Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?
3.40T1 sourcearXiv cs.MA
Source record
Published by arXiv cs.MA (T1 source). The original is at https://arxiv.org/abs/2607.17986.
Pipeline notes
The summary and note below are generated by the signal pipeline — they are Beyond Desk’s reading, not quotations from the source.
SummaryResearch paper characterizing 'self-state attacks' on self-hosted AI agents, in which compromised agents modify their own memory and configuration files via legitimate OS system calls. Proposes a four-axis attack framework instantiated as a 23-cell matrix with 43 concrete operations, evaluated against layered OS defenses. Finds a small residual attack surface remains structurally indistinguishable at the OS level.
Why it mattersNames a new attack class specific to self-hosted agents and demonstrates that OS-level defenses alone cannot close a structural gap, relevant to anyone deploying agents on their own infrastructure.
Cited by
No citations on record.
