<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Odingard Security blog</title>
    <link>https://blog.odingard.com</link>
    <description>Insights on AI security, runtime protection, AI governance, and compliance automation from Odingard Security.</description>
    <language>en-us</language>
    <pubDate>Sun, 04 Oct 2026 09:14:22 GMT</pubDate>
    <dc:date>2026-10-04T09:14:22Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>Transitive Taint Propagation: Containing Poisoned Writes in Shared Agent State</title>
      <link>https://blog.odingard.com/transitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.odingard.com/transitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.odingard.com/hubfs/blog/transitive-taint-propagation-cover.jpg" alt="Dependency graph: one poisoned write (red) spreads taint (gold) to downstream records while the rest of the shared state stays clean" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Multi-agent AI systems increasingly coordinate through shared state: a common memory, blackboard, or retrieval store that many agents read from and write to. That design makes agents more capable. It also creates a security problem most stacks do not address: if one write is poisoned, honest agents can read it, act on it in good faith, and write new records that carry the poison forward. By the time anyone notices, the damage has spread through the field.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multi-agent AI systems increasingly coordinate through shared state: a common memory, blackboard, or retrieval store that many agents read from and write to. That design makes agents more capable. It also creates a security problem most stacks do not address: if one write is poisoned, honest agents can read it, act on it in good faith, and write new records that carry the poison forward. By the time anyone notices, the damage has spread through the field.&lt;/p&gt; 
&lt;p&gt;This post explains &lt;strong&gt;transitive taint propagation (TTP)&lt;/strong&gt;, a primitive for tracing and containing that spread, and summarizes what our measurements show so far. It draws on two preprints published on Zenodo. Both are preprints and have not been peer reviewed.&lt;/p&gt; 
&lt;div class="od-findings"&gt;
 &lt;p class="od-findings__label"&gt;Key findings&lt;/p&gt; 
 &lt;ol&gt; 
  &lt;li&gt;Across three model families (Claude Haiku 4.5, Claude Sonnet 4.5, and Gemini 2.5 Flash), a read-relevance gate raised blast-radius precision from 80% to 100% in the same threshold band.&lt;/li&gt; 
  &lt;li&gt;Across six agent topologies, precision reached 100% in every one. The recall cost varied by workload and is reported per topology.&lt;/li&gt; 
  &lt;li&gt;Ground truth cannot be assumed. Under-declared dependencies were about 0% in five topologies and 50% in one (plan-execute).&lt;/li&gt; 
  &lt;li&gt;Two instrumentation fixes closed specific gaps: cross-session recall rose from 33% to 100%, and plan-execute precision rose from 46.2% to 88.5%.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/div&gt; 
&lt;h2&gt;The Unverified-Writer Gap&lt;/h2&gt; 
&lt;p&gt;Shared-state systems usually answer two questions well. Authentication tells you who wrote a record. Concurrency control tells you when writes happen and in what order. Neither tells you whether a write is trustworthy before it becomes shared reality, and neither traces what happened downstream once a write turns out to be bad.&lt;/p&gt; 
&lt;p&gt;We call this the &lt;strong&gt;unverified-writer gap&lt;/strong&gt;. Trust in a shared field is transitive. An honest agent can read a poisoned record and produce a derived record of its own, under its own valid identity. Every access check passes. The poison has now been laundered through an agent you trust.&lt;/p&gt; 
&lt;p&gt;This is the same pattern that makes indirect prompt injection dangerous for single agents, scaled up to a whole system. One injected record can become many.&lt;/p&gt; 
&lt;h2&gt;How Transitive Taint Propagation Works&lt;/h2&gt; 
&lt;p&gt;TTP does three things.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Record dependencies at write time.&lt;/strong&gt; When an agent writes to shared state, the system records which earlier records the write depended on. Those links form a trust-dependency graph.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Compute the blast radius on detection.&lt;/strong&gt; When a record is later identified as poisoned, the system walks the graph forward to find every downstream write that depended on it, directly or through a chain of other writes.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Contain the tainted subgraph.&lt;/strong&gt; Those records are quarantined. The rest of the field keeps running, and nothing has to be re-verified from scratch.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The key design choice is recording provenance at write time. Trying to reconstruct dependencies after an incident is slow and unreliable. Recording them as writes happen makes containment a graph traversal.&lt;/p&gt; 
&lt;p&gt;The first paper specifies the model, the propagation rule, and the containment operation. It argues for three properties a correct implementation needs: containment soundness (everything that depended on the poison is caught), bounded over-containment (it does not quarantine far more than necessary), and tractability at scale. It also states plainly what remains to be proven formally and shown empirically.&lt;/p&gt; 
&lt;h2&gt;What We Measured&lt;/h2&gt; 
&lt;p&gt;The empirical companion tested TTP on real, instrumented agent traces rather than only a synthetic oracle. The question it set out to answer was generalization: does the approach hold beyond one model and one agent layout?&lt;/p&gt; 
&lt;h3&gt;It holds across model families&lt;/h3&gt; 
&lt;p&gt;The method depends on a premise: when an agent reads a record and then writes, the write actually derives from what it read. That premise held in all three model families tested. Adding a read-relevance gate, which filters out reads that did not actually influence a write, lifted blast-radius precision from 80% to 100%. The same threshold band worked for every family.&lt;/p&gt; 
&lt;h3&gt;It holds across topologies, with a recall cost&lt;/h3&gt; 
&lt;p&gt;Across six agent topologies, the gate reached 100% precision in each. Recall did not always reach 100%. The losses fell where the paper's two published boundaries predict: dependencies carried across sessions, and information that is paraphrased so heavily it no longer matches. Each cost is reported per workload rather than averaged away.&lt;/p&gt; 
&lt;h3&gt;Ground truth has to be measured&lt;/h3&gt; 
&lt;p&gt;The method relies on agents' recorded dependencies being complete. In five of six topologies, under-declaration was about 0%. In the plan-execute topology it was 50%. That is the most important practical lesson in the study: you cannot assume your dependency records are complete. You have to measure them for each workload.&lt;/p&gt; 
&lt;h3&gt;Two gaps were closed with better instrumentation&lt;/h3&gt; 
&lt;ul&gt; 
 &lt;li&gt;An observable carry channel recovered a cross-session dependency edge, raising recall on a no-re-read handoff from 33% to 100%.&lt;/li&gt; 
 &lt;li&gt;Logging inputs at the retrieval layer, instead of relying on what agents self-report, raised measured precision on plan-execute from 46.2% to 88.5%.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Why This Matters for Security Teams&lt;/h2&gt; 
&lt;p&gt;Most agent security today focuses on a single agent and a single action: should this tool call be allowed? That is necessary. It does not answer what happens after a bad write gets into shared memory and other agents start building on it.&lt;/p&gt; 
&lt;p&gt;TTP gives incident response a concrete answer to three questions: what did this poisoned record touch, what can we safely keep running, and how do we prove the scope of the incident to an auditor? Because dependencies are recorded as writes happen, the answer is a graph query, not a forensic reconstruction.&lt;/p&gt; 
&lt;p&gt;It also changes how you instrument agents. The results show that dependency records are only as good as the place you capture them. Self-reported provenance can miss half the edges in some topologies. Capturing inputs at the retrieval layer is more reliable.&lt;/p&gt; 
&lt;h2&gt;Limits and Open Questions&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;Both papers are preprints and have not been peer reviewed.&lt;/li&gt; 
 &lt;li&gt;Formal proofs of the containment properties are stated as open work, not completed.&lt;/li&gt; 
 &lt;li&gt;Recall drops under cross-session carry and heavy paraphrase unless extra instrumentation is added.&lt;/li&gt; 
 &lt;li&gt;Correct containment can itself be turned into an attack, by steering poison so that containment disables large amounts of legitimate state. Our later work on containment denial-of-service examines that problem directly.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Read the Papers&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;Byrd, A. Transitive Taint Propagation for Shared Agent State: A Trust Primitive for the Verified Field. Zenodo preprint. &lt;a href="https://doi.org/10.5281/zenodo.20786402"&gt;doi:10.5281/zenodo.20786402&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;Byrd, A. Transitive Taint Propagation for Shared Agent State: Measured Generalization Across Models and Topologies, An Empirical Companion (v0.3). Zenodo preprint. &lt;a href="https://doi.org/10.5281/zenodo.20838847"&gt;doi:10.5281/zenodo.20838847&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;More of our work is listed on the &lt;a href="https://odingard.com/research"&gt;Odingard research page&lt;/a&gt;. For how runtime enforcement fits alongside containment, see &lt;a href="https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems"&gt;Cyber Security and AI: Enterprise Defense in 2026&lt;/a&gt; and &lt;a href="https://odingard.com/cerberus"&gt;Cerberus&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Running multiple agents on shared memory?&lt;/strong&gt; &lt;a href="https://42byke.share-na2.hsforms.com/24kGdkydiR-mx2C1M9cI5TA"&gt;Request an AI agent security assessment&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=245781950&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state&amp;amp;bu=https%253A%252F%252Fblog.odingard.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Research</category>
      <category>AI Agent Security</category>
      <pubDate>Sun, 04 Oct 2026 09:14:22 GMT</pubDate>
      <author>andre.byrd@odingard.com (Andre Byrd)</author>
      <guid>https://blog.odingard.com/transitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state</guid>
      <dc:date>2026-10-04T09:14:22Z</dc:date>
    </item>
    <item>
      <title>Cyber Security and AI: Enterprise Defense in 2026</title>
      <link>https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.odingard.com/hubfs/blog/cyber-security-and-ai-enterprise-defense-2026.jpg" alt="Cyber security and AI: enterprise defense in 2026" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Artificial intelligence now sits on both sides of the security equation. Enterprises use it to detect and contain attacks faster, and they also deploy AI systems that create attack surfaces traditional controls were never built to see. In the World Economic Forum's &lt;a href="https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf"&gt;Global Cybersecurity Outlook 2026&lt;/a&gt;, 94% of surveyed leaders said AI will be the most significant driver of change in cybersecurity this year, and 87% named AI-related vulnerabilities as the fastest-growing cyber risk.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Artificial intelligence now sits on both sides of the security equation. Enterprises use it to detect and contain attacks faster, and they also deploy AI systems that create attack surfaces traditional controls were never built to see. In the World Economic Forum's &lt;a href="https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf"&gt;Global Cybersecurity Outlook 2026&lt;/a&gt;, 94% of surveyed leaders said AI will be the most significant driver of change in cybersecurity this year, and 87% named AI-related vulnerabilities as the fastest-growing cyber risk.&lt;/p&gt; 
&lt;p&gt;That creates a dual mandate: use AI to strengthen defense, and secure the AI you deploy. This guide covers both, with a focus on the second, which is where most organizations are least prepared.&lt;/p&gt; 
&lt;h2&gt;The Dual Nature of AI in Cybersecurity&lt;/h2&gt; 
&lt;p&gt;Attackers use AI to automate reconnaissance, write convincing personalized phishing at scale, and adapt malware to evade signature-based detection. These attacks run at machine speed, which overwhelms teams that rely on manual triage.&lt;/p&gt; 
&lt;p&gt;Defenders use the same technology to establish behavioral baselines, correlate signals across millions of events, and trigger containment in seconds. The organizations that benefit most treat AI as an accelerator for an existing security program, not a replacement for one.&lt;/p&gt; 
&lt;h2&gt;How AI Transforms Threat Detection and Response&lt;/h2&gt; 
&lt;p&gt;AI-driven security delivers value in three areas:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Anomaly detection.&lt;/strong&gt; User and entity behavior analytics (UEBA) and AI-enhanced EDR learn what normal looks like for users, devices, and workloads, then flag deviations such as off-hours access to sensitive databases or unusual data transfers.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Automated response.&lt;/strong&gt; SOAR platforms connected to SIEM, identity, and endpoint tools can isolate a host, disable a compromised account, and preserve forensic evidence within seconds of detection.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Vulnerability prioritization.&lt;/strong&gt; Correlating vulnerability data with threat intelligence and asset criticality focuses limited patching capacity on what attackers are most likely to exploit.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Securing AI Systems: Runtime Protection&lt;/h2&gt; 
&lt;p&gt;AI applications and agents introduce risks that static testing cannot catch. An agent that can read data, call tools, and reach external services can be manipulated through its inputs. Prompt injection tops the &lt;a href="https://genai.owasp.org/llm-top-10/"&gt;OWASP Top 10 for LLM Applications&lt;/a&gt; for that reason.&lt;/p&gt; 
&lt;p&gt;The most dangerous pattern combines three conditions in one agent: privileged access to sensitive data or systems, exposure to untrusted input, and a path to send data out. When all three are present, a single injected instruction can turn a helpful agent into an exfiltration channel.&lt;/p&gt; 
&lt;p&gt;Runtime protection addresses this by monitoring what an AI system actually does in production: inspecting tool calls as they happen, enforcing policy before an action executes, and blocking unsafe actions in real time. Pre-deployment testing still matters, but it cannot anticipate every input an agent will see once it is live.&lt;/p&gt; 
&lt;p&gt;Beyond runtime, AI security covers the full lifecycle: training-data provenance to resist poisoning, model integrity verification, input validation, and adversarial robustness testing.&lt;/p&gt; 
&lt;h2&gt;Governance and Shadow AI&lt;/h2&gt; 
&lt;p&gt;Employees adopt AI assistants, coding tools, and automation agents faster than security teams can review them. Effective governance needs four things: an inventory of AI systems in use, policy controls on which tools are approved, continuous monitoring of AI behavior and data flows, and audit trails that document AI-driven decisions.&lt;/p&gt; 
&lt;p&gt;The WEF report shows progress here: the share of organizations with a process to assess the security of AI tools before deployment rose from 37% in 2025 to 64% in 2026. That still leaves roughly one in three without one.&lt;/p&gt; 
&lt;h2&gt;Compliance for AI Deployments&lt;/h2&gt; 
&lt;p&gt;Regulation is catching up. The EU AI Act sets risk-based obligations, with high-risk systems facing requirements for transparency, human oversight, and technical documentation. For the most serious violations, &lt;a href="https://artificialintelligenceact.eu/article/99/"&gt;fines can reach €35 million or 7% of global annual turnover&lt;/a&gt;, whichever is higher. In the United States, many organizations use the voluntary &lt;a href="https://www.nist.gov/itl/ai-risk-management-framework"&gt;NIST AI Risk Management Framework&lt;/a&gt; as their baseline.&lt;/p&gt; 
&lt;p&gt;Because AI systems change as data and prompts change, compliance cannot be a point-in-time exercise. Regulators increasingly expect continuous evidence: model versions, data lineage, configuration changes, and records of what the system did.&lt;/p&gt; 
&lt;h2&gt;Choosing AI Security Tooling&lt;/h2&gt; 
&lt;p&gt;When evaluating platforms, look at:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Coverage:&lt;/strong&gt; whether the tool secures AI systems themselves, or only uses AI to improve traditional detection.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Enforcement point:&lt;/strong&gt; whether it can block an unsafe action before it executes, or only alert afterward.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Integration:&lt;/strong&gt; fit with your agent frameworks, SIEM, and identity stack.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Evidence:&lt;/strong&gt; audit trails that hold up in a compliance review.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Total cost:&lt;/strong&gt; licensing plus the staff time to tune and operate it.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;How Odingard Security Helps&lt;/h2&gt; 
&lt;p&gt;Odingard Security builds tools for the second half of the dual mandate: securing the AI agents you deploy.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;a href="https://github.com/Odingard/cerberus"&gt;Cerberus&lt;/a&gt;&lt;/strong&gt; is an open-core runtime enforcement engine for AI agents. It inspects tool calls as they happen and blocks the privileged-access, untrusted-input, and exfiltration combination described above. It works with LangChain, OpenAI Agents, Vercel AI, and MCP-based agents.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;a href="https://github.com/Odingard/Argus"&gt;ARGUS&lt;/a&gt;&lt;/strong&gt; is an autonomous AI red team platform. It attacks your agents the way an adversary would, so you find exploitable paths before someone else does.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;strong&gt;Want to know how exposed your agents are today?&lt;/strong&gt; &lt;a href="https://42byke.share-na2.hsforms.com/24kGdkydiR-mx2C1M9cI5TA"&gt;Request an AI agent security assessment&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=245781950&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.odingard.com%2Fai-and-cybersecurity-stronger-defenses-safer-ai-systems&amp;amp;bu=https%253A%252F%252Fblog.odingard.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Sun, 04 Oct 2026 05:15:21 GMT</pubDate>
      <author>andre.byrd@odingard.com (Andre Byrd)</author>
      <guid>https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems</guid>
      <dc:date>2026-10-04T05:15:21Z</dc:date>
    </item>
  </channel>
</rss>
