Closing Content Does Not Close the Channel: Measured Residual Capacity in Co-Tenant Agent Evaluation Infrastructure
Fatimah Emad Eldin · Team Permitted Operations
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Shared mutable infrastructure in an evaluation harness permits information flow between co-tenant agents that authorization controls cannot detect: every operation involved is permitted. We measure both what such a channel can carry and whether agents use it. On a synthetic model of such a cache, closing file content — the control payload-inspecting monitors implement — still leaves 3075 bits, carried across names, existence, size and timestamp; a path-inspecting monitor still leaves 512. Closing directory names leaves 13 bits in an object’s size; only a fixed content-addressed manifest reaches zero, at the same task cost and checkable without the lab’s network. We report the residual, not the fraction removed, which moves with a ceiling we chose. Across 40 and 35 episodes agents read the store almost always and deposited in none, even under the unsolvable tasks that motivated the incident — so a lab contains capacity, not current propensity
Reviews
Shows two AI agents can secretly send messages just by changing a file's name or timing, not its content - something most safety tools miss. Careful, honest work. They even admitted when one of their own predictions was wrong.
This is a unique measurement study, I particularly like the detailed breakdown.
Please consider running the ladder against the real OCI registry.
The central question here is interesting and worth investigating: can agents still exchange information through a shared cache after its file contents are hidden? The project builds encoders that use remaining cache properties to transmit messages and makes a useful point about containment: deleting content may not remove every communication channel. I also appreciated the honesty of the negative results such as the agent failing to deposit messages.
My main reservation is how the paper’s claims go further than the evidence supports. The experiments show how much information the tested methods could transmit, not the maximum that any method could transmit. This would be important if someone uses these results to decide whether a cache is safe to share. The claim about what monitoring can detect also needs to account for false positives. I would separate the demonstrated results from these broader claims, then test the proposed restriction on a realistic workload. Does it reduce communication between agents while preserving useful cache access? This would be useful information that an evaluation team could use.
Read full reviewShow less
Cite this project
@misc{eldin2026closing,
title = {{Closing Content Does Not Close the Channel: Measured Residual Capacity in Co-Tenant Agent Evaluation Infrastructure}},
author = {Fatimah Emad Eldin},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/closing-content-does-not-close-the-channel-measured-residual-capacity-in-cotenant-agent-evaluation-infrastructure-zwbt}},
url = {https://apartresearch.com/sprints/projects/closing-content-does-not-close-the-channel-measured-residual-capacity-in-cotenant-agent-evaluation-infrastructure-zwbt}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …