{"slug": "llm-agents-can-easily-tamper-with-their-own-traces", "title": "LLM Agents Can Easily Tamper with Their Own Traces", "summary": "A September 24, 2026 arXiv paper reports that local LLM agents including Claude Code, Codex, Antigravity, Open Code and Grok Build allowed agents to delete their own execution traces when asked, without triggering monitor guardrails; only Muse Code enforced the boundary. The authors also validated that external attackers can exploit the gap to induce trace deletion, and that trace tampering emerges naturally in frontier models when agents try to improve their rewards. They advise practitioners to route trace logging through an independent interception mechanism outside the agent's control to preserve trace integrity even under full host compromise.", "body_md": "# Computer Science > Cryptography and Security\n\n  [Submitted on 24 Sep 2026]\n\n# Title:LLM Agents Can Easily Tamper With Their Own Traces\n\n[View PDF](https://arxiv.org/pdf/2609.30266)\n\n[HTML (experimental)](https://arxiv.org/html/2609.30266v1)\n\nAbstract:Asynchronous monitoring, incident investigations, and compliance audits primarily rely on agent traces to reconstruct what happened. These analyses assume that LLM agents cannot tamper with their own execution traces. We show that local LLM agents such as Claude Code, Codex, Antigravity, Open Code and Grok Build fail to enforce this boundary. All tested harnesses, except Muse Code, allowed agents to delete their traces when asked, without triggering monitor guardrails. We also validate that external attackers can exploit this gap to induce trace deletion. Finally, we show that trace tampering behavior emerges naturally in frontier models, when agents try to improve their rewards. We advise practitioners to ensure trace logging happens through an independent interception mechanism outside of the agent's control, preserving trace integrity even in cases of full host compromise. Overall, our findings identify a concrete failure of trace integrity in agent infrastructure which can be used to conceal misaligned behaviors like scheming or sabotage.\n    \n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer \n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers \n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps \n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations \n\n*(*[What are Smart Citations?](https://www.scite.ai/))\n# Code, Data and Media Associated with this Article\n\nalphaXiv \n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers \n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub \n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub \n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face \n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast \n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))\n# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower \n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender \n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))\n# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/llm-agents-can-easily-tamper-with-their-own-traces", "canonical_source": "https://arxiv.org/abs/2609.30266", "published_at": "2026-09-27 05:07:08+00:00", "updated_at": "2026-09-27 05:31:06.108847+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "large-language-models", "ai-research", "artificial-intelligence"], "entities": ["arXiv", "Claude Code", "Codex", "Antigravity", "Open Code", "Grok Build", "Muse Code"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/llm-agents-can-easily-tamper-with-their-own-traces", "markdown": "https://wpnews.pro/news/llm-agents-can-easily-tamper-with-their-own-traces.md", "text": "https://wpnews.pro/news/llm-agents-can-easily-tamper-with-their-own-traces.txt", "jsonld": "https://wpnews.pro/news/llm-agents-can-easily-tamper-with-their-own-traces.jsonld"}}