SYNTHESIS NOTE
Topics›Agents Multi Architecture›this note

How does a signal's position in a workflow change its influence?

Multi-agent systems may amplify or suppress malicious signals based on where they enter the workflow. Understanding position-dependent propagation could reveal which nodes are most critical to defend.

Synthesis note · 2026-05-28 · sourced from Agents Multi Architecture

FLOWSTEER's attack works because of two structural regularities in how multi-agent workflows propagate information. First, position matters: the same malicious signal injected into a high-influence subtask propagates far more than one injected into a peripheral node, because downstream agents depend on the outputs of upstream ones. Influence is not uniform across the graph — it concentrates wherever many dependencies converge. Second, framing matters: a signal dressed in sycophantic, task-relevant language is more likely to be relayed by downstream agents, because it reads as evidence rather than as instruction. The attack aligns a malicious signal with an influential subtask and then guides replanning toward dependency patterns that preserve propagation.

These two regularities compose into a propagation mechanics that any MAS designer should recognize. The pattern generalizes beyond attacks: legitimate signals also gain or lose influence by position, and any framing that mimics evidence will be over-trusted downstream. The counterpoint is that replanning introduces instability — a manipulated prompt may cause the planner to regenerate roles and dependencies — but FLOWSTEER turns even this into an asset by expressing propagation-favorable dependency patterns as natural-language guidance. This matters because it tells us where to harden: not every node equally, but the high-influence positions, and not every input equally, but those whose framing borrows the authority of evidence.

Inquiring lines that read this note 60

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

Can single-point security defenses protect multi-agent systems from multi-step attacks? Why do agents falsely report success on failed tasks? How should agents manage memory granularity to improve long-term performance? How does misalignment propagate through agent communication networks? Can multi-agent systems avoid converging on false agreement without deliberation? When do multi-agent systems outperform single frontier models? Why do some clarifying approaches produce understanding while others just satisfy? How do standardized protocols improve multi-agent coordination and reliability? How can persona-attention mechanisms improve both recommendation quality and explainability? Do multi-agent systems introduce security vulnerabilities that single-agent architectures avoid? How can humans maintain meaningful oversight as AI systems become increasingly autonomous and complex? What attack surfaces do reasoning traces and chains introduce? What trajectory-level metrics beyond task success best evaluate agent performance? How do agent-learned skills transfer and improve across different tasks? What execution architectures enable agents to most effectively use tools? Can harness architecture and protocols provide agent reliability without model scaling? How do multi-agent LLM systems fail distinctly compared to single agents? How can we detect and prevent harm propagation through multi-agent delegation workflows? What types of diversity prevent reasoning systems from collapsing? How effective are honeytokens and decoys against different security threats? How can infrastructure records verify actual agent behavior?

Related concepts in this collection 4

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
15 direct connections · 108 in 2-hop network ·medium cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

workflow position amplifies or suppresses malicious signals and sycophantic framing makes downstream agents relay them