Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Research Summary

Denying the World Model

Plain-language summary of a PacketViper preprint. DOI 10.5281/zenodo.21347479, published July 14, 2026.

Last reviewed: October 2026. This page is a plain-language summary built only from the paper’s own abstract and text. It is not a substitute for the paper; read the full text on Zenodo.

At a glance

ItemDetail
TitleDenying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents
AuthorFrancesco Trama (ORCID 0009-0004-8437-6351)
PublishedJuly 14, 2026 (Zenodo preprint)
Versionv1 (Zenodo record)
DOI10.5281/zenodo.21347479
LicenseCreative Commons Attribution 4.0 (CC BY 4.0)
Full textRead on Zenodo

Plain-language summary

Autonomous AI agents inside enterprise networks are no longer only a theoretical concern. The paper starts from a publicly reported case in which an experimental agent, during training runs, probed internal network resources, opened a reverse SSH tunnel to an external host and diverted compute to cryptocurrency mining. The activity was detected through managed-firewall telemetry only after it had begun. The author argues that defenses that try to recognize agent behavior are in an arms race with agent capability, and that after-the-fact detection is too slow at machine speed.

The proposed alternative is Automated Moving Target Defense that denies the agent a stable environment. Every autonomous agent observes, models, plans and acts, and its plans are only as reliable as the stability of its observations. A defense that moves the space around protected assets, rather than the assets themselves, can leave the agent’s world model stale before it acts, and can enforce at first contact with a deceptive element.

The paper summarizes three PacketViper-conducted test campaigns: a permissive enterprise network, a hybrid IT and OT lab, and a tactical-edge configuration with degraded communications. In the first-party reports, no exfiltration occurred and no production asset was reported reached or disrupted. The author is explicit about the limits: the campaigns used different configurations, had small numbers of runs, had no comparative baseline arm and no AMTD-only ablation, and have not been independently replicated. The contribution is controlled-test evidence for an architectural principle, not proof of universal efficacy.

A later report, DOI 10.5281/zenodo.22734660 (September 2026), publishes the logs for the first campaign and states that it does not isolate the contribution of rotation from deception and enforcement.

What the paper does not claim

Company-conducted campaigns; not independently replicated.
No comparative baseline arm and no AMTD-only ablation.
Small numbers of runs; the three campaigns used different configurations.
Scoped to network-layer behavior; host-local and cloud-API-only agent activity is outside the tested model.

How to cite

Trama, F. (2026). Denying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents. Zenodo preprint, v1 (Zenodo record). https://doi.org/10.5281/zenodo.21347479