Poster: Collaboration Fingerprinting Reveals What Adaptive Multi-Agent LLM Systems Process on the Wire

Abstract

Multi-agent LLM systems promise improved reasoning by collaboration of specialized agents through a sequence of API calls. This collaboration is also visible on the wire and opens new channels for leakage. Despite encrypted communication, a passive on-path observer can still learn the number, order, size and timing of the API calls. This metadata is generated by the system as a function of the input it processes. In adaptive multi-agent systems, the collaboration structure itself is chosen by the input, and that choice is visible in the traffic pattern. We coin this threat collaboration fingerprinting. Using MDAgents, a state-of-the-art medical multi-agent framework, we demonstrate on two datasets that a passive observer can recover the assigned case complexity and narrow a case’s diagnosis to a coarse clinical group, solely from collaboration metadata. A case’s clinical complexity determines the complexity of the collaboration. This dependency results in an inference-time privacy channel, unaddressed by existing content-level defenses. We thus argue that a multi-agent system’s observable network traffic must be treated as part of its confidentiality boundary.

Type
Publication
Proceedings of the 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS ’26)
Event
33rd ACM Conference on Computer and Communications Security, Nov 15 - Nov 19, 2026, The Hague, Netherlands
Klaus Wehrle
Klaus Wehrle
Head of Group
Dr. rer. nat. Jan Pennekamp
Dr. rer. nat. Jan Pennekamp
Postdoctoral Researcher / Staff Scientist