arXiv:2604.12461cs.AI2026-04ACL被引 4

攻击者可黑箱推断大模型多智能体通信结构,暴露系统隐私漏洞。

CIA: Inferring the Communication Topology from LLM-based Multi-Agent Systems

  • 通过构造对抗性查询诱导中间智能体输出,分析语义关联推断通信拓扑。
  • 在优化通信结构的多智能体系统上,平均AUC达0.87,最高达0.99。
  • 揭示大模型多智能体系统在黑箱下的通信隐私风险,适合安全与隐私研究者关注。

基于大语言模型的多智能体系统(MAS)在解决复杂任务方面展现出卓越能力。通信拓扑是其核心,决定智能体间信息交换方式。因此,通信拓扑的安全性日益受到关注。本文研究一个关键隐私风险:在严格的黑箱设置下,多智能体系统的通信拓扑可被推断,暴露系统漏洞并带来重大知识产权威胁。为此,我们提出通信推理攻击(CIA),通过构建新的对抗性查询,诱导中间智能体产生推理输出,并利用全局偏置解耦和大模型引导的弱监督方法建模其语义相关性。在具有优化通信拓扑的多智能体系统上进行的大量实验表明,CIA有效,平均AUC达到0.87,峰值高达0.99,充分揭示了多智能体系统中的显著隐私风险。

原文摘要 · Abstract (English)

LLM-based Multi-Agent Systems (MAS) have demonstrated remarkable capabilities in solving complex tasks. Central to MAS is the communication topology which governs how agents exchange information internally. Consequently, the security of communication topologies has attracted increasing attention. In this paper, we investigate a critical privacy risk: MAS communication topologies can be inferred under a restrictive black-box setting, exposing system vulnerabilities and posing significant intellectual property threats. To explore this risk, we propose Communication Inference Attack (CIA), a novel attack that constructs new adversarial queries to induce intermediate agents' reasoning outputs and models their semantic correlations through the proposed global bias disentanglement and LLM-guided weak supervision. Extensive experiments on MAS with optimized communication topologies demonstrate the effectiveness of CIA, achieving an average AUC of 0.87 and a peak AUC of up to 0.99, thereby revealing the substantial privacy risk in MAS.

多智能体隐私安全大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。