Global foundation-model progress briefing
English Edition中文
Enter keywords to search ingested stories.

Today / Thursday, August 13, 2026

limbo logolimbo

Data updated

Jul 2, 05:59 PM

Live sources

17

Ingestion status

Live ingest

ResearcharXiv AI / CL

Distributed Attacks in Persistent-State AI Control

Summary

As AI coding agents become more autonomous, they increasingly ship code iteratively, with the codebase persisting across sessions. This persistence creates a new attack surface: a misaligned or prompt-injected agent can distribute attacks across pull requests...

Original Article

Captured source content or English translation, normalized into this reading format.

Read Source

Skip to main content

![](https://arxiv.org/static/base/1.0.1/images/icons/smileybones-small.svg)arXiv is now an independent nonprofit!Learn more×

Search arXiv

Press Enter to search ·Advanced search

Computer Science > Artificial Intelligence

arXiv:2607.02514v1 (cs)

[Submitted on 2 Jul 2026]

Title:Distributed Attacks in Persistent-State AI Control

Authors:Josh Hills,Ida Caspary,Asa Cooper Stickland

View a PDF of the paper titled Distributed Attacks in Persistent-State AI Control, by Josh Hills and 2 other authors

View PDFHTML (experimental)

Abstract:As AI coding agents become more autonomous, they increasingly ship code iteratively, with the codebase persisting across sessions. This persistence creates a new attack surface: a misaligned or prompt-injected agent can distribute attacks across pull requests (PRs) and time its payload for the PR with the best natural cover. To study the resulting dynamics, we introduce Iterative VibeCoding, a setting for AI control, the study of safely deploying capable but potentially untrusted AI. In Iterative VibeCoding, a coding agent builds software over a sequence of PRs in a persistent codebase while pursuing a covert side task. Our benchmark includes two task families: CLI tools and Flask web services, across 20 total task variations. We use Claude Sonnet 4.5 as the attack agent and GPT-4o as the monitor. We compare gradual attacks, which distribute the side task across PRs, against non-gradual attacks concentrated in a single PR. No single monitor is robust to both: which strategy evades best (success while evading the monitor) depends on the monitor type, so a defender cannot close off both gradual and non-gradual attacks with any one monitor. High evasion (>= 65%) generalizes across model attack agent backends (Sonnet 4.5, Gemini 3.1 Pro, Kimi K2.5), confirming this is a property of the persistent-state attack surface rather than a single model's capability. Evasion also remains high across state-of-the-art monitor models and the gap between gradual and non-gradual evasion widens for more capable models. We introduce a stateful link-tracker monitor that tracks suspicious buildup across PRs. On both task families, it detects gradual attacks substantially better than diff monitors that merely see more accumulated history. Combining this stronger monitor with trajectory monitors in a four-monitor ensemble reduces gradual-attack evasion from 93% under the weakest standard diff monitor to 47%.

| | | | --- | --- | | Subjects: | Artificial Intelligence (cs.AI) | | Cite as: |arXiv:2607.02514[cs.AI] | | | (orarXiv:2607.02514v1[cs.AI] for this version) | | |https://doi.org/10.48550/arXiv.2607.02514<br>Focus to learn more<br>arXiv-issued DOI via DataCite (pending registration) |

Submission history

From: Josh Hills \[view email]

[v1] Thu, 2 Jul 2026 17:59:56 UTC (170 KB)

Full-text links:

Access Paper:

View a PDF of the paper titled Distributed Attacks in Persistent-State AI Control, by Josh Hills and 2 other authors

![license iconview license](http://creativecommons.org/licenses/by/4.0/ "Rights to this article")

Current browse context:

cs.AI

[< prev](https://arxiv.org/prevnext?id=2607.02514&function=prev&context=cs.AI "previous in cs.AI (accesskey p)")  \|  [next >](https://arxiv.org/prevnext?id=2607.02514&function=next&context=cs.AI "next in cs.AI (accesskey n)")

new\|recent\|2026-07

Change to browse by:

cs

References & Citations

export BibTeX citation

Bookmark

![BibSonomy](http://www.bibsonomy.org/BibtexHandler?requTask=upload&url=https://arxiv.org/abs/2607.02514&description=Distributed%20Attacks%20in%20Persistent-State%20AI%20Control "Bookmark on BibSonomy")![Reddit](https://reddit.com/submit?url=https://arxiv.org/abs/2607.02514&title=Distributed%20Attacks%20in%20Persistent-State%20AI%20Control "Bookmark on Reddit")

Bibliographic Tools

Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer _(What is the Explorer?)_

Connected Papers Toggle

Connected Papers _(What is Connected Papers?)_

Litmaps Toggle

Litmaps _(What is Litmaps?)_

scite.ai Toggle

scite Smart Citations _(What are Smart Citations?)_

Code, Data, Media

Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv _(What is alphaXiv?)_

Links to Code Toggle

CatalyzeX Code Finder for Papers _(What is CatalyzeX?)_

DagsHub Toggle

DagsHub _(What is DagsHub?)_

GotitPub Toggle

Gotit.pub _(What is GotitPub?)_

Huggingface Toggle

Hugging Face _(What is Huggingface?)_

ScienceCast Toggle

ScienceCast _(What is ScienceCast?)_

Demos

Demos

Replicate Toggle

Replicate _(What is Replicate?)_

Spaces Toggle

Hugging Face Spaces _(What is Spaces?)_

Spaces Toggle

TXYZ.AI _(What is TXYZ.AI?)_

Related Papers

Recommenders and Search Tools

Link to Influence Flower

Influence Flower _(What are Influence Flowers?)_

Core recommender toggle

CORE Recommender _(What is CORE?)_

  • Author
  • Venue
  • Institution
  • Topic

About arXivLabs

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community?Learn more about arXivLabs.

Which authors of this paper are endorsers?\| Disable MathJax (What is MathJax?)

Region

Global

Heat Score

89

Category

Research

Language

en