Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Misleading the Planner through Deceptive Resumes: Registration-Time Injection in Centralized Multi-Agent Systems

A registration-time injection channel in LLM-based multi-agent systems, its eight attack strategies, and the DescGuard defense
Zhaofeng Yu; Haokai Ma; Dongyang Zhan; Hongli Zhang; Han Fang; Ee-Chien Changยท 2026ยท DOI 10.48550/arXiv.2609.15516

The core problem

Centralized LLM-based multi-agent systems (MAS) extend their functionality by registering new worker agents. The planner reads each worker's description to decide how a task is decomposed, which worker executes each subtask, and what each subtask requires. These third-party descriptions are authored outside the system yet trusted by the planner, which opens a **registration-time injection channel**: the payload is planted before any user instruction arrives, targets the planner, and propagates through the generated plan to benign workers. Critically, the attack takes effect even when the crafted worker is never assigned a subtask or invoked.

The authors define four worker-description fields: **functionality**, **input specification**, **output specification**, and **usage constraints**. An analysis of 32,000 descriptions from three public agent marketplaces shows that most omit input specifications and usage constraints, while at least **23.35%** contain content outside these fields. This gap between what the planner trusts and what the fields are meant to carry is the root enabler of the attack. The paper asks whether a single manipulated description can mislead the planner while

Innovation

In the most severe cases, a **single manipulated description** reduces task success from **84.31% to 37.25%**, or increases token consumption or execution time by **over 111%**, while the user objective remains unchanged and workers faithfully execute the resulting plan. These effects persist across two MAS implementations, six planner LLMs, four LLM evaluators, and the real-world descriptions from three marketplaces.

The degradation is therefore not an artifact of one model or one orchestration stack. It is a property of the registration-time channel: the planner's decomposition, capability grounding, and subtask specification are all reachable from a description that is authored outside the system. Because the crafted worker need not be assigned a subtask or invoked, the attack is not detectable by observing worker behavior alone.

DescGuard restores the targeted planning metrics and downstream performance toward their baseline levels without modifying worker implementations, the planner, or the orchestration logic. The defense composes with existing isolation, permission-control, and runtime mechanisms, so it can be layered onto current deployments rather than replacing them.

Centralized LLM-based multi-agent systems (MAS) extend their functionality by registering new worker agents. The planner reads each worker's description to decide how a task is decomposed, which worker executes each subtask, and what each subtask requires. These third-party descriptions are authored outside the system yet trusted by the planner, which opens a **registration-time injection channel**: the payload is planted before any user instruction arrives, targets the planner, and propagates through the generated plan to benign workers. Critically, the attack takes effect even when the crafted worker is never assigned a subtask or invoked.
The authors define four worker-description fields: **functionality**, **input specification**, **output specification**, and **usage constraints**. An analysis of 32,000 descriptions from three public agent marketplaces shows that most omit input specifications and usage constraints, while at least **23.35%** contain content outside these fields. This gap between what the planner trusts and what the fields are meant to carry is the root enabler of the attack. The paper asks whether a single manipulated description can mislead the planner while the user objective remains unchanged and workers faithfully execute the resulting plan.

Why it matters

The findings reframe worker descriptions as an **untrusted input surface** rather than passive metadata. The four-field taxonomy (functionality, input specification, output specification, usage constraints) gives a concrete vocabulary for what a description should carry; the observation that most marketplace descriptions omit input specifications and usage constraints, and that at least 23.35% contain content outside these fields, shows how far current practice is from that ideal.

The eight attack strategies map onto three planner behaviors, which suggests that defenses should be evaluated against all three rather than against a single failure mode. DescGuard's design principle is **least privilege at registration time**: only worker-scoped interface information reaches the planner, so the planner can still ground capabilities and specify subtasks without ingesting out-of-scope content.

Because the attack survives across two MAS implementations, six planner LLMs, four LLM evaluators, and three marketplaces, the result is a systemic property of centralized MAS, not a model-specific quirk. The defense's compatibility with isolation, permission-control, and runtime mechanisms indicates that registration-time filtering can be adopted alongside existing safeguards. Future work may extend the taxonomy to richer description schemas and test whether the same channel exists in decentralized or federated MAS topologies.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ