Asynchronous monitoring, incident investigations, and compliance audits primarily rely on agent traces to reconstruct what happened. These analyses assume that LLM agents cannot tamper with their own execution traces. We show that local LLM agents such as Claude Code, Codex, Antigravity, Open Code and Grok Build fail t...
Jeremy Qin, David Schmotz, Derck W. E. Prinzhorn et al.· 0 citations
It is found that GPT-6 Astra's low evasion rate comes with overrefusal, as it frequently abandons otherwise solvable tasks under a denial-of-service prompt injection.
David Schmotz, Derck W. E. Prinzhorn, Luca Beurer-Kellner et al.· 1 citation
An architectural vulnerability is identified that circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model's reasoning, as well as proposing concrete cryptographic and system-level mitigations to secure client-side reasoning.
Alexander Panfilov, David Schmotz, I. Shumailov et al.· 9 citations· ⚡3
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.