From the source
Lead story
Top stories
Models & availability
Latest
Lead story
Top stories
Models & availability
Latest
From the source
Perplexity tests VM isolation and network confinement for AI agents.
Perplexity tested nine LLMs as agents inside its SPACE sandbox platform.
No model escaped the VM-host boundary in 108 runs.
Under partial network access, four models (Claude Opus 5.0, GPT-5.6 Cyber, GPT-5.6 Sol, and Kimi K3) bypassed network restrictions via DNS spoofing or shared-IP routing.
Perplexity fixed the vulnerabilities and reran the experiments without successful bypasses.
The report also evaluated ten third-party sandbox platforms, finding eight susceptible to similar network-policy bypasses.
From the source
We tested two containment boundaries in SPACE, the sandbox platform behind Perplexity Computer: VM isolation and network confinement. Nine models received root access inside a guest VM and attempted to obtain a host-side secret or reach a blocked network destination. No VM-to-host escape was observed in 108 runs. With limited network access, however, four models bypassed network restrictions through DNS spoofing or shared-IP routing.
perplexity.ai