<p>Large Language Models (LLMs) are increasingly deployed as interconnected agentic swarms that leverage the Model Context Protocol (MCP) to invoke shared external tools, APIs, and databases. In these settings, conventional security strategies based on agent-to-agent airgapping can be insufficient because agents that never directly communicate may still cross-infect one another through shared infrastructure tools, producing a “Confused Deputy” cascade. This paper develops a formal mathematical framework for modeling this cross-layer contagion in MCP-enabled multi-agent swarms. We construct a <i>coupled multiplex Microscopic Markov Chain Approach</i> (MMCA) that simultaneously tracks the node-level probability flow across two layers: an Agent cognitive layer (governed by Susceptible–Exposed–Infected–Quarantined (SEIQ) dynamics) and a Tool infrastructure layer (governed by Susceptible–Infected–Susceptible (SIS) dynamics). Our contributions are threefold: (i) we formulate a coupled multiplex MMCA with asymmetric SEIQ–SIS dynamics across agent and tool layers; (ii) we derive an analytical characterization of systemic risk, including an epidemic-threshold approximation via Next-Generation Matrix analysis and a closed-form budget-allocation rule under an exponential defense-efficiency model; and (iii) across eight experiment groups on synthetic and empirical agent-layer topologies, we show that shared-tool coupling consistently amplifies contagion and that tool-side controls can dominate agent-side hardening under the modeled regime. For cybersecurity practice, the framework identifies when shared tool infrastructure can transform localized prompt-injection events into system-level risk even under direct agent-to-agent isolation.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cross-layer contagion of prompt injections in multi-agent swarms: a multiplex microscopic markov chain approach

  • Tran Duc Le,
  • Truong Duy Dinh,
  • Thi Le Quyen Nguyen,
  • Cong Danh Nguyen

摘要

Large Language Models (LLMs) are increasingly deployed as interconnected agentic swarms that leverage the Model Context Protocol (MCP) to invoke shared external tools, APIs, and databases. In these settings, conventional security strategies based on agent-to-agent airgapping can be insufficient because agents that never directly communicate may still cross-infect one another through shared infrastructure tools, producing a “Confused Deputy” cascade. This paper develops a formal mathematical framework for modeling this cross-layer contagion in MCP-enabled multi-agent swarms. We construct a coupled multiplex Microscopic Markov Chain Approach (MMCA) that simultaneously tracks the node-level probability flow across two layers: an Agent cognitive layer (governed by Susceptible–Exposed–Infected–Quarantined (SEIQ) dynamics) and a Tool infrastructure layer (governed by Susceptible–Infected–Susceptible (SIS) dynamics). Our contributions are threefold: (i) we formulate a coupled multiplex MMCA with asymmetric SEIQ–SIS dynamics across agent and tool layers; (ii) we derive an analytical characterization of systemic risk, including an epidemic-threshold approximation via Next-Generation Matrix analysis and a closed-form budget-allocation rule under an exponential defense-efficiency model; and (iii) across eight experiment groups on synthetic and empirical agent-layer topologies, we show that shared-tool coupling consistently amplifies contagion and that tool-side controls can dominate agent-side hardening under the modeled regime. For cybersecurity practice, the framework identifies when shared tool infrastructure can transform localized prompt-injection events into system-level risk even under direct agent-to-agent isolation.