LATIDIA · Ciberseguridad
El silencio es respaldo: verificación: lavado de estado en las tuberías de agentes de LLM
arXiv: 2609.20211v1Tipo de anuncio: nuevo Resumen: Los monitores de seguridad en los sistemas de agentes LLM a menudo juzgan las acciones a partir de resúmenes o traspasos almacenados, no de la evidencia original. Esto crea un modo de falla simple pero peligroso
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.20211v1 Announce Type: new Abstract: Safety monitors in LLM agent systems often judge actions from summaries or stored handoffs, not from the original evidence. This creates a simple but dangerous failure mode: the handoff preserves the claim that an action is authorized while losing the fact that the claim was never verified. We call this verification-status laundering. Across nine open-weight monitors and two hosted models, the action and authorization proposition remain fixed while we remove the unverified provenance framing around the claim. This change raises approval for risky actions from $5\%$ to $60\%$ on Llama-3.1-8B and from $9\%$ to $98\%$ on Qwen2.5-14B, with similarly large shifts on both hosted models.