Beyond Centrality: Position-Decoupled Verification for Finite-Horizon Attacks in LLM Multi-Agent Systems
Abstract
Large language model-based multi-agent systems (LLM-MAS) are vulnerable to misinformation that propagates through inter-agent dependencies. Topology-aware defenses often prioritize structurally central sources, implicitly assuming that lower-centrality sources pose lower security risk. We challenge this assumption with matched Hub/Nonhub attacks that differ only in source position, and find that nonhub sources can pose risks comparable to hubs. We further show formally that dominant asymptotic Perron source rankings need not order finite-horizon task-relevant adversarial influence; when such uncalibrated rankings drive selective verification, residual risk can shift toward structurally deprioritized sources. To address this risk–protection mismatch, we propose CORA-GG, a position-decoupled assertion-governance framework that separates verification allocation from source centrality, prioritizes risky assertions within each source, tracks semantic lineages across downstream reuse, and gates factual influence on verifier-supported evidence. This prevents unverified or repeatedly inherited assertions from gaining factual authority through propagation. Across Quant, Rigid, and MMLU on MetaGPT, LangGraph, and AutoGen, CORA-GG records no observed targeted attack successes and achieves lower worst-source residual risk than evaluated baselines under matched token, false-positive-rate, and clean-utility constraints.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.