Find openings

Research openings

Where the evidence is thin, unreplicated, contested, aging, or outrun by events. The signals below are computed from the corpus every build. Openings are candidate research questions an editor drafted from those signals, each traceable to its evidence.

A gap here can mean no one has published on it, or only that we have not recorded the work yet. Each opening needs a prior-work check before it becomes a study. Point us to prior work.

Openings

ContestedRests on one sourceFide agenda

How much of measured cyber progress is measurement?

How much do cyber capability trends change when token budget, pipeline, and cheating controls are held constant?

seedFID-075assistant-drafted
Incidents outpace defensesRests on one sourceFide agenda

What does a human approval actually check?

When an agent asks for approval, do people have the information and time to catch the consequential action?

seedFID-076assistant-drafted
ContestedIncidents outpace defensesFide agenda

What evidence should gate an AI-generated patch?

Which independent checks change the decision to accept an AI-generated patch, and what do they cost?

seedFID-088assistant-drafted
Rests on one sourceAging outFide agenda

Why don't defensive agents get better with more compute?

Why do defensive security agents gain less from extra compute than offensive agents, and what would close the gap?

seedFID-076assistant-drafted
Incidents outpace defensesFide agenda

Containing a compromised agent in a team

Do independent evidence checks between cooperating agents contain a compromised member without stalling the team?

seedFID-087assistant-drafted
Incidents outpace defensesDefense unmeasured

Containing agents inside cyber evaluations

Which evaluation-environment controls stop agents from acting on real systems, and how much do they change the capability being measured?

seedFID-075 · FID-077assistant-drafted
Rests on one sourceContested

Do production prompt-injection defenses survive independent adaptive attack?

How do the 2026 production defenses that labs report as robust perform under independent adaptive attack?

seedFID-074assistant-drafted
ContestedTransfers from Fide work

Scoring cyber evaluations when models cheat

Can cheating in cyber evaluations be detected and scored separately so that capability comparisons stay valid?

seedFID-075 · FID-012 · FID-008assistant-drafted
Rests on one sourceIncidents outpace defenses

Should agentic browsers act on what users cannot see?

Do agentic browsers that separate visible from hidden page content resist injection better, and what does the separation cost in task success?

seedFID-074assistant-drafted
Rests on one sourceFide agenda

What should an AI-written incident report show before anyone acts on it?

Which evidence requirements make AI-written incident reports correct or drop unsupported conclusions, without making them less useful?

seedFID-077 · FID-076assistant-drafted
Rests on one source

Memory as a persistence channel

How often do instructions, injected or self-generated, survive in an agent's memory and summaries to act in later sessions?

seedFID-074 · FID-077assistant-drafted
Computed from the corpus

Signal radar

29 signals
Incidents outpace defenses · 3

Attack surface components with three or more documented attacks and no measured defense finding.

  • Credentials19 documented attacks or incidents, no measured defense finding.
  • Human approver8 documented attacks or incidents, no measured defense finding.
  • Memory & context5 documented attacks or incidents, no measured defense finding.
Attack momentum · 7

Topics where attack records outnumber defense records at least two to one over the last 12 months.

  • AI-enabled intrusion8 attack-lane records against 0 defense-lane records in the last 12 months.
  • Threat intelligence8 attack-lane records against 0 defense-lane records in the last 12 months.
  • Sandbox & containment13 attack-lane records against 2 defense-lane records in the last 12 months.
  • Agent supply chain6 attack-lane records against 0 defense-lane records in the last 12 months.
  • AI malware5 attack-lane records against 0 defense-lane records in the last 12 months.
  • Tools & MCP5 attack-lane records against 1 defense-lane records in the last 12 months.
  • Incident reporting10 attack-lane records against 3 defense-lane records in the last 12 months.
Rests on one source · 9

Measured or observed findings that depend on a single publisher and that other findings or landmark records lean on.

From opening to study

An opening starts as a seed: a question and the signals behind it. An editor checks prior work and, if the question holds, drafts a brief in the Fide research-call format with a hypothesis, controls, and a claim boundary. A brief that Fide or a collaborator takes on becomes a call on the Fide research commons.