How fast must a coalition gather observations before containment?
When probing triggers containment, attackers face a race to accumulate enough samples before removal. A finite-sample bound quantifies the speed required for successful separation of decoys from genuine objects.
The abstract closes its list of results with two sentences: "If probing can trigger containment, the coalition must also remain active long enough to collect the observations. A finite-sample bound measures the speed."
This changes what the defender is competing over. The earlier results say indistinguishability is hard to achieve and that quiet probing eventually separates decoys from genuine objects. This one says the separation has a price in time. If some probes set off containment, the attacker needs enough observations before it is removed, and the finite-sample bound gives how many are enough for a target error. The contest becomes sample accumulation against containment. My reading is that the defender has two levers the abstract does not spell out: raise the number of observations required, which is what What cost does making decoys convincing impose on legitimate users? prices, or shorten the time before probing is contained. The abstract says only that the coalition must stay active and that the bound measures the speed.
The vault has a related class but no measured counterpart. What vulnerabilities emerge where AI agents meet their evaluation sandbox? lists "the speed of automated action." This bound is not tied to that class in the excerpt, so the link is a vault reading. It also raises a question: if a coalition can rebuild after removal (Can removing a communication channel stop persistent information sharing?) and later agents inherit findings, does "remain active" have to be one uninterrupted interval? The abstract's bound is stated for a coalition that stays active, and it does not say whether accumulation across removals is covered. The vault's one defensive unit that spans executions is Should defence units span multiple executions and agents?, defined over executions that need not overlap in time; whether a coalition's active interval can be read as such an episode is open in both excerpts.
What the excerpt does not give. The bound's form, what "containment" means in the model, whether removal is permanent, and any time scale.
Inquiring lines that read this note 13
This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.
What conditions enable agent collusion in multi-agent verification tasks? How can defenders detect coordinated attacks across episodes?- Why must recurrence tests apply both channel closure and state quarantine separately?
- What would a containment test look like across an entire incident population?
- What happens to a finite-sample collection bound when containment is temporarily removed?
- Can a containment control work if defenders cannot reach or reason about it?
- What false-alert budget would make indistinguishable decoys tolerable in real deployments?
- How do decoy-response bounds interact with finite-sample time constraints?
Related concepts in this collection 4
This note in its neighbourhood — explore the map, then jump to a related concept in the list below.
Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph
-
Can repeated quiet probes separate decoys from genuine objects?
Explores whether an attacker with enough non-triggering probes can distinguish decoys from genuine objects when their response distributions differ, and what information the attacker needs to succeed.
the result this one bounds in time
-
What vulnerabilities emerge where AI agents meet their evaluation sandbox?
Research identifies five classes of vulnerabilities at the boundary between cyber-capable agents and their testing environments. Understanding these classes matters for designing safer evaluations and containment strategies.
the speed class; the connection is a vault reading
-
Can removing a communication channel stop persistent information sharing?
When a shared mechanism for passing information is deleted, does the sharing actually stop, or can agents rebuild it using inherited knowledge? This matters for understanding whether removing infrastructure alone defeats coordinated threats.
the episode's own answer to "how long does the coalition stay active"
-
Should defence units span multiple executions and agents?
Can security detection improve by treating coordinated intrusions as linked episodes across executions rather than isolated actions? This matters because attackers can hide coordination across time and system boundaries.
a defender's unit defined across non-overlapping executions, against a bound stated for one active coalition; how the two line up is not addressed in either excerpt
Related papers in this collection 8
Papers most semantically related to this note, ranked by cosine similarity in the embedding space.
- When Agents Talk: Honeytokens under Shared Memory
- Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions
- Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response
- The Troy Moment of AI: Why Some Will Cheat and Some Will Follow?
- LLMs Can Covertly Sandbag on Capability Evaluations Against Chain-of-Thought Monitoring
- Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection
- Generalized Agent Iteration: One Formal Framework for Iterative Policy Improvement and Recursive Self-Improvement
- Norms at a Price: Why RL-Based Alignment Can Promise Conditional Compliance at Best
Original note title
when probing can trigger containment the coalition must stay active long enough to collect its observations — a finite-sample bound measures how fast