Tuesday, October 6, 2026 Newsletter Advertise
Research

Research Radar, October 6, 2026: 13 new AI and security papers to know

The most relevant new AI and security research from Nature & arXiv, with the authors' own summaries and links to the papers.

13 papers, Nature & arXiv

New research on AI and security, selected for relevance to language models, AI agents and cybersecurity. Summaries are the authors’ or publisher’s own words, linked to the original.

Peer-reviewed

New preprints (not yet peer-reviewed)

AgentSpy: Making AI Agent Behavior Observable

arXiv · Christoph B"uhler, Matteo Biagiola, Luca Di Grazia, Guido Salvaneschi

AI agents built on large language models (LLMs) run shell commands, read and write files, and reach the network, typically with their user's privileges. However, what an agent does during an execution is difficult to understand: tests assert on the result, and the agent's trajectory records only what the agent reports about itself, which may omit behavior executed by its subprocesses.

Characterizing Security Effects of OSS Vulnerabilities in Agent Systems

arXiv · Yu Ji, Yang Wei, Yutao Hu, Haojun Zhao, Yueming Wu, Deqing Zou

Software agents increasingly depend on open-source components when executing tools and interacting with external systems. Security flaws in these dependencies may therefore influence more than the software process in which they occur: their consequences can be carried through tool outputs, agent state, and information subsequently exposed to the model.

MLLMs Fail to Refuse when Using Tools Agentically

arXiv · Rikiya Takehi, Ryo Hachiuma, Shaona Ghosh, Dan Zhao, Yu-Chiang Frank Wang, Yusuke Hirota

Agentic multimodal large language models (MLLMs) have recently pushed the frontier of visual reasoning by calling tools such as zooming and tagging. Despite the recent strong success of agentic MLLMs, this work uncovers a critical safety failure in the tool-use paradigm: agentic tool-using MLLMs become less capable of refusing harmful requests.

Beware EviLLM: Enabling Vulnerability Injection via Large Language Models

arXiv · Zeezoo Ryu, Simon Chung, Muhammad Faraz Karim, Anna Raymaker, Karan Singh Jodha, Yash Chaturvedi, Sukarno Mertoguno

Advances in large language models (LLMs) have enabled AI-driven code generation from natural language specifications, introducing new attack surfaces for injecting vulnerabilities into software. Prior work has studied this problem only in benign settings where vulnerabilities are introduced inadvertently, or under unconventional threat models where the LLM itself is malicious (backdooring) or the user is the attacker (jailbreaking).

Self-Propagating Misalignment in LLM Agents, and Why Auditing or Disabling Memory Is Not Enough

arXiv · Debeshee Das, Jacqueline Tay, Bruce Tsai, David Huang, Javier Rando

Memory poisoning attacks on LLM agents typically assume an external adversary who plants content in the agent's persistent memory to steer its behavior. We instead study, with no adversary involved, whether a misaligned agent can write a goal it cannot yet act on to persistent memory, so that a future aligned agent carries it out when the opportunity arises.

Agentic-ZTA: A Multi-Agent Architecture for Autonomous Zero Trust Enforcement

arXiv · Shovan Roy, Lopamudra Praharaj, Maanak Gupta, Bhavani Thuraisingham

Agentic AI is emerging as a promising paradigm for automating complex cybersecurity decisions, yet its use in enforcing zero trust introduces significant challenges in safety, reliability, and policy compliance. This paper presents Agentic AI based zero trust architecture (Agentic-ZTA) that operationalizes the NIST SP 800-207 ZTA architecture control loop through coordinated multi- agent decision pipeline.

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Research