Localhost is not a trust boundary for agents
A loopback address restricts network reachability but does not, by itself, authenticate a caller or authorize a privileged action.
8 explicit connections
AI security research / concepts
Mechanisms and patterns across the research.
31 Topics · Page 2 of 2
11 matching records on this page
A loopback address restricts network reachability but does not, by itself, authenticate a caller or authorize a privileged action.
8 explicit connections
An MCP endpoint exposes privileged local or remote capabilities without adequate authentication, origin checks or action constraints.
6 explicit connections
Any parameter an LLM can influence must be treated as untrusted input at the tool boundary.
1 explicit connection
Communication paths that cross an intended isolation boundary through physical emissions, environmental effects, sensors, shared infrastructure or semantic carriers outside the approved data path.
16 explicit connections
Phantom squatting is a software-supply-chain risk in which an AI system hallucinates or invents a package/domain dependency and an attacker registers the nonexistent name so later automated consumers resolve to attacker-controlled infrastructure. The risk becomes more serious when agents can install dependencies or follow generated URLs without independent verification.
2 explicit connections
Architecture that moves authorization out of the LLM and cryptographically binds an approved intent/policy decision to exact execution bytes.
2 explicit connections
Recursive self-improvement is not one evidentiary claim. A narrow system can improve a search or orchestration policy while leaving its underlying model unchanged; a stronger scenario is AI automating enough AI R&D to accelerate capability development; stronger again is uncontrolled recursive capability escalation that outpaces human evaluation and intervention. The scoped sources support active expert concern, governance debate and a futurist community tendency to compress these levels into the same label. They do not demonstrate the strongest scenario. Palisade's interviews are useful for understanding beliefs inside and around frontier labs, but Palisade itself says its interviewees are not representative and are disproportionately safety-oriented, so their extinction-risk estimates are testimony rather than population statistics or incident evidence.
1 explicit connection
Unintended disclosure of screen content or activity through reflections captured from eyeglasses, faces or other reflective surfaces in camera views.
1 explicit connection
A service reachable from nominally isolated workloads becomes an unintended cross-session or cross-environment communication path.
3 explicit connections
Compromised API keys provide compute, cover and resale value to attackers.
5 explicit connections
A service silently forwards user inputs to a different model or provider than the user believes they are using.
1 explicit connection
No matches on this page.