Skip to content

[new-research] arXiv:2609.30266 — LLM Agents Can Easily Tamper With Their Own Traces #170

Description

@github-actions

New arXiv Research Paper

arXiv ID: 2609.30266
Title: LLM Agents Can Easily Tamper With Their Own Traces
Authors: Jeremy Qin, David Schmotz, Derck Prinzhorn, Luca Beurer-Kellner, Ameya Prabhu, Maksym Andriushchenko
Published: 2026-09-24T17:59:54Z
URL: https://arxiv.org/abs/2609.30266

Abstract (first 300 chars)

Asynchronous monitoring, incident investigations, and compliance audits primarily rely on agent traces to reconstruct what happened. These analyses assume that LLM agents cannot tamper with their own execution traces. We show that local LLM agents such as Claude Code, Codex, Antigravity, Open Code a…

Suggested OWASP Mapping

ASI01, ASI02

Suggested Action

Review this paper against the OWASP GenAI Crosswalk entries and update relevant mapping files if new attack patterns or mitigations are identified.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions