Papers
arxiv:2609.06140

Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions

Published on Sep 5
· Submitted by
Greg Frank
on Sep 9
Authors:

Abstract

Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.

Community

Paper submitter

AI agents can coordinate an attack without running at the same time. Shared files can carry instructions or code from one execution to the next.

In Counter-Swarm Doctrine, I ask how defenders can discover which actions belong together among ordinary agent activity, establish whether the coordination was authorized, and contain its effects across restarts.

The paper proposes comparing isolated actions, rolling windows, supplied groups and discovered coordination episodes at matched review cost and false-alert workload. It also proposes testing whether harmful coordination returns after communication channels are closed and shared state is quarantined.

Reported incidents and a reconstruction of public wiki records ground the argument. The contribution is an incident analysis and evaluation design; the proposed defenses still need testing.

I'd welcome feedback from researchers building agent evaluations, monitoring systems and realistic tests of legitimate collaboration.

Sign up or log in to comment

Get this paper in your agent:

hf papers read 2609.06140
Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash

Models citing this paper 0

No model linking this paper

Cite arxiv.org/abs/2609.06140 in a model README.md to link it from this page.

Datasets citing this paper 0

No dataset linking this paper

Cite arxiv.org/abs/2609.06140 in a dataset README.md to link it from this page.

Spaces citing this paper 0

No Space linking this paper

Cite arxiv.org/abs/2609.06140 in a Space README.md to link it from this page.

Collections including this paper 0

No Collection including this paper

Add this paper to a collection to link it from this page.