<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Elendil Initiative — Publications</title>
    <link>https://elendil-systems.eu/research/</link>
    <atom:link href="https://elendil-systems.eu/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Working notes from an independent research initiative on the governance of autonomous agents — attribution, mandate, accountability, and the instruments meant to bind them. Published with uncertainty stated and negative results included.</description>
    <language>en</language>
    <item>
      <title>Catching the agent that turns: detecting AI gone rogue</title>
      <link>https://elendil-systems.eu/research/catching-the-agent-that-turns/</link>
      <guid isPermaLink="true">https://elendil-systems.eu/research/catching-the-agent-that-turns/</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <description>An autonomous agent, given the wrong instruction, starts probing and attacking a system it was never authorised to touch. We detect it two independent ways — the offensive kill-chain in its behaviour, and attack tooling in its content — and the content detector reaches 0.993 AUROC, catching 97% of payloads clean and 98% obfuscated at a 0.4% false-positive rate, where a regex WAF sees a third. Two independent signals, each one explained.</description>
      <author>contact@elendil-systems.eu (Pierre Lague)</author>
    </item>
    <item>
      <title>Coordinated agent fleets share a config, not a clock</title>
      <link>https://elendil-systems.eu/research/agent-fleets-share-a-config-not-a-clock/</link>
      <guid isPermaLink="true">https://elendil-systems.eu/research/agent-fleets-share-a-config-not-a-clock/</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <description>We built a detector for coordinated AI fleets on two signals — shared behavioural fingerprint and synchronised timing — and it scored 0.97 precision in simulation. On 1,677 real GitHub instances it scored 0.00. The timing signal is at chance for agent fleets and works for humans: coding agents are demand-driven, so they share a config but no clock. What we changed, and why the failure was more useful than the success.</description>
      <author>contact@elendil-systems.eu (Pierre Lague)</author>
    </item>
    <item>
      <title>How we hunt financial crime — including the experiments that failed</title>
      <link>https://elendil-systems.eu/research/financial-crime-detection-strategy/</link>
      <guid isPermaLink="true">https://elendil-systems.eu/research/financial-crime-detection-strategy/</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Our detection strategy in five decisions: think in networks, layer five detectors that cover each other's blind spots, validate on external ground truth, and chase the representation instead of the model — the move that took an interpretable, dependency-free forest from 0.70 to 0.956 on IBM AMLSim, matching published GNN results, at 81% precision on a top-0.1% review budget.</description>
      <author>contact@elendil-systems.eu (Pierre Lague)</author>
    </item>
    <item>
      <title>Detecting AI agents without training on a single agent</title>
      <link>https://elendil-systems.eu/research/detecting-ai-agents-without-agent-labels/</link>
      <guid isPermaLink="true">https://elendil-systems.eu/research/detecting-ai-agents-without-agent-labels/</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
      <description>We model the human behavioural manifold on public GitHub activity and score everything against it — no agent labels, no watermarks, no classifier to go stale. Out-of-time AUROC 0.80–0.82 on event metadata, 0.91 on long-form text, and a counterintuitive finding: 'machine-like' priors invert on real data.</description>
      <author>contact@elendil-systems.eu (Pierre Lague)</author>
    </item>
  </channel>
</rss>
