July 2026Unreviewed
ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems
Elias Hossain, Md Mehedi Hasan Nipu, Fatema Tuj Johora Faria, Tasfia Nuzhat Ornee, Maleeha Sheikh
Abstract
Multi-agent LLM applications chain a planner, worker agents, a verifier, and a synthesizer, and every hop between agents is an unmonitored channel through which an adversary can smuggle instructions. Existing defenses guard only the input boundary (IBProtector, Llama Guard, perplexity filters, SmoothLLM) or run outside the application as opaque, stochastic provider-side filters. We show this gap carries a consequence rarely measured: on a 2,100-trace evaluation across eight attack families, five
Categories
Cite
@misc{hossain2026channelguard,
title = {{ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems}},
author = {Elias Hossain and Md Mehedi Hasan Nipu and Fatema Tuj Johora Faria and Tasfia Nuzhat Ornee and Maleeha Sheikh},
year = {2026},
month = jul,
eprint = {2607.19430},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.19430}
}