EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
cs.CR, cs.AI
Submitted: 2026-08-26
Updated: 2026-08-26
Code: https://github.com/chroma-core/chroma
Terminology
Sources
- Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
- gpt-oss-120b & gpt-oss-20b Model Card
- DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence
- SWE-Bench Pro: Can AI Agents Solve Long-Horizon Software Engineering Tasks?
- Qwen3-Coder-Next Technical Report
- SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems
- LlamaFirewall: An open source guardrail system for building secure AI agents
- MalTool: Malicious Tool Attacks on LLM Agents
- Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
- The Attack and Defense Landscape of Agentic AI: A Comprehensive Survey
- Anatomy of a Machine Learning Ecosystem: 2 Million Models on Hugging Face
- Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies
- Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
- Your Agent May Misevolve: Emergent Risks in Self-evolving LLM Agents
- Progent: Securing AI Agents with Privilege Control
- A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents
- BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs