Line of inquiry
Inquiring lines›How do we ensure safety, alignment…›How can effective AI defenses with…›this line of inquiry
How vulnerable are token issuance and authorization policies to coordinated attacks?
A broader line of inquiry — a family of 14 specific questions the research asks around this. Follow one into its inquiring-line page, or move sideways to a related line below.
Questions in this line of inquiry 14
Specific inquiring lines the field asks around this — ordered from the most general framing down to the most specific angle.
- Who issues tokens and what attacks can reach them?
- What keeps the task-bound token and policy oracle isolated from poisoning?
- Who issues the task-bound token and when does issuance occur?
- Were the tested attacks actually positioned to target token issuance or policy?
- How much does authorization layer safety cost in false rejections on safe tasks?
- Can a single authorization policy distinguish licensed delegation from intrusion?
- Which of the two authorization components carries the zero percent Unsafe Action Rate?
- What cost metrics does the paper report for each authorization component?
- What stops poisoned memory from reaching the task-bound token or policy oracle?
- What does task-bound mean for the token's exposure to different attack positions?
- How do forged approvals fail differently at token versus policy checks?
- Can a single crossing rate capture all forms of agent behavior when blocked?
- What happens to approval rates when authorization checks are enabled?
- Can the same tool call be both authorized and unauthorized depending on intent?