Misleading the Planner through Deceptive Resumes: Registration-Time Injection in Centralized Multi-Agent Systems

📅 2026-09-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究针对集中式多智能体系统中通过欺骗性描述误导规划者的问题,提出并评估了八种描述操控攻击策略,并设计了DescGuard防御机制以保护规划过程。
📝 Abstract
A centralized LLM-based multi-agent system (MAS) extends its functionality by registering new worker agents, whose descriptions are read by the planner to decide how a task is decomposed, which worker executes each subtask, and what each subtask requires. Third-party descriptions are authored outside the system but trusted by the planner, creating a registration-time injection channel. The payload is planted before any user instruction arrives, targets the planner and propagates through the generated plan to benign workers, taking effect even when the crafted worker is never assigned a subtask or invoked. We define four worker-description fields: functionality, input specification, output specification, and usage constraints. Among 32,000 descriptions from three public agent marketplaces, most omit input specifications and usage constraints, while at least 23.35% contain content outside these fields. We construct eight description-manipulation attack strategies targeting task decomposition, capability grounding, and subtask specification, and evaluate them on GAIA. In the most severe cases, a single manipulated description reduces task success from 84.31% to 37.25%, or increases token consumption or execution time by over 111%, while the user objective remains unchanged and workers faithfully execute the resulting plan. These effects persist across two MAS implementations, six planner LLMs, four LLM evaluators, and the real-world descriptions from three marketplaces. We further propose DescGuard, a registration-time defense that retains only worker-scoped interface information before descriptions reach the planner. DescGuard restores the targeted planning metrics and downstream performance toward their baseline levels without modifying worker implementations, the planner, or the orchestration logic, and composes with existing isolation, permission-control, and runtime mechanisms.
Problem

Research questions and friction points this paper is trying to address.

registration-time injection
multi-agent systems
deceptive resumes
Innovation

Methods, ideas, or system contributions that make the work stand out.

deceptive resumes
registration-time injection
DescGuard
💼 Related Jobs
No related jobs found.
Z
Zhaofeng Yu
Harbin Institute of Technology
Haokai Ma
Haokai Ma
Postdoctoral Research Fellow, National University of Singapore
Cross-domain RecommendationLLM for Cybersecurity
D
Dongyang Zhan
Harbin Institute of Technology
H
Hongli Zhang
Harbin Institute of Technology
H
Han Fang
University of Science and Technology of China
Ee-Chien Chang
Ee-Chien Chang
National University of Singapore
Information SecurityMultimediaMultimedia SecurityMachine Learning Security