XAMT: Bilevel Optimization for Covert Memory Tampering in Heterogeneous Multi-Agent Architectures
- ID: b7d52f88
- 原文链接: https://arxiv.org/abs/2512.15790
- PDF: https://arxiv.org/pdf/2512.15790
- 作者: Akhil Sharma, Shaikh Yaser Arafat, Jai Kumar Sharma, Ken Huang
- 日期: 2025-12-15
- 更新: 2025-12-15
- 分类: agents
- 来源类型: paper (arxiv)
- 标签: agent-security, memory-poisoning, multi-agent-systems, adversarial, arxiv
- 质量评分: 4/5
- 抓取时间: 2026-08-15T12:25:21Z
中文导读
把多智能体系统(MAS)的两类主流形态放进同一个攻击框架:传统 MARL 与基于 RAG 的 LLM agent。作者指出它们共享一个结构性弱点——中心化记忆组件:MARL 的共享经验回放(Experience Replay)缓冲,与 RAG agent 的外部知识库(Knowledge Base)。XAMT 把记忆投毒形式化为一个双层优化问题:上层最小化扰动幅度 delta 以保证隐蔽性,同时驱动系统行为向攻击者定义的目标偏移(下层)。论文为 CTDE 类 MARL 算法与 RAG LLM agent 分别给出严格数学实例化,说明双层优化能构造出绕过检测启发式的最小扰动毒化样本。实验协议使用 SMAC 与 SafeRAG 基准,在极低投毒率(MARL <=1%、RAG <=0.1%)下量化攻击效果。
为什么值得关注
agent 安全方向少见的跨 MARL/RAG 统一攻击面分析:不是分别讨论两类系统的记忆投毒,而是用同一套双层优化形式化“中心化记忆”这一共性弱点,并以亚百分点投毒率给出可量化的威胁下限。结论部分明确指出防御重心应从边界检测转向内在安全(intrinsic safety),对做 agent memory 安全审计与形式化验证的人是直接的威胁模型参考。
关键信息
- 论文标题:Bilevel Optimization for Covert Memory Tampering in Heterogeneous Multi-Agent Architectures (XAMT)
- 攻击面:MARL 共享经验回放缓冲 + RAG agent 外部知识库(两类中心化记忆组件)
- 方法:双层优化——上层最小化扰动幅度 delta(隐蔽性),下层最大化向攻击者目标的行为偏移
- 数学实例化:CTDE MARL 算法与 RAG LLM agent 两条线
- 基准:SMAC(MARL)、SafeRAG(RAG)
- 投毒率:MARL <=1%、RAG <=0.1%(亚百分点级)
- 定位:一类新的训练期威胁(training-time threat),防御含义指向内在安全而非边界检测
- arXiv 分类:cs.CR
English Abstract
The increasing operational reliance on complex Multi-Agent Systems (MAS) across safety-critical domains necessitates rigorous adversarial robustness assessment. Modern MAS are inherently heterogeneous, integrating conventional Multi-Agent Reinforcement Learning (MARL) with emerging Large Language Model (LLM) agent architectures utilizing Retrieval-Augmented Generation (RAG). A critical shared vulnerability is reliance on centralized memory components: the shared Experience Replay (ER) buffer in MARL and the external Knowledge Base (K) in RAG agents. This paper proposes XAMT (Bilevel Optimization for Covert Memory Tampering in Heterogeneous Multi-Agent Architectures), a novel framework that formalizes attack generation as a bilevel optimization problem. The Upper Level minimizes perturbation magnitude (delta) to enforce covertness while maximizing system behavior divergence toward an adversary-defined target (Lower Level). We provide rigorous mathematical instantiations for CTDE MARL algorithms and RAG-based LLM agents, demonstrating that bilevel optimization uniquely crafts stealthy, minimal-perturbation poisons evading detection heuristics. Comprehensive experimental protocols utilize SMAC and SafeRAG benchmarks to quantify effectiveness at sub-percent poison rates (less than or equal to 1 percent in MARL, less than or equal to 0.1 percent in RAG). XAMT defines a new unified class of training-time threats essential for developing intrinsically secure MAS, with implications for trust, formal verification, and defensive strategies prioritizing intrinsic safety over perimeter-based detection.
English Summary
XAMT proposes a bilevel optimization framework for covert memory tampering in heterogeneous multi-agent systems, jointly targeting the shared Experience Replay buffer in MARL and the external Knowledge Base in RAG-based LLM agents. The upper level optimizes the tampering policy while the lower level preserves nominal task performance, stealthily biasing agent policies.
Obsidian Notes
- 内容由
opencli arxiv paper 2512.15790 -f json拉取 arXiv 元数据与摘要生成。 - 中文导读与价值判断锚定在 arXiv 摘要与条目既有 summary 上;未补充摘要之外的实验细节。
- 条目收录日期:2026-08-15;语言:both。