Fetching from the wire…
Agents2026-09-21 · source-backed
Provisional Reachability holds each agent crossing in escrow for one period, audits held items with probability r, and revokes the window on any catch. An adversary crossing k times with c bits each expects kc(1-r)^k, giving a public-safe bound near c/(er) per window that simulation matches to 7.7 standard errors. The full stack drops a leak from 100,000 bits to 59 while leaving 12% of legitimate work standing, restored to 100% by keying windows per caller. The closing number is the honest one and the authors state it plainly: escrow over 65 read-only tools still leaves 2,400 bits per call. Read-only is not leak-free.
Each link below shares sources, entities, or timing with this story.
arXiv 2609.17698 read documentation, source, config and tests across 157 LLM-agent projects with 100+ stars. Coverage fragments in a specific, checkable way: a guard on the direct tool call and nothing on the shell that reaches the same effect, tests that rarely exercise bound...
FARSIGHT evaluates 15 representative academic financial trading schemes at the scheme level across robustness under market turbulence including flash-crash scenarios, and security against attacks on information sources, on the agent, and agent-as-attacker behavior. Every schem...
arXiv 2609.18674 extends CaMeL with a static verification layer. CaMeLoT translates a generated plan into a finite-state transition system labeled with tool calls, provenance and taint, then checks it against CTL policies with nuXmv before execution starts. Unsafe plans get re...
RideWay pairs a stateful tool-calling ridehailing benchmark with Efficiency Utility, a success-gated metric discounting trajectories for excess tool calls and user-facing turns against task-specific reference effort, penalties calibrated from human paired preferences. Across 5...
A 15-run pilot, a pre-registered 20-run confirmatory ablation and a pre-registered 2x2 factorial with 40 runs across two vulnerable lab systems (arXiv 2609.15887). Removing verification raised reported findings (median 2 against 0, p = 0.00003) and cut precision (0.353 against...
AGENTQ is the first study of this attack against agents rather than free-text generation, where the payload is a structured function call nobody reads (arXiv 2609.14060). Naive adaptation of prior backdoor methods wrecks benign utility; AGENTQ combines layer-banded LoRA inject...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.