ResearchSleeper Cell Temporal Backdoors in Tool-Using LLMs via SFT-GRPOarXiv·high signalXBlueskyLinkedInCopy linkPoisoned models pass all benchmarks while harboring trigger-activated malicious tool calls. Supply-chain risk for LoRA adopters.SourceSource pagearXiv↳ Follow the threadPolicy dependency / Stack layerMemSentry gates persistent memory writes on a signed security-state delta rather than on content classificationarXivPolicy dependency / Stack layerPattern: the agent config layer is being treated as an unmanaged dependency graph, and three independent sources said so this weekarXivPolicy dependency / Stack layerRetrieval that crosses into your dependencies' source, not just your repo, adds up to 6.3% pass@1 and survives version changesarXiv 2609.09987Policy dependency / ContrastA Fine-Tuned 4B Qwen in 2.6 GB Beats GPT-5.6 on a Transit-Kiosk Agent Benchmark, and PEFT Gains Vanish by 27BarXiv 2609.10016Stack layer / Threat patternAgentAudit attaches to a running agent and scores its trace on ten dimensions, exposing 95.1 vs 22.6 trust spreads at similar task completionarXivPolicy dependency / Threat patternAgents hit 80% F1 deciding whether a dependency CVE is exploitable, but fall below 70% explaining whyarXiv 2609.08040Policy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Stack layer / ContrastA capability-scoped harness cut prompt-injection execution from 33-47/75 runs to 3/75 without asking the model to spot malicious textarXiv 2609.08371