State Surfaces

Compromised Summaries and Context Compaction: Security Risks for AI Agents

What the security risks of context compaction are for AI agents: how compaction can preserve adversarial state while dropping valid constraints, what evidence to log, and how to prevent, contain, and recover from compromised summaries without publishing attack recipes.

Target: Context and Durable MemoryPersistence: Session to Cross-Session

Definitions

Agent State Attack: Definition, Scope, and Boundaries

The SSA working definition of an agent state attack, with boundaries around model-weight attacks, accidental behavioral state decay, ordinary invalid input, and the OS-layer self-state attacks defined in arXiv 2607.17986.

Target: MultiplePersistence: Single Turn to Shared-System