acceptodds
Under review as a conference paper at ICLR 2027

Which Structures Amplify Attacks? Uncovering Collaboration-Induced Vulnerability in LLM Multi-Agent Systems

Abstract

Collaboration enables LLM-based multi-agent systems (MAS) to solve complex tasks, but can also amplify adversarial influence. We observe that direct collaboration among malicious agents strengthens existing attacks, with gains varying substantially across communication topologies. This raises a question: which collaboration structures most effectively amplify attacks? Our analysis associates higher attack success with denser internal connections that support attacker coordination and outward connections that enable propagation to normal agents. These findings motivate Collaboration-Induced Vulnerability (CIV), a perspective that examines how local collaboration structures support attack amplification. To assess CIV, we propose CIV-Amplify, a graph-based red-teaming framework that identifies vulnerable collaborative subgraphs using agent attributes, internal coordination, and outward connections. It then adapts existing attacks on multi-agent systems into coordinated behaviors tailored to the selected structure. Our work highlights structural weaknesses in multi-agent systems and supports security evaluation against collaborative threats. Our code is anonymously released at https://anonymous.4open.science/r/CIV-Amplify-6F15.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.