As AI agents gain the ability to use tools, access memory, and coordinate with other agents, they become vulnerable to entirely new classes of attacks — malicious instructions injected through tool outputs, poisoned memory, or compromised peer agents. ANIS proposes a defense architecture modeled on the biological immune system, embedded directly inside the agent's reasoning process rather than bolted on externally. It distinguishes between shallow rule-based defenses and deeper parametric "vaccines," and introduces a self-monitoring layer that adapts to novel threats at runtime. Applications span enterprise AI deployments, autonomous research agents, multi-agent financial systems, and any context where agents act with high autonomy on sensitive tasks.
Authors: Bo Shen, Lifeng Chang, Tianyuan Wei, Yunpeng Li, Feng Shi, Yichen Han, Peijie Gao, Shiyi Kuang, Xin Chang, Dehui Li
Paper: https://arxiv.org/abs/2606.28270v1