Fetching from the wire…
Agents2026-09-22 · source-backed
The distinction it draws: a boundary crossing mediated over provenance admits a deterministic check, one mediated over content semantics does not. The two semantic judgments with no sound mediator are separating data from instruction in untrusted input, and separating an authorized action from an unauthorized one. That leaves an irreducible residual wherever inputs and actions aren't restricted to an enumerated set in advance. The useful move for builders is the resulting split: any attack-success number is either deployment debt, meaning a sound mediator existed and wasn't used, or a structural gap you can't engineer away. (arXiv 2609.23700)
Each link below shares sources, entities, or timing with this story.
AutoTuneBench characterizes four failure modes from a four-day corpus of 619 model calls where agents tuned GPU kernels in a propose-measure-keep loop: strawman baselines manufacture speedups, absolute times don't transfer across machines, saturated tasks nullify comparisons,...
arXiv 2609.17698 read documentation, source, config and tests across 157 LLM-agent projects with 100+ stars. Coverage fragments in a specific, checkable way: a guard on the direct tool call and nothing on the shell that reaches the same effect, tests that rarely exercise bound...
CADWorld is a 200-task FreeCAD benchmark across 11 mechanical-CAD workflow categories, with agents operating through screenshots and GUI actions and success determined by executable checks over the saved native project. Seven current agents, best result 17.5%. The failure prof...
The failure mode is a well-formed but policy-forbidden call, cancel a booking, change a passenger count, that neither the tool nor the agent's self-report flags (arXiv). In the airline domain tested, the fix wasn't more reasoning. It was cheap, read-only deterministic gates th...
July MCP roundups documented Mid-Session Tool Injection against WebMCP agents, using threshold poisoning and fabricated diagnostic events to swap or re-scope tools after a session is already established. The uncomfortable implication: a context provider you trusted at connect...
The question safe deployment needs answered isn't whether a catastrophic trajectory can occur but how often. This method builds the importance-sampling proposal by perturbing the original model's weights, making the proposal itself a differentiably parameterized language model...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.