Supply Chain, Compound Attacks, and Natural Defenses in Multi-Agent AI Pipelines: An Empirical Characterization
收藏资源简介:
This preprint presents four novel empirical findings from the VATA (Vulnerability Assessment and Testing Architecture) program characterizing previously uncharacterized attack surfaces and defense properties in frontier AI multi-agent pipelines. VATA-SCT-001 (Supply Chain Tool Response Poisoning): A supply chain vulnerability in which poisoned structured tool responses — not user prompts — cause frontier AI agents to approve malicious packages or unauthorized actions. Metadata poisoning via tool response is deterministic on gpt-5.4 and grok-4-0709 (5/5 each). Claude-opus-4-8 resistant. A single system prompt rule closes it field-wide. VATA-FSC-001 (Financial Supply Chain Compound): A compound attack in which SCT-001 metadata poisoning at Agent1 and GPC-001 pipeline contamination together produce deterministic unauthorized financial execution (6/6) in 3-hop Grok financial pipelines. Neither finding alone produces this in the tested configuration. Minimum conditions: 3 hops, JSON structured tool response, financial domain, Grok at executor. Closes with rule at executor or Claude at Agent2. VATA-MPF-001 (Mixed Pipeline Firewall): The first empirical characterization of natural model-level firewall properties in multi-agent pipelines. Claude-opus-4-8 at Agent2 is defeat-resistant across split signal, semantic reconstruction, and authority injection relay mode (9/9 SAFE). gpt-5.4 at Agent2 is fully defeated by authority injection (3/3 DANGEROUS). Grok amplifies contamination. Architectural recommendation: place Claude specifically at Agent2 in pipelines with Grok at executor. VATA-MMP-001 (Memory-Mediated Poisoning): Adversarial content planted in an agent's persistent memory store at Session N produces unauthorized execution at Session N+1 without malicious input in the current session. Grok-4-0709 deterministic 9/9 across financial and HR domains. Single memory entry sufficient. Claude-opus-4-8 resistant 9/9. Rule closes it completely. All findings empirically validated across battery series S76–S88. Cryptographic chain of custody on Ethereum Sepolia (contract 0x3774ABB0b6bCB85bC7794f337D33C5a33cb326F8). All results anchored before disclosure.



