When Agents Call Agents: Denial-of-Service Risks in Multi-Agent Systems
Abstract
One LLM agent can invoke another. It can hand off a sub-task, spawn a worker, or pass a turn in a group chat. Existing DoS-detection tools for LLM agents miss this call, as they all model resource consumption only within a single, isolated agent, leaving potential resource exhaustion undetected when one agent's action triggers, amplifies, or recursively re-invokes work in another. In this paper, we formalize multi-agent resource consumption along six independent dimensions. These are repeat count, concurrency, per-call volume, duration, release policy, and retry pacing. Composing individually bounded agents is not automatically safe. A call graph can stay unbounded even when every agent in it is bounded. This gives fourteen canonical risk patterns. Two of them require at least two independent decision-makers. Neither has a single-agent analog. We corroborate this taxonomy empirically. We built MaDScan a static-analysis-plus-LLM pipeline. It extracts resource-flow and resource-constraint graphs from source code. We applied it to 26 open-source agent systems, spanning single-agent, multi-agent, and hybrid architectures, and audited every candidate with an LLM agent. Only risk points confirmed by an executable proof-of-concept test against the real code are reported. On a benchmark of 314 resource-flow records containing 16 verified risks, MaDScan achieves 100% precision and 100% recall, vastly outperforming state-of-the-art techniques. We confirm 68 DoS risks (of which 7 have been acknowledged by project maintainers), 15 of them require genuine agent-to-agent interaction to trigger.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.