[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-benchmark-finds-ai-safety-monitors-catch-attacks-too-late":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},10629,"benchmark-finds-ai-safety-monitors-catch-attacks-too-late","Benchmark Finds AI Safety Monitors Catch Attacks Too Late","A new benchmark shows AI monitors catch injection and decomposition attacks overall, but fail to flag decomposition attacks before harm is done.","Researchers built a benchmark that asks not just whether an AI agent's safety monitor catches misuse, but whether it catches it in time.\n\nThe team released a set of roughly 6,200 transcripts testing agent monitors against two separate threats: prompt injection, where a compromised tool slips in a malicious instruction, and decomposition attacks, where a harmful request gets split into innocent-looking sub-steps. Each transcript is labeled with a harm window, the span between when the agent first commits to a harmful action and when it finishes carrying it out. Across 17 monitor setups, monitors that watch the agent's actions rather than its raw text scored well on both threats, with an AUC of 0.95 on decomposition and 0.99 on injection. Monitors that only read conversation content collapsed on injection attacks, scoring just 0.52, barely better than a coin flip.\n\nThe more interesting finding is about timing, not accuracy. Even the strongest monitors struggled to flag decomposition attacks while they were actually unfolding, often catching them too early or too late to land inside the harm window. That matters more for real deployments than a headline AUC number, since a monitor that notices harm only after the agent has finished acting is not doing much safeguarding.\n\nMost agent-safety evaluations still ask a simple yes-or-no question about whether a trajectory was harmful. This one suggests that framing has been letting monitors look better than they actually are at the one thing that counts in production: catching trouble while there is still time to stop it.","[\"ai-safety\",\"prompt-injection\",\"ai-agents\",\"benchmarks\"]","2026-10-07T04:00:00.000Z","2026-10-09T00:00:49.249Z","2026-10-09T00:00:54.668Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek claims monitors struggle to flag prompt injection in time, but the source and body actually show injection detection scores highest (AUC 0.99) and it's decomposition attacks that monitors fail to localize in time — fix the dek to correctly attribute the timing\u002Flocalization weakness to decomposition attacks, not injection.","resolved","ai",[32,33,34,35],"ai-safety","prompt-injection","ai-agents","benchmarks",[37],{"name":38,"url":39},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.07089",0,{"sections":42},[43,47,51,56,61,65,69,74,79,84,88,93,98,103],{"name":44,"slug":30,"count":45,"latest_published_at":46},"AI",6778,"2026-10-09T04:00:00.000Z",{"name":48,"slug":49,"count":50,"latest_published_at":46},"Security","security",932,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",486,"2026-10-08T22:40:11.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",474,"2026-10-08T22:00:00.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":46},"Hardware","hardware",232,{"name":66,"slug":67,"count":68,"latest_published_at":46},"Science","science",193,{"name":70,"slug":71,"count":72,"latest_published_at":73},"Consumer Tech","consumer-tech",181,"2026-10-08T23:26:35.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Startups","startups",117,"2026-10-08T16:45:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Software","software",114,"2026-10-08T17:57:01.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":46},"Dev Tools","dev-tools",106,{"name":89,"slug":90,"count":91,"latest_published_at":92},"General","general",66,"2026-10-09T04:46:11.000Z",{"name":94,"slug":95,"count":96,"latest_published_at":97},"Gaming","gaming",58,"2026-10-08T20:08:45.000Z",{"name":99,"slug":100,"count":101,"latest_published_at":102},"Reviews","reviews",34,"2026-10-08T14:00:22.000Z",{"name":104,"slug":105,"count":106,"latest_published_at":107},"How-To","how-to",8,"2026-10-05T09:00:00.000Z"]