arXiv · 2609.26072
Policy-Backed Selective Regeneration under Tainted Inter-Agent Communication
Abstract
Inter-agent communication is essential to multi-agent language-model systems, yet a single message may combine task-critical information with instructions not authorized by the original request. Prompt-based defenses leave enforcement to models exposed to adversarial messages, while indiscriminate message removal discards useful information. We introduce Executable Semantic Commitments with Clean-Room Recovery (ESC-CR), a policy-backed framework for secure inter-agent code generation and recovery. It separates message claims from authorization, constructs executable commitments from trusted tasks, evidence, and policy, and enforces them at an external release boundary. Upon a violation, ESC-CR taints the responsible message and rejected artifact, reconstructs a clean context from evidence-backed task information, and regenerates under the same policy. We evaluate ESC-CR across communication-essential and standard code-generation benchmarks, multiple model families and communication topologies, and adaptive attacks spanning direct, obfuscated, and verifier-aware payloads. Results show that polluted-context retry frequently fails to remove unauthorized influence, while complete message removal can discard information required by communication-essential tasks. ESC-CR preserves evidence-backed claims while suppressing unauthorized releases under matched computational budgets, and the same design transfers to end-to-end agent trajectories.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jinghan Xu, Longze Fan, Zeyuan Wang, Xinjin Li, Hankai Liu. 2026-08-02. Policy-Backed Selective Regeneration under Tainted Inter-Agent Communication. https://arxiv.org/abs/2609.26072
Cite the original work for its findings. Save a collection to share your selection of sources.