arXiv:2608. 11632v1 Announce Type: cross Abstract: Persistent AI agents accumulate versioned state across long horizons, but storage retention alone does not identify authoritative state.
By Jun He, Deying Yu
The paper introduces "authorization succession," a framework that preserves authority across self‑modifying AI agent populations that can replace, fork, or roll back. It defines a protocol binding each generation to a manifest, root, unique parent, lineage, and population sequence, and establishes invariants that control root‑lifetime consumption and population exposure. The authors prove properties such as population‑safe succession, fork conservation, and rollback non‑reminting, and validate the approach with an executable evaluation covering 32 decisions and external adapters for two mutation systems.
By Genliang Zhu, Chu Wang
arXiv:2607. 10487v1 Announce Type: cross Abstract: LLM agents can commit durable effects from authority evidence that was valid earlier in execution: a DOM snapshot, approval epoch, version witness, branch token, or worker result.
By Igor Santos-Grueiro
arXiv:2608.21159v1 Announce Type: cross
Abstract: Tool-using AI agents turn delegated tasks into provider effects, yet authorization often ends at admission while provider state, delivery, retry, and...
By Yingzhe Tong, Leyu Dai, Songhui Guo
The paper examines the security challenges of delegating authority to autonomous LLM agents that act on users’ behalf. It introduces a threat model with four adversaries and eight security requirements, demonstrates that current frameworks (LangGraph, CrewAI, AutoGen, MCP) fail to meet these standards, and presents an authorization broker that blocks all identified threats with minimal overhead. The broker is shown to resist numerous attacks and limits compromised sub‑agents to their delegated tasks, and its principles are implemented in VotalAI’s LLM Shield.
By Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi
arXiv:2606. 22504v1 Announce Type: cross Abstract: Coding agents often receive broad tool access for an entire task, even when a resource is needed only for one subgoal.
By Igor Santos-Grueiro