Reshabh K Sharma

I am a PhD student at Paul G. Allen School of Computer Science & Engineering . I am advised by Professor Dan Grossman. I work at the intersection of Programming Languages (PL), Security, and LLMs. My research builds the infrastructure, specifications, and access-control mechanisms that make LLM-based software reliable, secure, and maintainable.

Securing and governing what an LLM-based system is allowed to do: An LLM agent acts with its user's authority over real tools, data, and web pages, so a single injected or adversarial instruction can turn that authority against the user. Rather than trusting the model to always behave, my work constrains it by construction. User-provided specifications capture how a system is supposed to behave and are enforced at runtime to detect deviations and filter malicious inputs, as in SPML and its extension to attacks hidden inside images. Complementing these defenses, least-privilege, task-scoped access control bounds which operations an agent may actually perform (AC4A, PAuth), and ClawDojo stress-tests such protections against realistic attacks.

Engineering LLM-based software to be reliable and maintainable. Prompts and agent instruction files are becoming programs, yet they lack the testing and regression infrastructure that traditional software takes for granted. Because model outputs are non-deterministic, a minor prompt edit can silently break behavior or introduce security risks. My work builds the missing infrastructure around specifications. PromptPex generates targeted tests from a prompt's specification, ContextCov turns natural-language instruction files into executable guardrails, and Willful Disobedience and Learning Correct Behavior from Examples detect when an agent deviates from its intended procedure.

Security & Access Control for LLM-Based Systems
Reshabh K Sharma, Dan Grossman. AC4A: Access Control for Agents. arXiv preprint arXiv:2603.20933 (2026). [arXiv] [GitHub]
Invited talk · Microsoft Research
Invited talk · Straiker Inc.
Blog · AI Models Need a Virtual Machine (SIGPLAN Blog, 2025)
Reshabh K Sharma, Linxi Jiang, Zhiqiang Lin, Shuo Chen. PAuth: Precise Task-Scoped Authorization for Agents. arXiv preprint arXiv:2603.17170 (2026). [arXiv]
Reshabh K Sharma, Linxi Jiang, Zhiqiang Lin, Shuo Chen. ClawDojo: A Dynamic and Extensible Framework for Evaluating Attacks and Defenses on OpenClaw. AgentSkills Workshop at ACM CAIS 2026. 🎤 Oral [OpenReview]
Reshabh K Sharma, Vinayak Gupta, Dan Grossman. SPML: A DSL for Defending Language Models Against Prompt Attacks. arXiv preprint arXiv:2402.11755 (2024). [arXiv]
Dataset · SPML Chatbot Prompt Injection Dataset (21,500+ downloads) [Hugging Face] [project page]
Reshabh K Sharma, Vinayak Gupta, Dan Grossman. Defending Language Models Against Image-Based Prompt Attacks via User-Provided Specifications. IEEE S&P Workshops (SAGAI), 2024. [IEEE] [PDF]
Software Engineering for LLM-Based Systems
Reshabh K Sharma, Jonathan De Halleux, Shraddha Barke, Dan Grossman, Benjamin Zorn. PromptPex: Automatic Test Generation for Language Model Prompts. arXiv preprint arXiv:2503.05070 (2025). [arXiv] [GitHub]
Selected talk · PNW PLSE 2025 [🎥 recording]
Invited talk · Uber Programming Systems Research Group
Invited talk · University of Utah, School of Computing
Blog · Prompts are Programs (SIGPLAN Blog, 2024)
Reshabh K Sharma. ContextCov: Deriving and Enforcing Executable Constraints from Agent Instruction Files. Agentic Software Engineering Workshop, ACM CAIS 2026. 🏆 Best Paper [arXiv]
Selected talk · PNW PLSE 2026 (Coding with Agents) [🎥 recording]
Reshabh K Sharma, Shraddha Barke, Benjamin Zorn. Willful Disobedience: Automatically Detecting Failures in Agentic Traces. ACM Conference on AI and Agentic Systems (CAIS), 2026. ⭐ Industry Spotlight [arXiv] [ACM] [GitHub]
Talk · CAIS 2026 [🎥 recording]
Reshabh K Sharma, Gaurav Mittal, Yu Hu. Learning Correct Behavior from Examples: Validating Sequential Execution in Autonomous Agents. arXiv preprint arXiv:2605.03159 (2026). [arXiv]
Systems, Compilers & Hardware Security
Reshabh K Sharma, Dan Grossman, David Kohlbrenner. SplittingSecrets: A Compiler-Based Defense for Preventing Data Memory-Dependent Prefetcher Side-Channels. Microarchitecture Security Conference (uASC), 2026. [arXiv] [GitHub]
Michael Flanders, Reshabh K Sharma, Alexandra E. Michael, Dan Grossman, David Kohlbrenner. Avoiding Instruction-Centric Microarchitectural Timing Channels via Binary-Code Transformations. ASPLOS, 2024. [ACM] [GitHub]
Selected LLVM talks & posters
Finding the cracks between the analysis. Fifth LLVM Performance Workshop at CGO 2021. [slides]
Integration of OpenMP, libc++ and libc++abi packages into the LLVM toolchain. 2018 LLVM Developers' Meeting (poster; GSoC 2018).
Blogs & RFCs