Showing cs.CRShow all
3 papers · 1 filter
cs.CR2026
Recognition Without Enforcement: Configuration-Dependent Failures in LLM Agent Instruction Arbitration and External Control
Jun Wen Leong
LLM agents arbitrate among instructions from system prompts, users, memory, and tools, but this arbitration cannot be assumed to enforce trust boundaries. We identify a recognition…
cs.CR2026
Forensic Trajectory Signatures for Agent Memory Poisoning Detection
Jun Wen Leong
We discover a behavioral invariant in LLM agents under persistent memory poisoning and characterize its deployment boundary. In architectures where retrieval is routed through obse…
cs.CR2026
Injection-Execution Dissociation: A Mechanistic Evaluation of Persistent Memory Attacks and Defenses in Stateful LLM Agents
Jun Wen Leong
We discover that prompt-injection success and tool-execution success are separable safety properties: defenses that block injection do not necessarily block execution, and vice ver…