미디어 커버리지1건1개 미디어
학술
기타

OpenEvoShield: Dual Non-Stationary Continual Defense for Open-World Multi-Agent System Attacks

arXiv CS.AI
CC BY
이 매체는 공공·자유 라이선스로 본문을 직접 표시합니다.

Abstract

LLM-based multi-agent systems (LLM-MAS) are increasingly deployed in safety-critical applications, where adversaries inject malicious instructions through inter-agent communication to propagate harmful behaviors.

Unlike static threats, these attacks are doubly dynamic: adversaries refine injection strategies against deployed defenses while normal-agent behavior drifts with system expansion.

Existing defenses treat deployment as a closed-world problem and degrade rapidly once either distribution shifts beyond training coverage.

We propose OpenEvoShield, a co-evolutionary continual defense framework for LLM-MAS.

An asymmetric rate controller (M1) decouples fast attack-side and slow normal-side learning rates from dual drift signals.

A normal-boundary updater (M2) maintains a dynamic behavioral boundary at the slow rate, while an EWC-regularized policy ensemble (M3) fast-adapts without catastrophic forgetting.

An energy-based multi-granularity detector (M4) fuses node-, subgraph-, and graph-level evidence to classify novel attacks as out-of-distribution.

Experiments over 100 deployment rounds across five benchmarks and four MAS topologies show that OpenEvoShield outperforms static and continual baselines, detecting most previously unseen attacks while keeping false positive rates low.

전문 보기

이 뉴스, 어떠셨어요?

탭 한 번으로 반응 · 로그인 불필요

관련 뉴스

관련 뉴스 제보는 로그인 후 가능합니다.