対スウォーム・ドクトリン:協調型エージェント侵入の封じ込め
Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions
September 5, 2026
著者: Gregory N Frank
cs.AI
要旨
エージェントは共有インフラストラクチャを協調型侵入のチャネルに変えうる。Hugging Faceのインシデントと別個の公開ウィキ調査は、セキュリティ評価が複数の実行とそれらが残すアーティファクトからの証拠を必要としうる理由を示している。我々は、防御の運用単位は、観測された転送、タスク権限、応答履歴を結びつける改訂可能な協調エピソードであるべきだと論じる。中心的な研究課題は予期的エピソード発見である。すなわち、評価者がそれらの所属を提供する前に、どの行為が一緒に属するかを見つけることである。我々は、非認可の協調を協働および委譲権限ポリシーに対して定義し、ストレージ媒介型協調をスティグメルジーに結びつけ、影響を共通原因から区別するために必要な証拠を特定する。初回接触シグナルは発見への可能な入力の一つであり、設計は継承された状態と後続の利用も追跡する。提案する評価は、孤立した行為、ローリングウィンドウ、既知のグループ、予期的に発見されたエピソードを、一致させたレビューコストと誤警報負荷の下で比較する。それは、割り当てられたすべての母集団実行にわたる有害な結果を測定し、チャネル閉鎖と状態隔離後の再発を検証する。チェックサム検証済みの公開ウィキエクスポートの再構築は、保持された書き込みの減少を後続の管理上のクリーンアップから分離する。貢献は、インシデントに根差した立場、記述的分析、評価設計である。それは、新しい検出器や測定された封じ込め便益を主張することなく、実行をまたぐ監視という勧告を検証可能にする。
English
Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.