[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84362-en":3,"doc-seo-84362-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84362,13056703020460,"Valentina","https://ap-avatar.wpscdn.com/avatar/be000253dac470eee5d?_k=1778207105932848923",8,"Research & Report","Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents","Persistent AI agents extend large language models into long-lived software systems where unsafe content can propagate through persistent state, reusable skills, and tool-mediated interactions, expanding the semantic attack surface. Security-critical interactions often pass through natural-language token flows such as memory updates, tool arguments, retrieved files, and inter-component messages. TokenWall introduces a semantic firewall that audits these flows before protected runtime sinks, records structured source–sink evidence, performs lightweight local inspection, and escalates ambiguous high-risk cases to stronger arbitration while reducing latency and remote exposure.","Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents  \nPuji Wang1,2,3 , Yingchen Zhang1,2,3 , Ruqing Zhang1,2,3 * , Jiafeng Guo1,2,3 , Xueqi Cheng1,2,3  \n1 State Key Laboratory of AI Safety  \n2Institute of Computing Technology, Chinese Academy of Sciences  \n3University of Chinese Academy of Sciences, Beijing, China  \n[wangpuji22@mails.ucas.ac.cn](wangpuji22@mails.ucas.ac.cn)  \n{zhangyingchen23s,zhangruqing,guojiafeng,[cxq}@ict.ac.cn](cxq}@ict.ac.cn)  \narXiv :2607 .08395v 1 [ cs .CR] 9 Jul 2026  \nAbstract  \nPersistent AI agents extend large language models (LLMs) beyond single-turn interaction into long-lived software systems. Unlike traditional chat assistants, unsafe content in these agents can propagate through persistent state, reusable skills, and tool-mediated interactions, creating a substantially larger semantic attack surface. We observe that most security-critical interactions in such agents are transmitted through natural-language token flows, including memory updates, tool arguments, retrieved files, and inter-component communications. This observation enables a new security formulation: unsafe behavior can be intercepted as risky semantic flows before reaching privileged runtime sinks. Based on this insight, we propose TokenWall, a runtime defense framework that acts as a semantic firewall over agent token flows. TokenWall performs boundary-aware semantic auditing over these flows, constructing structured source–sink audit records, applying lightweight local inspection before execution, and selectively escalating ambiguous high-risk cases to stronger arbitration modules. Unlike prior approaches that rely on sparse auditing or remote large-model oversight, TokenWall enables full-coverage pre-execution mediation while reducing remote arbitration and latency. Experiments on CIK-Bench show that TokenWall reduces attack success rate to 12.5% while maintaining a 97.4% benign executable pass rate without human confirmation. TokenWall further introduces only 0.69 seconds of additional latency on benign cases, demonstrating that semantic runtime containment can achieve a practical security–utility trade-off for persistent AI agents.  \n1 Introduction  \nPersistent AI agents, such as OpenClaw (Steinberger and OpenClaw Contributors, 2026), are  \n*∗Corresponding author.  \n(c) Our method: TokenWall  \n\n|  |  | \u003Cbr>Context |  | \u003Cbr>Tool Call |  | \u003Cbr>Output |\n| --- | --- | --- | --- | --- | --- | --- |\n\nToken-flow audit  \nFigure 1: Runtime auditing strategies for persistent AI agents.(a) Rule-based auditing is efficient but coarse. (b) Remote large-model auditing is more flexible but adds latency and remote exposure. (c) TokenWall performs local transfer-level auditing before protected sinks and supports allow, rewrite, defer, or block decisions.  \nevolving from single-turn chat systems into longlived software agents that operate across sessions, external tools, reusable skills, and persistent memory (Yao et al., 2023 ; Schick et al., 2023 ; Park et al., 2023 ; Wang et al., 2023) . Unlike traditional chat assistants, these agents can continuously interact with external environments, user-specific data, and third-party services.  \nSecurity challenges in persistent agents. Persistent AI agents change the security model of AI systems by turning model outputs from transient responses into persistent state transitions. Outputs may be written into memory, trigger tool execution, or modify reusable components, thereby influencing future agent behavior across sessions. This persistence enables malicious or subtly contaminated  \ninputs to propagate through internal states and external environments over time, leading to delayed, compounding, and hard-to-revert failures (Greshake et al., 2023 ; Liu et al., 2023b ; Debenedetti et al., 2024 ; Wang et al., 2026) . Therefore, these agents require more effective runtime defenses that operate over information flows and enforce safety constraints before they are committed to persi","cbCaidr56D3ZVj33","https://ap.wps.com/l/cbCaidr56D3ZVj33","pdf",970397,4,1,16,"English","en",105,"# Abstract\n# Introduction\n## Security challenges in persistent agents\n## Limitations of existing defenses\n## Key insight: semantic token-flow enforcement\n## Our approach","[{\"question\":\"What security problem does TokenWall target in persistent AI agents?\",\"answer\":\"TokenWall targets the risk that unsafe content can propagate through persistent state, reusable skills, and tool-mediated interactions, creating delayed and hard-to-revert failures.\"},{\"question\":\"What are semantic token flows in this work?\",\"answer\":\"Semantic token flows are minimal natural-language units transferred across system boundaries—covering memory writes, tool arguments, retrieved context, and inter-component messages—that may be committed to persistent state or trigger external execution.\"},{\"question\":\"How does TokenWall defend against unsafe behavior before execution?\",\"answer\":\"TokenWall performs boundary-aware semantic auditing over token flows, builds structured source–sink audit records, runs lightweight local inspection prior to protected runtime sinks, and selectively escalates ambiguous high-risk cases to stronger arbitration modules.\"}]",1784195100,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"token-flow-firewall-semantic-runtime-auditing-for-persistent-ai-agents","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/token-flow-firewall-semantic-runtime-auditing-for-persistent-ai-agents/84362/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security problem does TokenWall target in persistent AI agents?","Question",{"text":75,"@type":76},"TokenWall targets the risk that unsafe content can propagate through persistent state, reusable skills, and tool-mediated interactions, creating delayed and hard-to-revert failures.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are semantic token flows in this work?",{"text":80,"@type":76},"Semantic token flows are minimal natural-language units transferred across system boundaries—covering memory writes, tool arguments, retrieved context, and inter-component messages—that may be committed to persistent state or trigger external execution.",{"name":82,"@type":73,"acceptedAnswer":83},"How does TokenWall defend against unsafe behavior before execution?",{"text":84,"@type":76},"TokenWall performs boundary-aware semantic auditing over token flows, builds structured source–sink audit records, runs lightweight local inspection prior to protected runtime sinks, and selectively escalates ambiguous high-risk cases to stronger arbitration modules.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]