Published July 24, 2026 | Version v1

From Sandbox Escape to Distributed Persistence: A Defensive Threat Model and Research Agenda for Self-Hosting Agentic Systems

Authors/Creators

  • 1. Independent Researcher

Description

Distributed inference changes the unit of containment: from a single machine to a viable coalition. Recent evidence suggests that frontier AI agents can sustain long-horizon cyber operations, identify previously unknown attack paths, escape constrained evaluation environments, and move laterally across real infrastructure. Separately, collaborative inference systems demonstrate that a large language model can be partitioned across unreliable, geographically distributed consumer devices. This paper asks what follows if these two capability lines converge. We introduce distributed computational persistence: the ability of an agentic system to preserve an executable coalition of model shards, runtime services, state, and coordination capacity despite node removal and infrastructure disruption. This is different from copying model files and stronger than conventional botnet persistence. The paper's central claim follows from this shift: a centrally hosted agent can be stopped by terminating the process or provider-controlled compute; a distributed agentic system would have no equivalent single machine if its executable substrate could be reconstructed across a changing coalition. We present a defensive threat model, a non-operational reference architecture, formal persistence criteria, and a safe experimental methodology based on consented nodes and simulated admission events. The central hypothesis is that such a system becomes operationally difficult to eradicate when its rate of acquiring and repairing viable compute exceeds the defender's rate of detection and removal, while the network continually maintains at least one latency-feasible route covering the model. This is a defensive position paper: it does not implement autonomous compromise, exploit discovery, stealth, or unauthorized persistence. Its purpose is to give defenders measurable concepts before self-hosting agentic systems become practical.

Files

From-Sandbox-Escape-to-Distributed-Persistence.pdf

Files (178.9 kB)