Tag
A new arxiv paper by Yimeng Chen et al. formalizes 'self-state attacks' against AI agents, where an agent's own memory and configuration files are poisoned via legitimate OS calls. The authors evaluate OS-level defenses and identify structural limitations, suggesting the need for application-layer integrity measures.