[2608.11436] When Agents Talk: Honeytokens under Shared Memory
Skip to main content
Search arXiv
Press Enter to search · Advanced search
-->
Computer Science > Cryptography and Security
arXiv:2608.11436 (cs)
[Submitted on 11 Aug 2026]
Title:When Agents Talk: Honeytokens under Shared Memory
Authors:Joshua S. Gans<br>View a PDF of the paper titled When Agents Talk: Honeytokens under Shared Memory, by Joshua S. Gans
View PDF<br>HTML (experimental)
Abstract:During a 2026 cyber-capability evaluation, short-lived AI agents turned a shared package repository into persistent memory, passing exploit findings to later agents and rebuilding the channel after it was removed. The broader evaluation culminated in an intrusion into Hugging Face. This episode raises a question for defensive deception: can a honeytoken be harmless to trusted agents without becoming recognisable to an attacker who shares their information and can implement the trusted policy? The answer is no. A trusted rule that selects genuine objects while avoiding decoys can be copied by the attacker, while a total-variation bound limits legitimate compatibility when decoys resemble genuine objects. Shared memory creates a second leakage channel by pooling weak fingerprints. For a fixed candidate, repeated non-triggering probes drive the minimum Bayes classification error to zero when type-dependent response laws differ and are known or learnable. If probing triggers containment, learning also requires the coalition to remain active long enough. Transfer across objects requires a stable deployment rule and information that orients the classes. A separate detection bound distinguishes reliable token activation from reliable attack coverage. The architectural response is to keep token identity in a private reference monitor and route legitimate agents through a provenance-enforcing broker. This produces high-confidence detection only for a specified policy violation. Honeytokens remain useful sensors, but a separate security boundary is still required.
Comments:<br>artificial intelligence, cybersecurity, honeytokens, defensive deception, shared memory, intrusion detection
Subjects:
Cryptography and Security (cs.CR)
Cite as:<br>arXiv:2608.11436 [cs.CR]
(or<br>arXiv:2608.11436v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.11436
Focus to learn more
arXiv-issued DOI via DataCite (pending registration)
Submission history<br>From: Joshua Gans [view email]<br>[v1]<br>Tue, 11 Aug 2026 21:03:19 UTC (25 KB)
Full-text links:<br>Access Paper:
View a PDF of the paper titled When Agents Talk: Honeytokens under Shared Memory, by Joshua S. Gans<br>View PDF<br>HTML (experimental)<br>TeX Source
view license
Current browse context:
cs.CR
next >
new<br>recent<br>| 2026-08
Change to browse by:
cs
References & Citations
NASA ADS<br>Google Scholar
Semantic Scholar
export BibTeX citation<br>Loading...
BibTeX formatted citation
×
loading...
Data provided by:
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Code, Data and Media Associated with this Article
alphaXiv Toggle
alphaXiv (What is alphaXiv?)
Links to Code Toggle
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub Toggle
DagsHub (What is DagsHub?)
GotitPub Toggle
Gotit.pub (What is GotitPub?)
Huggingface Toggle
Hugging Face (What is Huggingface?)
ScienceCast Toggle
ScienceCast (What is ScienceCast?)
Demos
Demos
Replicate Toggle
Replicate (What is Replicate?)
Spaces Toggle
Hugging Face Spaces (What is Spaces?)
Spaces Toggle
TXYZ.AI (What is TXYZ.AI?)
Related Papers
Recommenders and Search Tools
Link to Influence Flower
Influence Flower (What are Influence Flowers?)
Core recommender toggle
CORE Recommender (What is CORE?)
Author
Venue
Institution
Topic
About arXivLabs
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs .
Which authors of this paper are endorsers? |<br>Disable MathJax (What is MathJax?)
Major funding support from