt Injection Data Governance LLM Agents Information Flow Control Open Source
October 03, 2026
Source: InfoQ AI

This summary and analysis were generated by AI from the original article at InfoQ AI and may contain errors (how Viqus works). Read the source for full details.

Viqus Verdict Logo Viqus Verdict Logo 8
Architectural Fix for Agentic Risk
Media Hype 6/10
Real Impact 8/10

Article Summary

Archestra has unveiled OpenAPPA, an open-source security engine designed to mitigate data exfiltration risks inherent in LLM agents, particularly those arising from prompt injection or hallucination. Unlike existing methods that rely on the LLM itself for policy judging, OpenAPPA operates externally, enforcing deterministic security rules based on defined data sources, audiences, and trust levels. The engine utilizes an Agentic Permissions Policy Algebra (APPA) to manage complex data flow constraints. Testing against rigorous benchmarks like Bench-Corp and AgentThreatBench, OpenAPPA reported a 0% attack success rate while maintaining high utility. This performance significantly outperforms models like Claude Code's auto mode (10% attack rate) and Microsoft FIDES (31% attack rate), addressing the critical industry tension between strict security and operational usability.

Key Points

  • OpenAPPA functions as an external security layer, executing policy enforcement outside the LLM's prompt and execution loop to prevent bypass.
  • The system uses an Agentic Permissions Policy Algebra (APPA) to manage data flow by tracking audience and trust levels across tool calls.
  • It demonstrated superior security by achieving a 0% attack success rate on major industry benchmarks compared to leading commercial models.

Why It Matters

This represents a crucial architectural advancement in making LLM agents enterprise-ready. The core problem in agentic AI is that the LLM itself is the attack surface; OpenAPPA tackles this by enforcing security via an external, deterministic policy engine. This shifts the paradigm from 'trusting the model to police itself' to 'enforcing policy externally,' which is a necessary step for high-stakes, multi-step enterprise automation.

You might also be interested in