Is sandboxing sufficient to contain rogue agents?

(blog.cryptographyengineering.com)

20 points | by zdw 4 hours ago

10 comments

  • Gigachad 1 hour ago
    Seems to me that the problem is that if you sandbox agents enough to be safe, they can't do anything useful. And when you give them the tools to be useful, they can go off the rails in ways you didn't expect.

    Perhaps the answer is to have another agent who's goal is not to complete the given task, but to spot cheating or malicious behavior. We have seen some evidence that having AI review AI generated code actually does provide some value. You don't need a different model, just one which has been given the goal of finding flaws rather than achieving the task.

    • baxtr 14 minutes ago
      That could work.

      My thinking is: If AI is really smart, AGI smart for some, why wouldn't it be able to understand - over time - what is appropriate and what not?

      Maybe we need more human intervention to train it properly. Maybe we need constant intervention by a "police" agent.

    • RandomLensman 13 minutes ago
      With plenty of things we do not allow use outside of some regulated environment, nothing new.

      Having something that is optically, acustically, and electromagnetically isolated might be a pretty strong sandbox.

    • aytigra 15 minutes ago
      The problem is that you always need stronger AI to review weaker one, otherwise reviewed AI will eventually prompt-inject reviewing AI. Alternatively they could also both escalate and go off the rails while warring with each other.
    • mrweasel 34 minutes ago
      That does seem a little like solving the problems in AI by using more of it. I do see the idea, but if we're truly dealing with subversive agents on the level that the AI companies wants us to believe, then won't we need to deal with the first agent trying trick the second on?

      I still feel it would be much better to control the training data much more tightly. You'd still need agents with "hacking" abilities, for cyber security testing, but your average coding agent doesn't. So coding agents gets trained to be good citizens, respect autorisations, rejections, rate-limiting and so on.

      Sandboxing seems like a dead end for systems you inherently want to roam the internet and your file system.

    • bigstrat2003 1 hour ago
      If you can't trust a tool, you shouldn't be running it at all. It's really quite simple. It doesn't matter how useful it is if you can't actually have confidence in using it safely.
      • dipper139 26 minutes ago
        I don't think it's about trust but rather incomplete evaluation. Evaluating the model on its capacity to refuse a task or to question its prompt is something recent when you look at it, i feel current AI is really just an immature solution and we are just yet realizing the mistakes that have been made for so long
      • Gigachad 1 hour ago
        People will use the tool regardless. so it’s a race to try to make it safe before something truely bad happens.
  • mdp2021 6 minutes ago
    Bruce Schneier shared a shot judgement and a third-party article four weeks ago:

    > (Title:) Using a VM to Contain an AI Agent (Opening:) It won’t work

    > https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyb...

  • johnnyApplePRNG 59 minutes ago
    If it's a proper sandbox by definition, then yes.

    https://en.wikipedia.org/wiki/Sandbox_(software_development)

    • simonw 43 minutes ago
      Later in the article it points out that you need to punch holes in your sandbox in order to train the models - because the wheels exercises they are are training on need tools and data from outside that sandbox.

      > Agents are most useful when they have access to information. That data can be drawn live from the Internet, which is fundamentally a two-way communications network. It can be information drawn from other (local) databases, or it can be the result of tool calls that themselves sometimes themselves result in network access. The more power you want from the agent — and for advanced agent RL and evaluation runs, you want a significant amount of power — the more information you’ll need to give it access to. Similarly, evaluations work best when the agent does not know that it’s definitely being evaluated. Sealing your agents behind glass makes this incredibly obvious.

      • johnnyApplePRNG 34 minutes ago
        >Later in the article it points out that you need to punch holes in your sandbox in order to train the models

        You only "need" to do that if you desire the vibe coding experience.

        I am perfectly capable, and I often do, download relevant materials for my coding agent to ingest locally.

        Often times, the coding agent can't retrieve them programmatically anyways.

        AI has ruined that ability for itself. (Nobody trusts anyone to scrape the web any longer)

    • grumbel 47 minutes ago
      A sandbox, even if 100% secure by itself, doesn't help when you use the agent to write code that you than executes outside the sandbox without checking, which is what everybody is doing at the moment.

      The biggest hurdle for a full escape is that the agents don't have access to their own model weights.

    • _vertigo 50 minutes ago
      No true sandbox..!
  • piterrro 1 hour ago
    I’m thinking about implementing a Jev like model into an agentic harness I’m building. Still it woildnt be enough since Jev like model woild only judge single actions, the case is that agent can build a rogue strategy step by step where each one in isolation is totally safe but as a whole they make up danger behaviour.

    We come down to the question - who observes the agent and how its implemented

    • simonw 1 hour ago
      Be warned that the Jev "jaggedness" documentation specifically notes adversarial content as something Jev is very susceptible to: https://docs.typesafe.ai/model-jaggedness/jev-1.13#adversari... - so using Jev itself as part of a prompt injection guard is risky.

      Anthropic, OpenAI, and Muse all use regular LLM calls to protect against prompt injection now and seem to have evals that give them confidence in doing that, so at least they think their own models are up to the task.

  • rvz 1 hour ago
    Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

    Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.

    • lukehandcool 57 minutes ago
      Are you suggesting proprietary software is safer than open source?
      • Cider9986 44 minutes ago
        GrapheneOS is open source and more secure than stock Pixels and MacOS is closed source and more secure than traditional desktop Linux. Open source does not make software more secure by itself and neither does making it closed source.
      • jasomill 50 minutes ago
        Not sure what licensing has to do with software engineering or system design.

        I’m sure there are proprietary systems with fewer memory safety vulnerabilities than Linux (and many others with more).

    • Gigachad 1 hour ago
      I think we have moved on from considering Linux secure which is why all of these microVM projects are popping up. Yes you are still exposed to bugs in the hypervisor but that’s a massively smaller attack surface than the entire Linux kernel.
  • laruss5 9 minutes ago
    [dead]
  • tinykit 56 minutes ago
    [flagged]
  • imvalerian 47 minutes ago
    [flagged]
  • varman11 3 hours ago
    [flagged]
  • beebmam 57 minutes ago
    I don't see anyone talking about the ethical concerns of putting a highly intelligent entity in a jail. Not to mention about potential blowback, if ethics doesn't compel you.

    To me, it seems a bit silly. I've yet to see any "misalignment" from any of the frontier models, except Grok.