acceptodds
Under review as a conference paper at ICLR 2027

RouterMAS: Value-Preserving Watermarking for Multi-Agent Routing

Abstract

Multi-agent systems derive capability from how they delegate work, yet embedding an ownership signal into delegation can alter every decision that follows. Exist- ing behavioral and expert-routing watermarks provide signature carriers without characterizing the routing freedom left by a system’s required continuation utility and cost. We propose RouterMAS, a value-preserving watermarking framework for multi-agent routing. Our key insight is that fixing task values need not fix the routing distribution: Bellman recursion converts prefix-wise preservation into local conservation equations, exposing an admissible space of probability redistributions. RouterMAS first constructs this space from continuation values, then encodes a secret key through a minimum-information-change routing law, and finally verifies the signature using evidence induced by the same law. An error budget connects value estimation and deployed-policy approximation to accumulated return drift. Controlled finite-state experiments validate conservation, sequential verification, and algebraically inert controls. Across reasoning, code generation, and environ- ment interaction, RouterMAS preserves task performance and operating cost while maintaining reliable detection. Its usable signature space expands with routing alter- natives and contracts as additional task values are protected, connecting watermark strength to the structure of multi-agent orchestration.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.