---
title: "Transitive Taint Propagation: Containing Poisoned Writes in Shared Agent State"
description: How transitive taint propagation traces and contains a poisoned write in shared AI agent memory, with measured results across three model families.
image: https://blog.odingard.com/hubfs/blog/transitive-taint-propagation-cover.jpg
---

[Skip to content](https://blog.odingard.com/transitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state#main-content)

Odingard Security

Get started

Get started

![Dependency graph: one poisoned write (red) spreads taint (gold) to downstream records while the rest of the shared state stays clean](https://blog.odingard.com/hs-fs/hubfs/blog/transitive-taint-propagation-cover.jpg?width=1600&height=900&name=transitive-taint-propagation-cover.jpg)

Research AI Agent Security

# Transitive Taint Propagation: Containing Poisoned Writes in Shared Agent State

![Andre Byrd](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Andre Byrd

October 4, 2026

Multi-agent AI systems increasingly coordinate through shared state: a common memory, blackboard, or retrieval store that many agents read from and write to. That design makes agents more capable. It also creates a security problem most stacks do not address: if one write is poisoned, honest agents can read it, act on it in good faith, and write new records that carry the poison forward. By the time anyone notices, the damage has spread through the field.

This post explains **transitive taint propagation (TTP)**, a primitive for tracing and containing that spread, and summarizes what our measurements show so far. It draws on two preprints published on Zenodo. Both are preprints and have not been peer reviewed.

Key findings

1. Across three model families (Claude Haiku 4.5, Claude Sonnet 4.5, and Gemini 2.5 Flash), a read-relevance gate raised blast-radius precision from 80% to 100% in the same threshold band.
2. Across six agent topologies, precision reached 100% in every one. The recall cost varied by workload and is reported per topology.
3. Ground truth cannot be assumed. Under-declared dependencies were about 0% in five topologies and 50% in one (plan-execute).
4. Two instrumentation fixes closed specific gaps: cross-session recall rose from 33% to 100%, and plan-execute precision rose from 46.2% to 88.5%.

## The Unverified-Writer Gap

Shared-state systems usually answer two questions well. Authentication tells you who wrote a record. Concurrency control tells you when writes happen and in what order. Neither tells you whether a write is trustworthy before it becomes shared reality, and neither traces what happened downstream once a write turns out to be bad.

We call this the **unverified-writer gap**. Trust in a shared field is transitive. An honest agent can read a poisoned record and produce a derived record of its own, under its own valid identity. Every access check passes. The poison has now been laundered through an agent you trust.

This is the same pattern that makes indirect prompt injection dangerous for single agents, scaled up to a whole system. One injected record can become many.

## How Transitive Taint Propagation Works

TTP does three things.

1. **Record dependencies at write time.** When an agent writes to shared state, the system records which earlier records the write depended on. Those links form a trust-dependency graph.
2. **Compute the blast radius on detection.** When a record is later identified as poisoned, the system walks the graph forward to find every downstream write that depended on it, directly or through a chain of other writes.
3. **Contain the tainted subgraph.** Those records are quarantined. The rest of the field keeps running, and nothing has to be re-verified from scratch.

The key design choice is recording provenance at write time. Trying to reconstruct dependencies after an incident is slow and unreliable. Recording them as writes happen makes containment a graph traversal.

The first paper specifies the model, the propagation rule, and the containment operation. It argues for three properties a correct implementation needs: containment soundness (everything that depended on the poison is caught), bounded over-containment (it does not quarantine far more than necessary), and tractability at scale. It also states plainly what remains to be proven formally and shown empirically.

## What We Measured

The empirical companion tested TTP on real, instrumented agent traces rather than only a synthetic oracle. The question it set out to answer was generalization: does the approach hold beyond one model and one agent layout?

### It holds across model families

The method depends on a premise: when an agent reads a record and then writes, the write actually derives from what it read. That premise held in all three model families tested. Adding a read-relevance gate, which filters out reads that did not actually influence a write, lifted blast-radius precision from 80% to 100%. The same threshold band worked for every family.

### It holds across topologies, with a recall cost

Across six agent topologies, the gate reached 100% precision in each. Recall did not always reach 100%. The losses fell where the paper's two published boundaries predict: dependencies carried across sessions, and information that is paraphrased so heavily it no longer matches. Each cost is reported per workload rather than averaged away.

### Ground truth has to be measured

The method relies on agents' recorded dependencies being complete. In five of six topologies, under-declaration was about 0%. In the plan-execute topology it was 50%. That is the most important practical lesson in the study: you cannot assume your dependency records are complete. You have to measure them for each workload.

### Two gaps were closed with better instrumentation

- An observable carry channel recovered a cross-session dependency edge, raising recall on a no-re-read handoff from 33% to 100%.
- Logging inputs at the retrieval layer, instead of relying on what agents self-report, raised measured precision on plan-execute from 46.2% to 88.5%.

## Why This Matters for Security Teams

Most agent security today focuses on a single agent and a single action: should this tool call be allowed? That is necessary. It does not answer what happens after a bad write gets into shared memory and other agents start building on it.

TTP gives incident response a concrete answer to three questions: what did this poisoned record touch, what can we safely keep running, and how do we prove the scope of the incident to an auditor? Because dependencies are recorded as writes happen, the answer is a graph query, not a forensic reconstruction.

It also changes how you instrument agents. The results show that dependency records are only as good as the place you capture them. Self-reported provenance can miss half the edges in some topologies. Capturing inputs at the retrieval layer is more reliable.

## Limits and Open Questions

- Both papers are preprints and have not been peer reviewed.
- Formal proofs of the containment properties are stated as open work, not completed.
- Recall drops under cross-session carry and heavy paraphrase unless extra instrumentation is added.
- Correct containment can itself be turned into an attack, by steering poison so that containment disables large amounts of legitimate state. Our later work on containment denial-of-service examines that problem directly.

## Read the Papers

- Byrd, A. Transitive Taint Propagation for Shared Agent State: A Trust Primitive for the Verified Field. Zenodo preprint. [doi:10.5281/zenodo.20786402](https://doi.org/10.5281/zenodo.20786402)
- Byrd, A. Transitive Taint Propagation for Shared Agent State: Measured Generalization Across Models and Topologies, An Empirical Companion (v0.3). Zenodo preprint. [doi:10.5281/zenodo.20838847](https://doi.org/10.5281/zenodo.20838847)

More of our work is listed on the [Odingard research page](https://odingard.com/research). For how runtime enforcement fits alongside containment, see [Cyber Security and AI: Enterprise Defense in 2026](https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems) and [Cerberus](https://odingard.com/cerberus).

**Running multiple agents on shared memory?** [Request an AI agent security assessment](https://42byke.share-na2.hsforms.com/24kGdkydiR-mx2C1M9cI5TA).

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state><https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state>[mailto:https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state](mailto:https%3A%2F%2Fblog.odingard.com%2Ftransitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state)

## Keep reading

### [![Cyber security and AI: enterprise defense in 2026](https://blog.odingard.com/hs-fs/hubfs/blog/cyber-security-and-ai-enterprise-defense-2026.jpg?width=1376&height=768&name=cyber-security-and-ai-enterprise-defense-2026.jpg) Cyber Security and AI: Enterprise Defense in 2026](https://blog.odingard.com/ai-and-cybersecurity-stronger-defenses-safer-ai-systems)

# Odingard Security

<https://www.linkedin.com><https://www.facebook.com><https://www.twitter.com><https://www.instagram.com><https://www.tiktok.com>

---

Privacy Policy · Legal · © 2026 Odingard Security. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andre Byrd",
    "url" : "https://blog.odingard.com/author/andre-byrd"
  },
  "dateModified" : "2026-10-04T09:14:22.254Z",
  "datePublished" : "2026-10-04T09:14:22.000Z",
  "headline" : "Transitive Taint Propagation: Containing Poisoned Writes in Shared Agent State",
  "image" : [ "https://blog.odingard.com/hubfs/blog/transitive-taint-propagation-cover.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.odingard.com/transitive-taint-propagation-containing-poisoned-writes-in-shared-agent-state",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Odingard Security"
  }
}
```