Evidence record 12314 · automatically gathered

Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?

Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via legitimate OS system call invocation. We refer to this class of threats as self-state attacks. In this paper, we investigate the OS resilience to this class of attacks. Formally, we characterize a four-axis attack space (Target, Mechanism, Granularity, Temporal); investigate the structural limits of prevention, detect

Record details

Published: 19 July 2026
Source: HuggingFace Daily Papers
Category: Research
Topics: Agents & autonomy · Finance, VC & PE
Retrieved: 22 July 2026

source-onlyevidence status

These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.

How to cite this record

ethics.ai (19 July 2026), “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?,” evidence record 12314, https://ethics.ai/record/12314 (originally published by HuggingFace Daily Papers).

JSON

Use and limitations

This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.