Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?
This paper investigates how operating system (OS) defenses can prevent self-state attacks on self-hosted AI agents, which involve compromising an agent's own memory and configuration files. Practitioners caring about AI agent security should consider the limitations of current OS defenses against these types of attacks.