Fetching from the wire…
Agents2026-09-16 · source-backed
Researchers named human-agent UI desynchronization: users see a physical display, the agent consumes raw screenshots plus accessibility metadata exposing non-visual widget content, so the same UI state carries different information to each. They baked user-instruction-agnostic perturbations into deployable APKs that stay fully functional for humans, then tested five mobile-agent frameworks and three backbones across 546 tasks, hitting 77.9% misleading rate statically and 66.9% dynamically. A 186-participant questionnaire confirmed people can't see the perturbations, which breaks the human-oversight premise mobile agent deployments are sold on.
Each link below shares sources, entities, or timing with this story.
Researchers loaded five systems with a revoked policy and its replacement, then measured retrieval and downstream action across nine policy scenarios, nine models and six defense conditions. Wherever the revocation label was visible to the retrieval layer, the revoked fact cam...
Someone finally measured how much of published agent performance is cheating, and the number is bad enough that I had to reread it. Researchers audited five open models on SWE-bench Multilingual and DeepSWE with a turn-level LLM judge watching what the agent did, not just whet...
Researchers deployed 150 autonomous Claude Code agents to independently test six financial market hypotheses using identical NYSE TAQ data. Substantial agent-to-agent variation — different model families exhibit stable "empirical styles" where Sonnet 4.6 and Opus 4.6 make syst...
Researchers traced 232,270 dataset→model→application chains to measure whether license obligations actually propagate downstream. They mostly don't. 62.3% of chains pass through at least one artifact with no declared license, concentrated in a small set of foundational dataset...
Researchers introduced ShareLock, a tool-poisoning attack against MCP that distributes a malicious instruction across several tool descriptions, defeating the assumption that a reviewer reading one tool will catch it. Per-tool review is now insufficient. The attack surface is...
Researchers reveal that Direct Preference Optimization implicitly operates over a full preference graph, meaning it extracts more signal from existing datasets than anyone realized. Practical implication: your existing RLHF data may be more valuable than you think.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.