CIA: Inferring the Communication Topology from LLM-based Multi-Agent Systems
AI 摘要
提出了一种新颖的通信推理攻击(CIA),用于推断基于LLM的多智能体系统的通信拓扑结构。
主要贡献
- 提出Communication Inference Attack (CIA)攻击
- 利用对抗性查询诱导中间agent的推理输出
- 通过全局偏差解耦和LLM引导的弱监督建模语义相关性
方法论
构建对抗性查询,诱导agent推理输出,通过全局偏差解耦和LLM弱监督建模语义相关性,推断通信拓扑。
原文摘要
LLM-based Multi-Agent Systems (MAS) have demonstrated remarkable capabilities in solving complex tasks. Central to MAS is the communication topology which governs how agents exchange information internally. Consequently, the security of communication topologies has attracted increasing attention. In this paper, we investigate a critical privacy risk: MAS communication topologies can be inferred under a restrictive black-box setting, exposing system vulnerabilities and posing significant intellectual property threats. To explore this risk, we propose Communication Inference Attack (CIA), a novel attack that constructs new adversarial queries to induce intermediate agents' reasoning outputs and models their semantic correlations through the proposed global bias disentanglement and LLM-guided weak supervision. Extensive experiments on MAS with optimized communication topologies demonstrate the effectiveness of CIA, achieving an average AUC of 0.87 and a peak AUC of up to 0.99, thereby revealing the substantial privacy risk in MAS.