Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Policy dependency / Threat pattern
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Stack layer / Contrast
Pre-registered ablation shows removing an LLM verifier stage from an offensive-security agent shifts median reported findings from 0 to 2 per run
arXiv
Policy dependency / Stack layer
CodeBLEU Scored 91% for Both RAG Strategies While One of Them Hallucinated APIs 56.4% of the Time
arXiv 2609.12464
Policy dependency / Stack layer
HazardAuditor runs Claude Code, Codex, Hermes and OpenClaw in one harness and normalizes their events to train a guard model
arXiv / HuggingFace Daily Papers
Stack layer / Contrast
Distilled Byte Models Match a Token Model's Accuracy on One-Sixth the Data and Cut Logit Storage to a Fifth
arXiv 2609.12303
Stack layer / Contrast
Odin Runs All 32 Llama-3-8B Transformer Layers Under FHE in 366 Seconds on One H100, 4.51x Faster Than THOR
arXiv 2609.12378
Stack layer / Contrast
Difficulty-aware topology selection beats always-hierarchical multi-agent coding by 4.1 points at 40% of the cost
arXiv