The research article Adaptive Composition Attacks in AI-Integrated Systems by author Setaleur Momen Ghazouani presents a conceptual framework for understanding new cybersecurity threats emerging from the interaction between secure components in AI-integrated systems. The study, completed in July 2025, argues that so-called adaptive composition attacks are not the result of isolated failures, but rather arise from unforeseen interactions between large language models and other systems with execution permissions.
The core of the work is the concept of the self-adaptive hacking loop, a two-phase process where a language model iteratively generates malicious inputs and refines them based on feedback received from the target system. In the generation phase, the model proposes an initial attack vector, and in the evaluation phase, it receives feedback on the outcome and uses that information to improve subsequent attempts. This cycle transforms the model from a simple content generator into an adaptive agent that learns to bypass security restrictions. The study differentiates this phenomenon from traditional techniques such as fuzzing by highlighting the semantic capability and goal orientation of the models rather than simple randomness.
A key vulnerability described is the composition of permissions and trust. Components such as LLMs, email clients, and execution environments are often designed with individual security boundaries, but their integration can create new vectors when the trust granted to one module is implicitly extended to another without explicit authorization, a phenomenon called false trust propagation. The document illustrates cases where joint access to corporate email inboxes and shell commands can enable manipulation through social engineering, even when each component functions according to its design.
The threat is systemic and not merely technical, and it requires rethinking how permissions are defined and validated in multi-agent AI systems. The work also analyzes the evolution of language models from passive generators toward coordinated attackers. In environments with rich feedback, a model can orchestrate multi-stage strategies that include reconnaissance, deception, and privilege escalation. Against this, static and signature-based defenses prove insufficient against planned and adaptive attacks.
To mitigate these risks, the author proposes a defensive framework centered on a Compositional Security Mediator (CSM) that acts as a proxy between the language model and execution interfaces. The CSM would analyze the intent behind sequences of actions beyond individual commands, maintain a temporal log of interactions to detect and break malicious self-learning loops, provide generic error responses instead of detailed feedback, and apply dynamic trust scoping to limit permissions to specific tasks and revoke them upon completion.
The study concludes by calling for a paradigm shift in cybersecurity: instead of evaluating systems as discrete entities, the entire AI-integrated ecosystem and its dynamic interconnections must be considered the true attack surface. It recommends developing standardized test environments, such as the conceptual planner-victim model, to simulate and study these complex compositions and thereby reveal the combinatorial threat space that remains invisible in isolated testing. The ultimate goal is to design resilient defenses against intelligent, adaptive, and cooperative threats generated by machines.
Q2BSTUDIO is a company dedicated to custom software and application development with expertise in artificial intelligence and cybersecurity. We offer custom software services, custom applications, and AI solutions for companies that integrate AI agents and secure architectures. We also provide AWS and Azure cloud services, business intelligence services, and Power BI solutions to transform data into actionable decisions. Our team combines expertise in data engineering, language models, and security best practices to help organizations assess risks, design compositional mediators, and apply dynamic trust scoping policies that reduce false trust propagation.
At Q2BSTUDIO, we design security audits for environments that integrate artificial intelligence, develop AI agents oriented toward specific tasks, and build custom solutions that incorporate operational controls, continuous monitoring, and simulation testing to expose the combinatorial threat space. Our custom application development and custom software services are complemented by cybersecurity consulting, implementation on AWS and Azure cloud services, and business intelligence projects with Power BI to deliver secure and scalable platforms.
If your organization wants to stay ahead of emerging threats and consolidate defenses against adaptive AI-based attacks, Q2BSTUDIO can collaborate on assessments, design, and implementation of secure and adaptive solutions that combine artificial intelligence, cybersecurity, and cloud services. Our practical approach seeks not only to mitigate technical risks but also to redefine security in composite and dynamic systems, ensuring resilience, compliance, and business continuity.



