为多智能体地理系统设计安全框架,提升对抗攻击下的可靠性。
Securing Multi-Agent GIS Systems: Risk Evaluation and Prompt Hardening Optimization

- 用状态机抽象智能体行为,实现模块化协调
- 通过自适应攻击和判定机制,识别系统漏洞并量化风险
- 优化提示词结构注入对抗样例,增强安全且不损失任务表现
多智能体系统正日益融入地理信息系统(GIS),多智能体协作虽能支持复杂对话与空间分析,但也带来安全风险。本文提出一个面向安全的框架,用于多智能体GIS系统的风险识别、评估与缓解,同时保持对更广泛智能体架构的适应性。在某商业地理空间合作伙伴的智能体系统上测试,构建了基于状态机的模块化编排框架,将智能体行为抽象为可复用组件。采用红队测试框架,结合自适应攻击型大模型与确定性判别器,在多轮攻击中生成二元结果及推理依据,评估系统鲁棒性。进一步提出提示词优化框架,将提示词视为结构化签名,注入对抗性示范,实现系统性安全增强,且未影响任务性能。
原文摘要 · Abstract (English)
Agentic systems are increasingly integrated with geographic information systems (GIS), where multi-agent coordination enables complex conversational and spatial analysis but introduces security risks. This work presents a security-oriented framework for risk identification, evaluation, and mitigation in a multi-agent GIS system while maintaining adaptability to broader agentic architectures. We test the agentic system of a commercial geospatial partner while developing a modular state-machine-based orchestration framework that abstracts agent behavior into reusable components. We evaluate robustness using a red-teaming framework with an adaptive attacker LLM and a deterministic judge that produces binary outcomes with supporting rationales across multi-turn attacks. We further improve resilience with a prompt optimization framework that treats prompts as structured signatures and injects adversarial demonstrations, enabling systematic security improvements without degrading task performance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。