arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37567cs.CRcs.AI

通过幻影结构注入隐藏基于LLM的多智能体拓扑

Concealing LLM-Based Multi-Agent Topology via Phantom Structure Injection

Longzhu He, Zelang Wen, Xinfeng Li, Sen Su, XiaoFeng Wang

首次发表
浏览论文内容

中文总结 AI 辅助

针对基于LLM的多智能体系统拓扑易被推断泄露知识产权的问题,提出MIRAGE框架,通过合成幻影拓扑并实现语义边,在保留任务效用的同时有效降低拓扑推断攻击成功率。

中文摘要 AI 辅助

受大型语言模型(LLM)快速发展的驱动,基于LLM的多智能体系统(MAS)已成为复杂任务协作推理的强大范式。MAS的一个关键设计要素是通信拓扑,它控制智能体之间的信息流,并常常编码有关系统架构的专有知识。然而,近期研究表明,即使在黑盒设置下,此类拓扑也可以通过利用可观察推理轨迹中的语义依赖关系被推断出来,从而带来知识产权泄露和系统漏洞暴露的重大风险。为应对这一威胁,我们提出MIRAGE,一种拓扑隐藏框架,它在为任务执行保留真实通信拓扑的同时,将面向对手的语义证据塑造成精心构造的幻影拓扑。具体而言,MIRAGE分三个阶段运行:(1)幻影拓扑合成,(2)语义边实现,以及(3)受保护的MAS执行。它构造一个在结构上与真实拓扑不同的幻影拓扑,将幻影边实现为合理的语义依赖关系,并抑制可能揭示真实边(这些边在幻影拓扑中不存在)的特定来源线索。在三个拓扑优化框架和四个基准数据集上的广泛实验表明,MIRAGE显著降低了拓扑推断攻击的有效性,同时大体上保留了受保护MAS的任务效用。

英文摘要

Driven by the rapid advancement of large language models (LLMs), LLM-based multi-agent systems (MAS) have emerged as a powerful paradigm for collaborative reasoning over complex tasks. A key design element of MAS is the communication topology, which governs information flow among agents and often encodes proprietary knowledge about the system architecture. However, recent work has shown that such topologies can be inferred even in black-box settings by exploiting semantic dependencies in observable reasoning traces, posing significant risks of intellectual property leakage and exposure of system vulnerabilities. To address this threat, we propose MIRAGE, a topology-concealment framework that preserves the genuine communication topology for task execution while shaping adversary-facing semantic evidence toward a carefully constructed phantom topology. Specifically, MIRAGE operates in three stages: (1) phantom topology synthesis, (2) semantic edge realization, and (3) protected MAS execution. It constructs a phantom topology structurally distinct from the genuine one, materializes phantom edges as plausible semantic dependencies, and suppresses source-specific cues that could reveal genuine edges absent from the phantom topology. Extensive experiments across three topology optimization frameworks and four benchmark datasets demonstrate that MIRAGE substantially reduces the effectiveness of topology inference attacks while largely preserving the task utility of the protected MAS.

发表机构

  • Nanyang Technological University(南洋理工大学)
  • Beijing University of Posts and Telecommunications(北京邮电大学)

机构由 AI 辅助整理,请以论文原文为准。

↑