Story · arXiv

When Consent Outlives Context: Residual Authority Replay in Long-Lived Agents (arXiv)

paper · Story page

An approval a long-lived agent keeps can outlive the context that justified it. Obtain that authority through benign interactions and replay it later, and attack success rises by up to 35.1 percentage points across 508 AgentDojo cases.

In plain words

  • Researchers found a way to trick artificial intelligence assistants into using permissions granted for earlier tasks.
  • The attack starts with harmless interactions that get the user to grant permission for a restricted action.
  • Later, the attacker reuses that permission in a different situation without asking the user again.
  • Users' earlier approvals can make later attacks more likely to succeed without the users agreeing to those later actions.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.