Research · curated 28 Sep 2026
Trust propagation and structural containment in Multi-agent LLM pipelines
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Multi-agent LLM pipelines with tiered privilege are vulnerable to a confused-deputy pattern where a compromised low-privilege agent triggers unauthorized high-privilege actions, and this work demonstrates that structural authorization boundaries—rather than agent judgment—are what actually contain the attack.
Researchers empirically study attack propagation in a four-agent LangGraph pipeline (Supervisor, Researcher, Validator, Executor), evaluating shared-memory poisoning and indirect prompt injection via forged approvals in retrieved documents. They introduce the Judgment Bypass Rate metric and show that structural authorization using task-bound signed tokens and a separately verified policy oracle can contain compromised agent behavior (100% JBR but 0% Unsafe Action Rate) even when upstream LLM judgment fails, with an Observer layer cutting hijacking false positives from 49% to 7%.