OpenEvoShield: Dual Non-Stationary Continual Defense for Open-World Multi-Agent System Attacks
Unlike static threats, these attacks are doubly dynamic: adversaries refine injection strategies against deployed defenses while normal-agent behavior drifts with system expansion. Existing defenses treat deployment as a closed-world problem and degrade rapidly once either distribution shifts beyond training coverage. We propose OpenEvoShield, a co-evolutionary continual defense framework for LLM-MAS.
- ▪Unlike static threats, these attacks are doubly dynamic: adversaries refine injection strategies against deployed defenses while normal-agent behavior drifts with system expansion.
- ▪Existing defenses treat deployment as a closed-world problem and degrade rapidly once either distribution shifts beyond training coverage.
- ▪We propose OpenEvoShield, a co-evolutionary continual defense framework for LLM-MAS.
Opening excerpt (first ~120 words) tap to expand
Computer Science > Artificial Intelligence arXiv:2607.19351 (cs) [Submitted on 13 May 2026] Title:OpenEvoShield: Dual Non-Stationary Continual Defense for Open-World Multi-Agent System Attacks Authors:Litian Zhang, Chaozhuo Li, Yuting Zhang, Zejian Chen, Bingyu Yan, Qiwei Ye View a PDF of the paper titled OpenEvoShield: Dual Non-Stationary Continual Defense for Open-World Multi-Agent System Attacks, by Litian Zhang and 5 other authors View PDF HTML (experimental) Abstract:LLM-based multi-agent systems (LLM-MAS) are increasingly deployed in safety-critical applications, where adversaries inject malicious instructions through inter-agent communication to propagate harmful behaviors.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at arXiv.org.