Corrupting Causal Action Graphs Induces High False Execution Rates in CIVeX
October 1, 2026
Red-teaming the CIVeX verifier reveals that omitting a single bidirected edge increases false executions from 0% to 15.3%, while reversing one arrowhead results in a 48.9% false execution rate. These misspecification attacks produce internally valid certificates despite failing to prevent harmful tool-use interventions.
HOW THIS AFFECTS YOU
●
builderDo not rely solely on internal certificates for agent tool-use safety without external verification steps.
●
researcherYou should account for graph misspecification when evaluating the robustness of causal verifiers.