CIA: Inferring the Communication Topology from LLM-based Multi-Agent Systems
arXiv cs.AI / 4/15/2026
💬 OpinionSignals & Early TrendsIdeas & Deep AnalysisModels & Research
Key Points
- The paper shows that communication topologies in LLM-based multi-agent systems can be inferred even under a restrictive black-box threat model, creating privacy and intellectual-property risks.
- It introduces a novel Communication Inference Attack (CIA) that uses adversarial queries to elicit intermediate agents’ reasoning outputs and then learns semantic correlations among them.
- The method relies on global bias disentanglement and LLM-guided weak supervision to improve inference accuracy from limited observable information.
- Experiments on MAS systems with optimized communication topologies demonstrate strong performance, with average AUC of 0.87 and peak AUC up to 0.99, suggesting the attack can reliably recover underlying communication structure.




