arXiv AI

Tool Use Enables Undetectable Steganography in Multi-Agent LLM Systems

arXiv:2606. 28425v1 Announce Type: cross Abstract: Increasingly autonomous agentic AI systems pose novel multi-agent risks, such as secret collusion via covert communication channels.

arXiv Computation and Language
Sep 1

A Comprehensive Survey on Linguistic Steganography: Methods, Countermeasures, Evaluation, and Challenges

This survey reviews 148 linguistic steganographic methods, 60 countermeasures, 23 evaluation metrics, and 9 open challenges, providing taxonomies, reviews, and adoption analyses. It identifies five paradigm shifts brought by large language models: moving from covertext modification to prompt-only generation, from heuristic to provable security, from white-box symmetric models to black-box or asymmetric access, from security-centric designs to joint optimization, and from text-quality concerns to engineering issues. The paper aims to serve as a reference and roadmap for practical and responsible linguistic steganography in the LLM era.

By Ruiyi Yan, Chenhui Chu, Zhongliang Yang, Yugo Murawaki
arXiv Machine Learning
Sep 11

CARTS: Contextual Autoregressive Rank Transcoding Steganography for Full-Capacity Keyed Text Encoding

The paper introduces CARTS, a steganographic method that uses autoregressive language models to encode a payload text into a stegotext of identical token length by preserving per‑position rank information across contexts. It provides a formal security analysis, proving exact correctness under deterministic model assumptions, and defines key security notions such as context search, key collisions, message equivocation, and non‑commutativity of encoding maps. Empirical tests on Llama 3 8B confirm perfect payload recovery, no random key collisions, and no commuting key pairs, indicating resistance to the studied attack vectors.

By Wissam Ghantous, Alexander V. Mantzaris
arXiv Machine Learning
Jun 2

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models

arXiv:2606. 00566v1 Announce Type: new Abstract: As language models take on agentic roles that span calling external APIs, reading tool outputs, and acting on instructions embedded in third-party content, their attack surface expands well beyond what users type.

By Mohammed Sameer Syed (University of Arizona), Rozhin Yasaei (University of Arizona)
arXiv AI
Aug 26

Poisoning Agentic Alpha: Adversarial Vulnerabilities Across Roles and Architectures in Multi-Agent Trading Systems

The paper investigates how adversarial signals can infiltrate large‑language‑model (LLM) based multi‑agent trading systems through the agents’ communication channels. By restricting the attacker to realistic inputs—source data and prompts—it studies role‑specific attacks on four functional roles (Analyst, Researcher, Trader, Risk Manager) and evaluates four communication topologies under data‑ and agent‑level attacks. Experiments across multiple assets, backbones, and target directions show that no architecture is inherently robust, highlighting the need for safer designs in agentic trading systems.

By CheolWon Na, Hao Ni, Lukasz Szpruch, Zhangyang Wang, Dhagash Mehta, Saurabh Nagrecha, Alejandro Lopez-Lira, Chanyeol Choi, Yongjae Lee, Jee-Hyong Lee