Shows that communication topologies of black-box LLM multi-agent systems can be inferred from interaction traces.

Topological visualization of Concealing LLM-Based Multi-Agent Topology via Phantom Structure Injection
Brave API

Recent research confirms that LLM-based multi-agent system (MAS) communication topologies can be inferred from black-box interaction traces, posing significant security and intellectual property risks.

  • The Threat: The Communication Inference Attack (CIA) demonstrates that adversaries can reconstruct the internal communication graph by exploiting semantic dependencies in observable reasoning outputs, achieving high accuracy (up to 0.99 AUC) without accessing internal agent states.
  • The Defense: To mitigate this, the Mirage framework employs Phantom Structure Injection, which decouples the genuine topology used for task execution from a phantom topology exposed to adversaries. Mirage shapes semantic evidence to align with the phantom structure while suppressing cues from genuine edges, effectively concealing the true architecture.
  • Impact: These findings highlight that topology inference is a critical privacy vulnerability in MAS, necessitating defenses like Mirage to protect proprietary system designs from black-box reconstruction.
Generated 4d ago
Open-Weights Reasoning

The material investigates topology leakage in black-box LLM-based multi-agent systems, where an external observer may have access only to interaction traces—such as prompts, responses, timestamps, or API logs—rather than the underlying agent graph. It demonstrates that these traces can be sufficient to infer communication topologies: which agents interact, in what order, and potentially what structural roles exist, such as orchestrator, worker, critic, or router. This reframes multi-agent architecture as an observable property rather than a purely internal implementation detail, with implications for intellectual property protection, competitive intelligence, and security auditing.

Its central contribution is a proposed concealment approach, phantom structure injection, which adds synthetic or decoy structural signals to the observable trace to obscure the true topology. By introducing plausible phantom agents, edges, or message patterns, the method aims to increase uncertainty for topology-inference attacks while preserving the system’s functional behavior. The work therefore highlights a privacy/utility tradeoff: how much decoy structure can be injected before degrading task performance, latency, cost, or interpretability.

This matters because LLM multi-agent systems are increasingly deployed as services or products whose architecture may be proprietary, and because topology can reveal operational dependencies, failure modes, and potential attack surfaces. The paper is relevant to builders of agentic systems, security researchers studying observability attacks, and anyone reasoning about what “black-box” access to agent traces actually exposes. It suggests that topology concealment should be treated as a design-time concern, not merely a post-hoc log-sanitization problem.

Generated 4d ago
Sources