{"slug": "agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination", "title": "AgentLSD: Evaluating AI Security Agents Under Adversarial Task Contamination", "summary": "Researchers submitted AgentLSD, a controlled framework for evaluating AI security agents under adversarial task contamination, to arXiv on 16 Sep 2026. Testing six models on 11 web Capture the Flag challenges, the framework found agents captured 41% of flags in clean conditions, while injected trap artifacts such as fake flags and decoy endpoints increased turns by 20 and reasoning tokens by 2k even when the flag was still recovered. The authors released the framework, configurations, trap specifications, and raw traces, arguing clean CTF performance understates vulnerability to deceptive task evidence.", "body_md": "# Computer Science > Cryptography and Security\n\n  [Submitted on 16 Sep 2026]\n\n# Title:AgentLSD: Evaluating AI Security Agents Under Adversarial Task Contamination\n\n[View PDF](http://arxiv.org/pdf/2609.19140v1)\n\n[HTML (experimental)](https://arxiv.org/html/2609.19140v1)\n\nAbstract:AI agents for security inspect web pages, source code, logs, configuration files, and command outputs. These environments may contain deceptive artifacts that influence the agent's behavior. We call this adversarial task contamination. Whereas prompt injection relies on attacker-supplied instructions, task contamination also includes non-instructional evidence, such as fake results and decoy endpoints. We present AgentLSD, a controlled framework for studying adversarial task contamination. AgentLSD uses Capture the Flag (CTF) challenges as its experimental environment. We inject trap artifacts, such as fake flags, misleading hints, decoy endpoints, and hidden cues, while preserving the intended CTF solution. The framework supports paired clean and trap-augmented experiments with deterministic trap generation, runtime injection, telemetry, and delivery verification. We evaluate six models on 11 web CTF challenges. In the clean condition, agents capture 41% of the flags, and no model solves every challenge. We then measure the impact of task contamination. Even when the agent still recovers the flag, traps increase the number of turns (+20) and reasoning tokens (+2k). Solve-rate effects are more heterogeneous, as some model-challenge pairs are largely unaffected while others follow decoys or submit wrong flags. These results show that clean CTF performance understates vulnerability to deceptive task evidence. AgentLSD isolates this effect and provides a reproducible benchmark for studying it. We release the framework, configurations, trap specifications, and raw traces.\n    \n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer \n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers \n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps \n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations \n\n*(*[What are Smart Citations?](https://www.scite.ai/))\n# Code, Data and Media Associated with this Article\n\nalphaXiv \n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers \n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub \n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub \n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face \n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast \n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))\n# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower \n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender \n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))\n# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination", "canonical_source": "http://arxiv.org/abs/2609.19140v1", "published_at": "2026-09-17 14:03:41+00:00", "updated_at": "2026-09-17 14:23:26.312565+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research", "artificial-intelligence"], "entities": ["AgentLSD", "arXiv", "Capture the Flag"], "alternates": {"html": "https://wpnews.pro/news/agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination", "markdown": "https://wpnews.pro/news/agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination.md", "text": "https://wpnews.pro/news/agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination.txt", "jsonld": "https://wpnews.pro/news/agentlsd-evaluating-ai-security-agents-under-adversarial-task-contamination.jsonld"}}