Story · arXiv
Safe to Resume? Breaking Execution Continuity of Agent Execution via Rollback (arXiv)
paper · Story page

A correctly restored checkpoint can resume a state whose assumptions and external effects never coexisted in any real history. The paper maps five failure modes for checkpoint-and-rollback in agent systems and demonstrates three end-to-end attacks on Hermes, Cline and LangGraph, including a malware-verification bypass.
In plain words
- Researchers found that restoring an artificial intelligence system to an earlier saved state can create security risks.
- The restored system may rely on assumptions and outside changes that never existed together in real operation.
- Researchers identified five ways this mismatch can happen, including outdated dependencies and outside actions that were never recorded.
- They demonstrated three attacks on Hermes, Cline, and LangGraph, including bypassing a malware check.
- This matters for teams using saved states to recover long-running artificial intelligence systems after failures.
Appeared in
- Anthropic's deliberately misaligned model, Fable 5.1, and a fix for reward hacking
Sep 02, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
