Tag
A new arxiv paper by Yimeng Chen et al. formalizes 'self-state attacks' against AI agents, where an agent's own memory and configuration files are poisoned via legitimate OS calls. The authors evaluate OS-level defenses and identify structural limitations, suggesting the need for application-layer integrity measures.
This paper investigates OS resilience against self-state attacks on self-hosted AI agents, characterizing an attack space and evaluating layered defense strategies. It finds that while a layered defense stack is effective, a small residual attack surface remains structurally indistinguishable at the OS level.