ResearchAgentSentry Temporal Causal Defense Against Indirect Prompt InjectionarXiv·high signalXBlueskyLinkedInCopy linkFirst defense modeling multi-turn IPI as temporal causal takeover. Counterfactual re-execution at tool-return boundaries.SourceSource pagearXiv↳ Follow the threadStack layer / Threat patternHARD Turns LLM Agent Runtime Defense Into a Self-Evolving Loop Instead of Hand-Written RulesarXiv 2608.12977Threat pattern / ContrastVertical Federated Learning Backdoor Results Collapse Under Realistic Constraints; BVBench Released to Reset the FieldarXiv 2608.12962Stack layer / ContrastColoring Positive Words Green Shifts VLM Sentiment Predictions — a Styling-Only Prompt Injection ChannelarXiv 2608.14286Stack layer / ContrastAgentao: a local-first agent runtime that separates what the model proposes from what the host authorizes — and admits it has no formal guaranteesarXivPolicy dependency / Stack layerEnvs-FORGE Solves a Per-Seed MILP to Synthesize Agent-RL Environments, Hitting 77.1% on SWE-bench Verified vs 73.4% BasearXiv 2608.14312Contrast / Update threadE2-Explainer turns multi-agent communication topology from black-box optimization into a causal attribution problem — then prunes the grapharXivStack layer / ContrastAlgorithm Audit: LLMs Tilt Doctor Recommendations by Demographics Worth $7-$14 a Visit, and Mention It in 0.03% of ExplanationsarXiv 2608.14399Policy dependency / Stack layerPattern: Permission Automation Flipped From Opt-In to Default Across Three Vendors in Two WeeksClaude Code Docs / GitHub Changelog / OpenAI Codex Changelog