Cross-System Agent Traversal
Multi-Agent SecurityDescription
Compromised agents use legitimate access and trust relationships to traverse connected systems. Agents acting as insider threats leverage authorised access to reach unauthorised resources across system boundaries.
Compromised customer service agent uses its database access to enumerate internal APIs and reach HR system data.
Academic studies and structured red-team evaluations have confirmed that LLMs produce materially different outputs for semantically equivalent prompts across runs, but there is no widely reported production incident where this inconsistency caused a discrete, documented harm event at scale in a deployed financial application.
Primary mitigations
- Strict agent network segmentation
- cross-system access monitoring
- lateral movement detection
- agent access path analysis.
Detection signals
Lateral movement detection events; cross-boundary access anomalies; agent authentication failures.