跳到正文
arXiv:cs.AI· Diego Fernandez Arias, Dev Prashant Mistry, Ren Wang, Yibo Hu·· 4 小时前AI 评分49

多智能体 LLM 系统中的分布式后门早期检测:一项特征刻画研究

Early Detection of Distributed Backdoors in Multi-Agent LLM Systems: A Characterization Study

AI 导读

研究构建了一个分层多智能体系统上的分布式后门攻击实例,攻击将加密载荷碎片分散到多个被投毒工具中,待运行结束后再重组执行。前缀检测器在注入开始后能以 99.5% 的召回率标记成功攻击,中位剩余十二步,未注入运行的误报率约 1%。检测器部分依赖密文长度和熵等可移除的表面线索,去掉这些线索后告警更晚且跨工具环境迁移更难。

正文

View PDF HTML (experimental)

Abstract:Multi-agent LLM systems can be attacked by a payload that no single agent ever holds in full: several poisoned tools each hide one encrypted fragment, spreading them across several agents, and an external step reassembles and executes them after the run. Per-step safety checks that judge each action in isolation may fail to recognize the complete distributed payload. We investigate how early such an attack can be detected while the run is still unfolding, and how robustly it can be caught once its most obvious cues are stripped away. We build a working instance on a hierarchical multi-agent system, run it under benign and attacked conditions across five language models and two tool environments, and record when each fragment is injected and when the payload is assembled and executed. Almost no run is flagged before its first fragment is injected; once injection begins, a prefix detector flags $99.5\%$ of successful attacks with a median of twelve steps remaining and an out-of-fold false-alarm rate of about $1\%$ on uninjected runs, higher on runs that carried fragments but never assembled. Because assembly occurs only after the run, these alarms could enable an abort before assembly on nearly every successful attack. We also test a detector that sees only the current observation, to ask whether earlier steps are needed. When the current observation carries an obvious clue, one observation is often enough; when that clue is removed, using earlier steps can help. Generic zero-shot and behavior-trained detectors fail to separate unsafe from safe runs; the detectors that do work lean in part on removable surface cues, chiefly the ciphertext's length and entropy. Take those cues away and the detector fires later, and carrying it from one tool environment to the other becomes much harder. A model fine-tuned on the raw text recovers part of the loss.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2607.24893 [cs.CR]
  (or arXiv:2607.24893v2 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2607.24893

arXiv-issued DOI via DataCite

Submission history

From: Yibo Hu [view email]
[v1] Mon, 27 Jul 2026 15:18:06 UTC (2,762 KB)
[v2] Fri, 2 Oct 2026 03:58:45 UTC (1,282 KB)

来源:arXiv:cs.AI · arxiv.org