AI RESEARCH

Stateful Online Monitoring Catches Distributed Agent Attacks

arXiv CS.AI

ArXi:2605.31593v1 Announce Type: cross Language models can find thousands of severe software vulnerabilities, and agents are increasingly being misused for cyberattacks. To avoid detection, attackers frequently distribute their misuse, splitting a harmful task across many user accounts so each individual transcript looks benign. Because safety monitors score only one agent context at a time, they are structurally blind to misuse that is only visible in aggregate, across many accounts.