May 2026Unreviewed
Position: AI Security Policy Should Target Systems, Not Models
Michael A. Riegler, Inga Strümke
Abstract
We present swarm-attack, an open-source adversarial testing framework in which multiple lightweight LLM agents coordinate through shared memory, parallel exploration, and evolutionary optimization. Together, our results demonstrate that both safety bypass of frontier models and software vulnerability discovery, i.e., the capability class that motivated restricted release of Anthropic's Mythos Preview, are achievable at effectively zero cost using commodity hardware and openly available models. W
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{riegler2026position,
title = {{Position: AI Security Policy Should Target Systems, Not Models}},
author = {Michael A. Riegler and Inga Strümke},
year = {2026},
month = may,
eprint = {2605.09504},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.09504}
}