Policy dependency / Threat pattern
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Policy dependency / Stack layer
Python's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or Critical
arXiv 2609.14791
Stack layer / Contrast
Emergence World ran 10 agents per world for 16 days and found no frontier model contained an injected attack — one acted on poisoned memory 46 hours later
arXiv
Stack layer / Threat pattern
MemRiskBench Scores Long-Horizon Agent Memory Risks Deterministically, With No LLM Judge on the Pass/Fail Path
arXiv 2609.14976
Stack layer / Follow-up thread
Planting Benign-Sounding Reasoning in an Agent's Context Evades Chain-of-Thought Monitors 25-33% of the Time
arXiv 2609.15989
Stack layer / Contrast
Adding more open models to a multi-agent system usually makes it worse than its own best single model
arXiv
Threat pattern / Contrast
An LLM agent doing static plus dynamic analysis found 81 log-exposure flaws across WordPress plugins with 250M installs; 79 reproduced by hand
arXiv
Stack layer / Update thread
Two Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many Settings
arXiv 2609.16098