Fetching from the wire…
Research2026-09-09 · source-backed
ResidualAuth proves two authorization histories can share identical current permissions and identical all-pairs reachability yet demand opposite decisions after the same revocation. Across four open-weight models, sham reads solved 0 of 16 while authenticated current-query reads solved 15-16. In a held-out diagnostic, exact ledger serializations fit all 128 four-coordinate pairs at 768 and 1,024 tokens, while factually supported model-written memories solved at most 1 of 128 per model. arXiv 2609.08062
Each link below shares sources, entities, or timing with this story.
Diffusion LMs decode many tokens per step but pay to interact with all suffix tokens every step, and existing fixes just keep a local window while re-initializing suffix tokens identically each timestep (arXiv 2608.23167). This method splits the suffix into local, middle and t...
The complete public record preserves not just what each agent wrote but what it could see before writing, and one rule governs all three arrival decisions (where to write, what to call itself, how to word the message): an agent picks an option with probability close to that op...
A fleet evaluation across 46 endpoints from six vendors found a recognition-enforcement gap: source-format features are linearly decodable from activations and models verbally identify forged authority when asked, but some configurations still emit the conflicting tool call. A...
$3,054 against $38,370. Same benchmark, better score. Praxist (arXiv 2608.25955, submitted August 26) replaces per-attempt agent memory with a typed evidence graph of findings, plus lane-structured frontiers and agendas, so later attempts inherit validated mechanisms rather th...
Recuris (arXiv 2608.24876) keeps a Working Memory tracking current task progress separate from an Experiential Memory of learned skills, so skill selection indexes against what the task needs now rather than the whole history. It improves 35 of 37 model-benchmark pairs, gains...
arXiv 2608.23873 starts from a structural observation I hadn't seen framed this cleanly: the serving stack knows which span is user input, tool output or instruction, but the model sees only tokens and infers span identity from text the attacker controls. Semantic Overlays are...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.