Research & notes
Notes from the inside view of agent security.
Cross-session threats, dynamic agent identity, trajectory-based detection, and the geometry of agentic AI.
I²TP · Information-Theoretic Identity & Threat Protocol · Patent pendingAI agent guardrails are memoryless. An adversary spreads a single attack across dozens of sessions and slips past every session-bound detector. We frame cross-session threat detection as an information bottleneck, release a benchmark (CSTM-Bench), and show that bounded coreset memory is the only architecture whose recall survives adversarial rewriting.
Read the gistTwo blockers kept security at the perimeter: massive activations, model-specific vectors. Platonic codes compress routes into a shared frame so behavioral anomaly detection can sit next to inference, including zero-day prompt injection attacks.
Read articleA unifying picture for ABA: anomaly detection across event, intent, and residual-stream space — from pub/sub tool calls to belief-state geometry inside the model.
Read articleAgent identity is not a static concept. It's a trajectory through an information manifold — and every threat is a deviation from the intended path.
Read articleExploring adaptive prompt injections and how reasoning-layer security provides superior protection against evolving AI threats.
Read articleUnderstanding how atomic attack components combine to form multi-stage threats, and how token-level analysis reveals complex attack patterns before they execute.
Read articleAs agentic AI systems take actions, security shifts from 'what happened?' to 'what was the model trying to do — and why?' Thought-level entities must become first-class in security monitoring.
Read article