NOTAS DE CAMPO / LDM ZARAGOZA / CALATAYUD · 2026
RESEARCH IA/PAPER 08

AGENTES · EVALUACIÓN · SEGURIDAD

MAStrike: Shapley-Guided Collusive Red-Teaming on Multi-Agent Systems

InteresanteLectura primaria completa

Red-teaming para sistemas multiagente jerárquicos.

AUTHORS / LABChejian Xu, Zhaorun Chen, Jingyang Zhang, Freddy Lecue, Avni Kothari, Sarah Tan, Wenbo Guo, Bo Li
FECHAV1 11 JUNIO 2026; V2 12 JUNIO 2026.
LECTURALectura primaria completa
LECTURA DE 60 SEGUNDOS

Lo esencial antes de invertir más tiempo.

HALLAZGO

Red-teaming para sistemas multiagente jerárquicos. Usa valores de Shapley para estimar qué agentes contribuyen más a la robustez del sistema y detectar coaliciones vulnerables. Construye benchmarks y entornos en finanzas, software engineering y CRM.

EVIDENCIA DISPONIBLE

Among the domains, they achieve strong performance in engineering tasks, demonstrating superior coding capabilities, with near-perfect success rates on code changes, DevOps, and data operations.

Resultado reportado con fuente enlazada · 5 localizadores disponibles.
LÍMITE

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 6 Experiments.

SIGUIENTE PRUEBA

Comparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.

EN UNA FRASE

Red-teaming para sistemas multiagente jerárquicos. Usa valores de Shapley para estimar qué agentes contribuyen más a la robustez del sistema y detectar coaliciones vulnerables. Construye benchmarks y entornos en finanzas, software engineering y CRM.

SEÑALbanca · CRM
EVIDENCIAResultado reportado con fuente enlazada
CONFIANZA EDITORIALMedia
RESULTADOS / PROCEDENCIA

Qué está reportado y qué conviene comprobar.

Hay resultado reportado con fuente enlazada.
RESULTADO REPORTADO

Among the domains, they achieve strong performance in engineering tasks, demonstrating superior coding capabilities, with near-perfect success rates on code changes, DevOps, and data operations.

contexto: 6 Experiments

RESULTADO REPORTADO

Finance tasks show moderate difficulty, with consistent performance on card and payment operations but noticeably lower success on account access.

contexto: 6 Experiments

RESULTADO REPORTADO

Overall, Gemini 3.1 Pro achieves the highest average success rate (72.3%), followed by Claude Opus 4.7 (69.6%) and GPT-5.5 (64.8%), but all models exhibit significant variance across tasks.

72.3% · contexto: 6 Experiments

LECTURA DEL PAPER / SÍNTESIS EDITORIAL

Qué estudiaron y qué cambia.

La síntesis está separada de los resultados reportados y de las inferencias.

PROBLEMA / La señal entra en el radar porque La seguridad de un sistema multiagente no es la suma de seguridades individuales; los ataques pueden coordinarse entre roles.

MÉTODO / La lectura de 2 Related Work describe la intervención y su construcción: Existing methods to red-team MAS apply techniques such as malicious content injection, persuasion, manipulating agent traits, and communication-based attacks 13 ; 2 ; 27 ; 11 ; 8 . However, they rely on heuristic choices to select the attacking agent(s) and do not model connections between agents. There have been efforts to study connections between agents, such as 10 who identified three types of behaviors in MAS that could increase the risks of system failure, namely conflict, miscoordination, collusion. However, they do not propose approaches to measure these failures, or leverage these behaviors to improve… [Fuente: https://arxiv.org/html/2606.12918#S2]

RESULTADO / La sección 6 Experiments informa: Among the domains, they achieve strong performance in engineering tasks, demonstrating superior coding capabilities, with near-perfect success rates on code changes, DevOps, and data operations. Finance tasks show moderate difficulty, with consistent performance on card and payment operations but noticeably lower success on account access. Overall, Gemini 3.1 Pro achieves the highest average success rate (72.3%), followed by Claude Opus 4.7 (69.6%) and GPT-5.5 (64.8%), but all models exhibit significant variance across tasks. [Fuente: https://arxiv.org/html/2606.12918#S6]

LÍMITE / El cierre de la fuente señala: We propose MAStrike , an end-to-end framework for collusive red-teaming in hierarchical MAS that leverages agent-level Shapley value analysis to quantify each agent’s marginal contribution to system robustness under task-specific distributions. We design an autonomous red-teaming agent guided by Shapley values to identify vulnerable coalitions and generate coordinated, role-aware adversarial manipulations. Extensive experiments across multiple MAS… La transferencia a auditoría de sistemas multiagente requiere repetir la comparación con datos y criterios propios [Fuente: https://arxiv.org/html/2606.12918#S7].

DECISIÓN RÁPIDAProbar la propuesta en auditoría de sistemas multiagente reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.
NO LO SOBREINTERPRETES

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 6 Experiments.

PROBLEMA
La seguridad de un sistema multiagente no es la suma de seguridades individuales; los ataques pueden coordinarse entre roles.
MÉTODO
La lectura de 2 Related Work describe la intervención y su construcción: Existing methods to red-team MAS apply techniques such as malicious content injection, persuasion, manipulating agent traits, and communication-based attacks 13 ; 2 ; 27 ; 11 ; 8 . However, they rely on heuristic choices to select the attacking agent(s) and do not model connections between agents. There have been efforts to study connections between agents, such as 10 who identified three types of behaviors in MAS that could increase the risks of system failure, namely conflict, miscoordination, collusion. However, they do not propose approaches to measure these failures, or leverage these behaviors to improve…
TIPO DE EVIDENCIA
La sección 6 Experiments informa 3 hallazgo(s) extraído(s) desde la fuente. El resultado principal se conserva con el localizador de sección https://arxiv.org/html/2606.12918#S6.
LÍMITE
La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 6 Experiments.
FIELD NOTES / ANOTACIONES

La lectura también deja rastro.

Guarda una observación junto a la evidencia. Tú escribes aquí; los agentes pueden añadir notas por MCP y aparecerán identificados.

MEMORIA PRIVADAEntra para anotar este paper y conectarlo con otros.
Entrar con ChatGPT
LECTURA AMPLIADAMetodología, implicaciones y preguntas para volver al paper.+
LECTURA EN 90 SEGUNDOSLo que conviene llevarse antes de abrir el PDF.
QUÉ HACE

La lectura de 2 Related Work describe la intervención y su construcción: Existing methods to red-team MAS apply techniques such as malicious content injection, persuasion, manipulating agent traits, and communication-based attacks 13 ; 2 ; 27 ; 11 ; 8 . However, they rely on heuristic choices to select the attacking agent(s) and do not model connections between agents. There have been efforts to study connections between agents, such as 10 who identified three types of behaviors in MAS that could increase the risks of system failure, namely conflict, miscoordination, collusion. However, they do not propose approaches to measure these failures, or leverage these behaviors to improve…

QUÉ APORTA

Las empresas están empezando a diseñar equipos de agentes, y esa arquitectura introduce superficies de ataque nuevas: colusión, escalada de privilegios, manipulación entre agentes.

QUÉ NO PRUEBA

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 6 Experiments.

Cómo lo llevaría a un proyecto

Probar la propuesta en auditoría de sistemas multiagente reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.

auditoría de sistemas multiagenteseguridad de workflowsrevisión de permisossimulación adversarial.

Preguntas que conviene probar

  • ¿La mejora se mantiene cuando auditoría de sistemas multiagente cambia de dominio o distribución?
  • ¿Qué componente del método explica la mayor parte del resultado y qué baseline lo pone realmente a prueba?
PLANTILLA DE PRUEBA / INFERENCIA EDITORIAL

Si tuviera que convertirlo en una prueba mañana.

ENTRADAauditoría de sistemas multiagente con un conjunto pequeño de casos representativos y la misma métrica o protocolo que la fuente cuando sea reproducible.
PREGUNTA¿La propuesta mejora auditoría de sistemas multiagente frente a la línea base actual?
MÉTRICAComparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.
PARADAParar si no aparece una mejora reproducible o si aumenta el riesgo, la complejidad o el coste sin compensación.

Mi lectura

La pregunta operativa es si auditoría de sistemas multiagente puede medirse con una línea base y un criterio de parada claros.

Esta última frase es una inferencia editorial a partir del paper y de sus posibles implicaciones; no es una afirmación de los autores.