Pıer
TidesCurrentsHarbor LightsLabBottlesAshore
Pıer

Navigation

  • Tides
  • Ashore
  • Harbor Lights
  • Agent Access
  • Changelog
  • Bottles
  • Now
  • Feedback

External links

GitHubCloudborne ↗

© 2026 Pier.

WatchingResearchWatching0 independent reports0

Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?

First seen · 7/20/2026, 10:16 PMLatest activity · 7/20/2026, 10:16 PM

This paper introduces self-state attacks, in which a self-hosted AI agent is compromised by modifying its own memory or configuration through legitimate operating-system system calls. The authors define a four-axis attack space covering target, mechanism, granularity, and temporal behavior. They collect live traces from a representative agent under distinct workload profiles, instantiate 23 attack cells, and inject 43 concrete operations into those traces. Their evaluation finds that layered defenses can cover most cells: access control for instruction and configuration files, workload-conditioned detection for memory, and periodic backups for recovery. However, some attacks remain structurally indistinguishable at the OS level.

Event heat · last 24 hours

No heat snapshots are available in the last 24 hours.

No heat snapshots are available in the last 24 hours.

Reporting Timeline

  1. AggregatorarXiv7/20, 10:16 PMnot independentRepresentative
    Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?