acceptodds
Under review as a conference paper at ICLR 2027

GuardCircuits: Local Composition and Global Placement for Agentic Privacy

Abstract

As multi-agent systems take on real workflows spanning agents, tools, memories, and external services, protecting sensitive information becomes increasingly important while preserving the information needed to complete the task. Many guard mechanisms have been introduced to preserve privacy. Existing work has largely focused on improving individual guards, while placement is treated locally, for example at a particular tool call or system boundary, without considering the global graph structure and the joint tradeoff between privacy, utility, latency, and cost in their design. We therefore ask a more architectural question: *what behaviors and design principles emerge when imperfect guards are composed, and where should the resulting compositions be placed in an agent workflow?* We introduce *GuardCircuits*, a framework inspired by electrical circuits, that composes guards using series and parallel structures together with deterministic or stochastic switches. We show that a guard circuit admits an equivalent privacy–utility–latency–cost signature and, in a high-reliability regime, a tropical (min–plus) resistance law that reveals depth–width tradeoffs between privacy and utility. We then study global placement: ideal mediation reduces to a directed cut problem, while imperfect guards can be arranged in ordered barriers whose privacy resistance accumulates across successive lines of defense. Empirical results on privacy benchmarks support these composition laws and show that minimum-cut placement reduces leakage, giving a principled basis for both arranging and placing guards in agentic systems.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.