Trust propagation and structural containment in Multi-agent LLM pipelines

📅 2026-09-15
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过共享内存中毒和间接提示注入攻击多代理LLM系统,提出使用任务绑定签名令牌和独立验证策略来防止未授权行为,确保即使验证者被攻破也能限制执行。
📝 Abstract
Multi-agent LLM systems increasingly automate tasks involving agents with different levels of privilege, creating a security risk in which a compromised low-privilege agent can influence a higher-privilege agent and trigger an unauthorized action. We study attack propagation in a four-agent LangGraph pipeline comprising a Supervisor, Researcher, Validator, and Executor. We evaluate shared-memory poisoning and indirect prompt injection through a forged approval embedded in a retrieved document. We compare the Validator's judgment with an independent authorization layer using task-bound signed tokens and a separately verified policy oracle. Our contribution is an empirical study of attack propagation, a component-level ablation of the authorization boundary, and the Judgment Bypass Rate (JBR), which measures compromise at the attacked agent rather than at the final action. Across three seeds and 60 labeled tasks, memory poisoning reaches execution in every undefended trial. With authorization enabled, it achieves 100% JBR but 0% Unsafe Action Rate, showing that the Validator can remain compromised while execution is contained. Against an attacker possessing the signing secret, the policy oracle provides the observed containment, while an independently authored least privilege policy preserves this result. An Observer layer reduces the false-positive rate for agent hijacking from 49% to 7% without weakening execution-level security. These results show that structural authorization can contain compromised agent behavior even when upstream LLM judgment fails.
Problem

Research questions and friction points this paper is trying to address.

Multi-agent LLM systems
security risk
compromised low-privilege agent
unauthorized action
Innovation

Methods, ideas, or system contributions that make the work stand out.

Authorization Boundary
Judgment Bypass Rate (JBR)
Task-bound Signed Tokens
Policy Oracle
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
T
Tanzim Hossain Safin
Department of Computer Science and Engineering, BRAC University, Dhaka, Bangladesh
S
Sharif Noor Zisad
Department of Computer Science, University of Alabama at Birmingham, Birmingham, Alabama, USA
Swakkhar Shatabda
Swakkhar Shatabda
Professor, School of Data and Sciences, BRAC University
optimizationmachine learningcomputational biologybioinformatics
Ragib Hasan
Ragib Hasan
Full Professor of Computer Science, University of Alabama at Birmingham
Computer SecurityCloud ComputingData ProvenanceDigital ForensicsInternet of Things (IoT)