LATIDIA · Ciberseguridad
Compiladores de comunicación invariantes de selección para flujos de trabajo LLM multiagente conscientes de la privacidad
arXiv: 2609.26076v1Tipo de anuncio: Cross Resumen: Los flujos de trabajo estructurados de múltiples agentes intercambian mensajes intermedios cuyo contenido y forma pueden revelar el estado privado incluso cuando la salida final es segura. Identificamos la selección-
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.26076v1 Announce Type: cross Abstract: Structured multi-agent workflows exchange intermediate messages whose content and form can reveal private state even when the final output is safe. We identify selection-channel leakage: after authorization fixes what may be released, a private-state-aware choice among semantically valid realizations creates an additional inference channel. We introduce the selection-invariant communication compiler(SICC), which constrains this post-authorization representation kernel rather than prescribing templates. Any deterministic or independently public-randomized generator satisfying the invariant is valid; requirement-indexed canonical forms are one auditable implementation. We prove a compositional communication-layer guarantee: authorization, public-only form generation, and a dependency-safe utility gate make the emitted transcript reveal no information beyond the complete authorized view.