{
  "id": 12219,
  "url": "https://arxiv.org/abs/2607.17986v1",
  "title": "Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?",
  "summary": "Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via legitimate OS system call invocation. We refer to this class of threats as self-state attacks. In this paper, we investigate the OS resilience to this class of attacks. Formally, we characterize a four-axis attack space (Target, Mechanism, Granularity, Temporal); investigate the structural limits of prevention, detect",
  "authors": "Yimeng Chen, Nathanaël Denis, Roberto Di Pietro, Jürgen Schmidhuber",
  "category": "research",
  "topics": "agents-autonomy,finance-investment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-20T14:16:55.000Z",
  "fetched_at": "2026-07-21T05:10:12.656Z",
  "source_slug": "x-arxiv-cs-ai",
  "source_name": "arXiv cs.AI",
  "source_homepage": "https://arxiv.org/list/cs.AI/recent",
  "ethics_ai_record_url": "https://ethics.ai/record/12219",
  "original_url": "https://arxiv.org/abs/2607.17986v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}