A 197-Paper SoK Argues Most Claimed Multi-Agent Security Effects Are Not Actually Multi-Agent
The authors systematize multi-agent LLM security through an execution-centered analysis of 197 works covering six interaction interfaces, four adversary positions, seven system-level risks, and eight recurring attack paths, organized into an A-I-R framework by adversary position, interaction interface, and resulting risk. Their central methodological point is that without an execution-level view, a merely multi-agent setting is easily mistaken for evidence of a genuinely multi-agent security effect. They organize defenses through a five-part contract over path target, observation, intervention, trust boundary, and recovery, and their audit of 44 evaluation and benchmark works finds path closure and recovery are where the field is weakest.
↳ Follow the thread