
Runtime defense framework targets semantic attacks in persistent AI agents
As AI agents move beyond single-turn chatbots into persistent, long-lived systems with memory and tool access, a new attack surface emerges: semantic flows through natural language tokens that can corrupt state and propagate harm across components. Researchers propose TokenWall, a runtime defense framework that intercepts risky semantic patterns before they reach privileged operations. This work addresses a critical gap in agent security as production deployments increasingly rely on multi-step reasoning and persistent context, making traditional input/output filtering insufficient for systems where internal token flows carry execution risk.62


























