Fetching from the wire…
Public story · 2026-08-25 · high
SecOPD trains on token-level feedback instead of whole-sequence signal, cutting adaptive attack success from 94% to 9%.
Why now: The paper posted August 25.
SecOPD, a new prompt-injection defense, drops adaptive attack success to 9.0% against PISmith injections on Qwen3.6-27B, per the SecOPD paper.
Meta-SecAlign, the previous best defense, let 94.0% of those same PISmith adaptive injections through on Qwen3.6-27B. Adaptive attacks are built to beat a defense once its exact behavior is already public, and every earlier defense before SecOPD broke against them. That matters for anyone running an agent that calls tools or reads content it doesn't control.
The gap comes from the training signal, the paper reports. SecOPD fine-tunes on token-level feedback during on-policy distillation, where Meta-SecAlign and other prior defenses trained on sequence-level feedback instead.
SecOPD also holds up outside the injection setting it was tuned on, cutting attack success to 4.7% on agentic tool calling. The model never saw that domain during training. That result points at the training signal as the fix for adaptive attacks, not broader domain coverage.
Each link below shares sources, entities, or timing with this story.
The leaderboard says first place. The methodology says you should check your own bill. Qwen3.8 Max now ranks first on Artificial Analysis' agentic index, scoring 86.1 on OSWorld-Verified ahead of GPT-5.6 Sol Max at 83.2 and Fable 5 at 85.0, priced at $2.00/M input and $6.00/M...
For about a year, "run your agent locally" meant accepting a model that couldn't reliably call a tool twice in a row. That excuse is gone. Meta Superintelligence Labs published Muse Glimmer today: a 29.6B dense causal transformer, 52 layers, 6,656 hidden dim, with a ~1.8B ViT-...
The models are good. The license is the real story. Google released Gemma 4 on April 2 with four variants: E2B, E4B, 26B MoE, and 31B Dense. All built on the Gemini 3 architecture. The 31B Dense variant claimed #3 on Arena AI's text leaderboard, beating models 20x its size. Th...
Majidi, Mireshghallah, and Taram demonstrate the first attacks inferring proprietary model and deployment details from per-token generation timing over a remote API (arXiv 2607.20723). One attack detects whether a provider runs speculative decoding and recovers the draft model...
Test-time training for long-context LLMs is highly sensitive to which spans you train on. Random spans degrade accuracy because most are irrelevant (arXiv:2607.09415). S-TTT has the model first identify relevant evidence passages, then run adaptation only on those, for up to 1...
Forerunner led a $30M Series A into Natural on July 20 to build "the transactional plumbing required for AI agents," entering a field that already has Google's UCP, OpenAI's ACP, Stripe/Tempo's MPP (with Visa as design partner), Google's AP2, Ant International's AMP, and Maste...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.