Priview: Trust-Source Decomposition for Robust and Composition-Safe Disclosure in Federated Multi-Agent Systems
Abstract
Federated multi-agent systems deploy agents at separate clients to collaborate through natural-language exchanges and multi-round negotiation. Each agent must contribute useful local information while respecting its client's privacy policy. Prior view-isolation methods extract abstractions of private information as views using trusted task descriptions or application interfaces, then restrict subsequent disclosure to those views. Open negotiation instead requires constructing such information from changing, untrusted requests and validating it together with prior disclosures, exposing the process to two key privacy threats: prompt-injection and differencing attacks. To address these threats, we propose Priview, a disclosure framework centered on trust-source decomposition. We first derive disclosure constraints from the integrity principle of robust declassification and the requirements of task utility and cumulative safety. Utility requires requests to guide information construction, whereas authorization integrity requires permission judgments to remain independent of untrusted request text. These requirements motivate trust-source decomposition: separating construction guided by low-integrity requests from authorization grounded in high-integrity, owner-controlled policies. Priview implements this decomposition in three isolated contexts: view construction proposes and ranks useful candidates, authorization checks them against the policy and disclosure history, and a confined speaker expresses approved content. A conservative ledger consolidates policy-relevant facts from actual disclosures for cumulative authorization. Across public benchmarks and the evaluated prompt-injection, differencing, and extended-context settings, Priview retains task utility with no observed unauthorized disclosures.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.