cd /news/artificial-intelligence/persistent-semantic-entities-in-tool… · home topics artificial-intelligence article
[ARTICLE · art-91497] src=machinebrief.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Persistent Semantic Entities in Tool-Augmented LLM Systems

A new arXiv study (2608.07952v1) formalizes Persistent Semantic Entities (PSEs) in tool-augmented LLM agents, finding that all 24 tested models from 11 families (1.5B–1T parameters) are susceptible to contamination, with name binding as the necessary mechanism (0% without it). Preference contamination persists undecayed on every model (100% at t=10), instruction contamination persists wherever adopted, and context-isolated self-verification reduces contamination by 20–79% (median 36.5%), while contamination compounds 1.9× along a four-stage agent pipeline (40%→75%).

read1 min views1 publishedAug 11, 2026

arXiv:2608.07952v1 Announce Type: new Abstract: Tool-augmented LLM agents can harbor implicit state that persists across sessions, activates through events, and propagates across agent boundaries---largely invisible to standard debugging. We formalize this as Persistent Semantic Entities (PSEs): constructs defined by name binding, event triggering, and cross-boundary propagation, and evaluate them across 24 models from 11 families (1.5B--1T parameters). First, every tested model is susceptible (20--100% on the 20-model susceptibility panel), with name binding as the necessary and dominant mechanism: without it, contamination is 0%. Second, persistence depends on contamination type rather than scale or deployment: preference contamination persists undecayed on every model probed (100% at t=10) and instruction contamination persists wherever adopted, persona-style injection decays partially (90%$\to$10%), while factual injection is model-dependent---self-corrected on Llama-3.1-8B and GPT-4o-mini but held at ceiling on both Qwen2.5-coder variants, so we do not claim it self-corrects in general. The preference and instruction results hold across providers in our controlled setting. Third, context-isolated self-verification achieves 20--79% reduction (median 36.5%) without oracle references while keyword-based detection produces systematic false positives, and contamination compounds 1.9$\times$ along a four-stage agent pipeline (40%$\to$75%). Preference and instruction contamination---persistent, lacking self-correction, and poorly captured by standard monitoring---represent a particularly concerning attack surface for deployed agent systems.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/persistent-semantic-…] indexed:0 read:1min 2026-08-11 ·