safety security
The Tool Response Lost Its Right to Speak
PIPES checked whether each response fragment had the provenance and semantic authority to make its claim.
Summary
PIPES checked whether each response fragment had the provenance and semantic authority to make its claim.
The researchers describe state-corruption attacks in which attacker-controlled content makes environmental claims beyond the authority of its response field. PIPES screens units against schema-derived or contextual priors plus source provenance. With atomic removal on six benchmark splits, it reduced average attack success from 84.7 to 2.3 percent while reported benign utility changed from 90.6 to 92.5 percent. Those results use one target model and benchmark suite, so deployment behavior remains to be established.
Why it matters
PIPES checked whether each response fragment had the provenance and semantic authority to make its claim.
Limits and context
No additional limitation was separately recorded.
Key claims
PIPES checked whether each response fragment had the provenance and semantic authority to make its claim.
Evidence: source-2026-08-16-004
Sources
- arXiv preprint 2608.12789arXiv · primary research
Corrections
No corrections have been recorded for this story.