Stack layer / Contrast
Emergence World ran 10 agents per world for 16 days and found no frontier model contained an injected attack — one acted on poisoned memory 46 hours later
arXiv
Policy dependency / Contrast
KV Cache Tiering Buys 73x More Sessions Per GPU, and the Eviction Policy Barely Matters
arXiv 2609.16215
Stack layer / Update thread
Two Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many Settings
arXiv 2609.16098
Stack layer / Threat pattern
Agent Frameworks Detect Dangerous Plan Steps and Then Execute Them Anyway; Fewer Than 20 Lines Closes the Gap
arXiv 2609.15293
Stack layer
A Prompt-Only Abstention Loop Cuts Wrong Commitments From 13.1% to 8.9% Across Eleven Model Families
arXiv 2609.17516
Stack layer
Persistent Memory Poisoning Hits Claude Code at 81.7% Cross-Session Attack Success and OpenClaw at 55.5%
arXiv 2609.13889
Policy dependency / Stack layer
Python's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or Critical
arXiv 2609.14791
Policy dependency / Stack layer
Converting GUI Trajectories Into Replayable MCP-Style Calls Instead of Unstructured Memories
arXiv 2609.16635