跳到正文
arXiv:cs.AI· Ryuichi Yamafuji Lun, Jingzhen Wang, Shreyas Kolte, Ruiteng Li·· 4 小时前AI 评分46

MIRROR:面向 LLM 多智能体通信的多路径仲裁完整性机制

MIRROR: Multipath Quorum Integrity for LLM Multi-Agent Communication

AI 导读

针对 LLM 多智能体系统中可篡改传输消息的 Agent-in-the-Middle(AiTM)攻击,研究者提出通信层完整性原语 MIRROR:将同一规范化载荷复制到 k 条逻辑路由,仅当严格多数路由报告相同摘要时才接受消息。

正文

View PDF HTML (experimental)

Abstract:Inter-agent communication is central to Large Language Model Multi-Agent Systems (LLM-MAS), but it introduces an underexplored vulnerability: Agent-in-the-Middle (AiTM) attacks that manipulate messages in transit without compromising the agents themselves. Prior work reports Attack Success Rates (ASR) approaching 100% on structured tasks. Existing defenses rely on semantic validation, which requires additional inference and can block benign outputs, or on transport-layer encryption, which does not help when an intermediary legitimately terminates TLS. We present MIRROR, a communication-layer integrity primitive that replicates a single canonicalized payload across k logical routes and accepts a message only when a strict majority of routes report the same digest. MIRROR uses unkeyed hashing and so authenticates nothing on its own, since an active on-path adversary can always recompute a digest over a payload it has modified. All integrity derives from the assumption that honest routes form a majority. The digest serves only to make witness routes constant-size and to bind the recovered payload to the quorum-agreed value under second-preimage resistance. We give the guarantee under a route-compromise bound alpha < 0.5, and extend it to correlated routes, where the quantity that matters is the size of the largest shared-failure group and not the route count. We further show that availability and integrity degrade at the same threshold: below alpha = 0.5, quorum-denial and message-dropping adversaries cannot block honest traffic. Across MMLU, HumanEval, and MBPP on two frameworks and four communication topologies, and in a MetaGPT deployment against a production API, MIRROR reduces ASR to 0% below the threshold at 1x LLM token cost. LLM-as-a-Judge costs 35x in the same deployment, and blocks up to 44.2% of benign outputs in the topology sweep.
Comments: Accepted at the NeurIPS 2026 Workshop on Foundations of Language Model Security (FLMSec). 12 pages, 4 figures, 3 tables
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Multiagent Systems (cs.MA)
Cite as: arXiv:2610.02349 [cs.CR]
  (or arXiv:2610.02349v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.02349

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Ryuichi Lun [view email]
[v1] Thu, 1 Oct 2026 18:22:22 UTC (306 KB)

来源:arXiv:cs.AI · arxiv.org