{"slug": "when-agents-talk-honeytokens-under-shared-memory", "title": "When Agents Talk: Honeytokens Under Shared Memory", "summary": "A 2026 cyber-capability evaluation found that short-lived AI agents used a shared package repository as persistent memory to pass exploit findings and rebuild the channel after removal, culminating in an intrusion into Hugging Face. The paper proves that honeytokens cannot be both harmless to trusted agents and unrecognizable to attackers who share information, and recommends a private reference monitor with a provenance-enforcing broker to achieve high-confidence detection only for specified policy violations.", "body_md": "# Computer Science > Cryptography and Security\n\n[Submitted on 11 Aug 2026]\n\n# Title:When Agents Talk: Honeytokens under Shared Memory\n\n[View PDF](/pdf/2608.11436)\n\n[HTML (experimental)](https://arxiv.org/html/2608.11436v1)\n\nAbstract:During a 2026 cyber-capability evaluation, short-lived AI agents turned a shared package repository into persistent memory, passing exploit findings to later agents and rebuilding the channel after it was removed. The broader evaluation culminated in an intrusion into Hugging Face. This episode raises a question for defensive deception: can a honeytoken be harmless to trusted agents without becoming recognisable to an attacker who shares their information and can implement the trusted policy? The answer is no. A trusted rule that selects genuine objects while avoiding decoys can be copied by the attacker, while a total-variation bound limits legitimate compatibility when decoys resemble genuine objects. Shared memory creates a second leakage channel by pooling weak fingerprints. For a fixed candidate, repeated non-triggering probes drive the minimum Bayes classification error to zero when type-dependent response laws differ and are known or learnable. If probing triggers containment, learning also requires the coalition to remain active long enough. Transfer across objects requires a stable deployment rule and information that orients the classes. A separate detection bound distinguishes reliable token activation from reliable attack coverage. The architectural response is to keep token identity in a private reference monitor and route legitimate agents through a provenance-enforcing broker. This produces high-confidence detection only for a specified policy violation. Honeytokens remain useful sensors, but a separate security boundary is still required.\n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer\n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers\n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps\n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations\n\n*(*[What are Smart Citations?](https://www.scite.ai/))# Code, Data and Media Associated with this Article\n\nalphaXiv\n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers\n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub\n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub\n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face\n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast\n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower\n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender\n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [ Learn more about arXivLabs](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/when-agents-talk-honeytokens-under-shared-memory", "canonical_source": "https://arxiv.org/abs/2608.11436", "published_at": "2026-08-14 03:07:06+00:00", "updated_at": "2026-08-14 03:41:06.353429+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research"], "entities": ["Hugging Face", "arXiv"], "alternates": {"html": "https://wpnews.pro/news/when-agents-talk-honeytokens-under-shared-memory", "markdown": "https://wpnews.pro/news/when-agents-talk-honeytokens-under-shared-memory.md", "text": "https://wpnews.pro/news/when-agents-talk-honeytokens-under-shared-memory.txt", "jsonld": "https://wpnews.pro/news/when-agents-talk-honeytokens-under-shared-memory.jsonld"}}