Skip to content
Search
paperJuly 2026Unreviewed

ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems

Elias Hossain, Md Mehedi Hasan Nipu, Fatema Tuj Johora Faria, Tasfia Nuzhat Ornee, Maleeha Sheikh

Abstract

Multi-agent LLM applications chain a planner, worker agents, a verifier, and a synthesizer, and every hop between agents is an unmonitored channel through which an adversary can smuggle instructions. Existing defenses guard only the input boundary (IBProtector, Llama Guard, perplexity filters, SmoothLLM) or run outside the application as opaque, stochastic provider-side filters. We show this gap carries a consequence rarely measured: on a 2,100-trace evaluation across eight attack families, five

Categories

Cite

@misc{hossain2026channelguard,
  title = {{ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems}},
  author = {Elias Hossain and Md Mehedi Hasan Nipu and Fatema Tuj Johora Faria and Tasfia Nuzhat Ornee and Maleeha Sheikh},
  year = {2026},
  month = jul,
  eprint = {2607.19430},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.19430}
}