Randomized trial examines containment survivability in shared agent systems, highlighting risks and recovery strategies.
Shared-state agent systems can preserve coordination while amplifying a different risk: one poisoned write may be consumed by honest agents, re-expressed under valid identities, and propagated through the common field. The Containment Survivability Research program examined this problem in four stages — transitive taint propagation, containment denial-of-service, availability-preserving containment, and governed recovery — the first of which also produced a separate empirical evaluation (CSR-PUB-0001b). Paper 2's confirmatory campaign has since been admitted: across 69,930 trials it establishes containment amplification and placement effects within its frozen synthetic benchmark, while four of its seven preregistered hypotheses were not supported. This paper synthesizes those stages into a unified framework for containment survivability. The framework requires integrity-bound dependency recording, transitive blast-radius handling, historically monotonic quarantine, bounded continuity that cannot clear taint, reconstruction through new identity and provenance complete against a declared evidence boundary, fail-closed verification through a separated derivation path, controlled reintegration, recurrence withdrawal, and explicit irreducibility. It distinguishes framework conformance, which an audit can decide, from containment survivability within a stated operating envelope, which only a preregistered joint empirical criterion can establish; no system is claimed to have satisfied the second. The empirical record is mixed and is reported without retrospective harmonization. Paper 3 did not satisfy its joint success criterion. Paper 4 found that governed repair increased verified repair coverage over continuity alone by a median paired difference of 0.600 within its frozen synthetic benchmark while preserving containment and mandatory safety invariants exactly; however, its joint success rule was not satisfied — five of nine clauses held and four did not — several hypotheses were inconclusive, not rejected, or unevaluable, and about 38.7% of governed repair rows were irreducible, which that paper records as the single largest determinant of what repair achieved. The synthesis therefore does not claim that containment denial-of-service is solved or that production effectiveness is established. It contributes an evidence-bounded architecture, a claim taxonomy, and a minimum assurance case for future systems that must remain safe while recovering useful state.
No takes yet. Share an insight, caveat, or question.
Andre Byrd (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: