Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?
Self-hosted AI agents read and write their own memory and configuration files to function. An agent may get compromised via corruption of its own state -- a compromise realized via legitimate OS system call invocation. We refer to this class of threats as self-state attacks. In this paper, we investigate the OS resilience to this class of attacks. Formally, we characterize a four-axis attack space (Target, Mechanism, Granularity, Temporal); investigate the structural limits of prevention, detection, and recovery; and introduce a workload-conditioned view of detectability. To instantiate the fr
Lineage graph
Paper → model → repo connections mined from source citations (Tier-1 exact match).
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- PossiblePossibly related (embedding) · 26%apache/hertzbeat →
“Possibly related via embedding similarity 0.56 (not asserted). Timestamp check: artifact slightly before paper (-18d).”
- FuzzySimilar title/name (fuzzy) · 87%NirDiamant/GenAI_Agents →
“Fuzzy title match (0.94): “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS ” ≈ “NirDiamant/GenAI_Agents””
- FuzzySimilar title/name (fuzzy) · 84%Unity-Technologies/ml-agents →
“Fuzzy title match (0.92): “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS ” ≈ “Unity-Technologies/ml-agents””
- FuzzySimilar title/name (fuzzy) · 59%datawhalechina/hello-agents →
“Fuzzy title match (0.73): “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS ” ≈ “datawhalechina/hello-agents””
- FuzzySimilar title/name (fuzzy) · 59%TauricResearch/TradingAgents →
“Fuzzy title match (0.73): “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS ” ≈ “TauricResearch/TradingAgents””
- FuzzySimilar title/name (fuzzy) · 59%Eigenwise/atomic-agents →
“Fuzzy title match (0.73): “Self-State Attacks on Self-Hosted AI Agents: How Far Can OS ” ≈ “Eigenwise/atomic-agents””
- LinkedLinked via arxiv author · 85%Yimeng Chen →
“Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?”
- LinkedLinked via arxiv author · 85%Nathanaël Denis →
“Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?”
