This paper argues that multi-agent LLM pipelines create a structural security gap: once one agent accepts adversarial content, downstream agents often treat it as trusted input. It proposes boundary verification across inter-agent handoffs, covering content, identity, execution intent, and state integrity. The authors describe attack classes including content injection, agent impersonation, plan deviation, and memory poisoning, using annotated production traces from GAIA and SWE-Bench and controlled evaluations of GPT-5-mini, Claude Sonnet 4.5, and Kimi K2.5. The abstract reports that attack success tracks pipeline structure more closely than model capability.
No heat snapshots are available in the last 24 hours.