Shattered Intent: Payload Sharding Attacks on Multi-Agent LLM Systems
Abstract
Multi-agent systems (MAS) decompose complex tasks across specialized agents, with each agent accessing only the inputs assigned to its role. We show that this structure creates a vulnerability we term payload sharding, where a malicious payload is split into individually benign shards distributed across agents. We instantiate the attack as Mosaic, which decomposes a payload along intent, logic, and target boundaries aligned with the plan-code-execute workflow of code-generating MAS. Shards are synthesized by an iterative procedure that generates a cover context, decouples logic from sensitive parameters, and verifies via LLM auditing that each shard appears benign in isolation. Mosaic achieves ASR across five LLMs and five MAS architectures, exceeding the strongest prior attack by . Under defenses, it retains ASR against LlamaFirewall and against LLM-based cross-artifact auditing.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.