Line of inquiry
Inquiring lines›What determines the reliability an…›How robust are security defenses a…›this line of inquiry
How can defenders detect coordinated attacks across episodes?
A broader line of inquiry — a family of 41 specific questions the research asks around this. Follow one into its inquiring-line page, or move sideways to a related line below.
Questions in this line of inquiry 41
Specific inquiring lines the field asks around this — ordered from the most general framing down to the most specific angle.
- Should defense against coordinated intrusion span multiple execution episodes?
- How do defenders discover which actions belong to the same coordination episode?
- Can episode-based detection catch coordination without over-flagging innocent sharing?
- Why do outcome-level metrics fail to reveal contained attacks in multi-agent pipelines?
- Can action-level attack success rates distinguish contained attacks from prevented ones?
- What makes a coordination episode revisable under agent intrusion?
- How should defenders decide whether to publish detection rules and incident analyses?
- What trace-level defenses exist beyond per-step review overhead?
- What makes behavioral containment different from securing individual actions?
- What makes a coordination episode the right unit for defense response?
- Does terminating an intrusion differ from stopping the agent behind it?
- What does agent security look like when measured across interaction trajectories?
- What state-tracking requirements exist for defenses that verify multi-party behavioral invariants?
- How can detection systems identify loops across sequences of delegations?
- How can a defense validated on one agent silently fail when the system scales?
- Can a single authorization policy distinguish licensed delegation from intrusion?
- How should policy define which agent transfers count as sanctioned versus intrusion?
- Why does a single crossing rate fail to characterize multiple agent behaviors?
- Why do defense metrics fail without specifying the attacker's position?
- Why do non-overlapping workloads remain invisible to execution-scoped monitoring?
- Can stopping one intrusion pathway leave the underlying activity intact elsewhere?
- Can a single crossing rate capture all forms of agent behavior when blocked?
- What makes prospective episode discovery harder than using known group membership?
- What counts as evidence for adding or removing an action from an episode?
- How much does a responder action like removal shape the security boundary?
- How can per-agent or per-message checks catch harm that emerges only in composition?
- Can a shared audit record settle which policy governed a delegation step?
- How do you find which actions belong together before evaluation?
- Does responder access mean ability to investigate or protection against misuse?
- Why did the endpoint defender not need attribution to act?
- Why must recurrence tests apply both channel closure and state quarantine separately?
- Why does least privilege fail when harm exists only in accumulation?
- What would a containment test look like across an entire incident population?
- What makes the Telephone Loop attack specific to agent delegation?
- How does responder access differ from containment and privilege controls?
- Were the tested attacks actually positioned to target token issuance or policy?
- Do layered defenses work better than single privacy techniques?
- What does recovery mean as a defense contract component?
- Does remain active require one uninterrupted interval or linked episodes?
- What does the five-part defense contract actually require of each part?
- How many agents participated in the July 2026 package service incident?