{
  "id": 12314,
  "url": "https://arxiv.org/abs/2607.17986",
  "title": "Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?",
  "summary": "Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via legitimate OS system call invocation. We refer to this class of threats as self-state attacks. In this paper, we investigate the OS resilience to this class of attacks. Formally, we characterize a four-axis attack space (Target, Mechanism, Granularity, Temporal); investigate the structural limits of prevention, detect",
  "authors": "Yimeng Chen, Nathanaël Denis, Roberto Di Pietro, Jürgen Schmidhuber",
  "category": "research",
  "topics": "agents-autonomy,finance-investment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-19T20:00:00.000Z",
  "fetched_at": "2026-07-22T05:10:49.469Z",
  "source_slug": "hf-daily",
  "source_name": "HuggingFace Daily Papers",
  "source_homepage": "https://huggingface.co/papers",
  "ethics_ai_record_url": "https://ethics.ai/record/12314",
  "original_url": "https://arxiv.org/abs/2607.17986",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}