Conceptio › Archive › arXiv CS
arXiv CSopen access

Concealing LLM-Based Multi-Agent Topology via Phantom Structure Injection

Longzhu He et al. · arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

P REPRINT.

C ONCEALING LLM-BASED M ULTI -AGENT T OPOLOGY VIA P HANTOM S TRUCTURE I NJECTION Longzhu He Nanyang Technological University

Zelang Wen Beijing University of Posts and Telecommunications

arXiv:2609.37567v1 [cs.CR] 29 Sep 2026

Sen Su Beijing University of Posts and Telecommunications

Xinfeng Li The Hong Kong Polytechnic University

XiaoFeng Wang Nanyang Technological University

A BSTRACT Driven by the rapid advancement of large language models (LLMs), LLM-based multi-agent systems (MAS) have emerged as a powerful paradigm for collaborative reasoning over complex tasks. A key design element of MAS is the communication topology, which governs information flow among agents and often encodes proprietary knowledge about the system architecture. However, recent work has shown that such topologies can be inferred even in black-box settings by exploiting semantic dependencies in observable reasoning traces, posing significant risks of intellectual property leakage and exposure of system vulnerabilities. To address this threat, we propose M IRAGE, a topology-concealment framework that preserves the genuine communication topology for task execution while shaping adversary-facing semantic evidence toward a carefully constructed phantom topology. Specifically, M IRAGE operates in three stages: ① phantom topology synthesis, ② semantic edge realization, and ③ protected MAS execution. It constructs a phantom topology structurally distinct from the genuine one, materializes phantom edges as plausible semantic dependencies, and suppresses source-specific cues that could reveal genuine edges absent from the phantom topology. Extensive experiments across three topology optimization frameworks and four benchmark datasets demonstrate that M IRAGE substantially reduces the effectiveness of topology inference attacks while largely preserving the task utility of the protected MAS.

1

I NTRODUCTION

The rapid advancement of large language models (LLMs) (Naveed et al., 2025) has given rise to LLM-based multi-agent systems (MAS) (Li et al., 2024; He et al., 2025a; Shao et al., 2026; Du et al., 2026), which harness collaborative reasoning and division of labor among multiple agents to achieve remarkable performance on complex, multi-step tasks. Compared with single-agent approaches (Yang et al., 2024; Shinn et al., 2023; Zhao et al., 2024), MAS decompose complex analytical tasks into specialized subtasks handled by agents with distinct expertise, demonstrating strong capabilities in data-intensive scenarios such as data analysis (Bai et al., 2025), mathematical reasoning (Lei et al., 2024), and code generation (Islam et al., 2024). These advantages have established MAS as an increasingly important technical paradigm for frontier applications, including data discovery (Xiao et al., 2026), web data collection (Ma et al., 2025), and scientific discovery (Ghareeb et al., 2026). The effectiveness of MAS largely stems from their carefully designed communication topology, which defines the directed connectivity structure governing information flow among agents. By determining how agents interact and how information propagates through the system, the topology directly shapes the system’s reasoning process and task performance. Recent studies (Zhang et al., 2025; Li et al., 2025; 2026) have therefore explored topology optimization methods that automatically construct effective communication structures for specific tasks. These carefully optimized topologies can thus encode substantial design expertise and constitute valuable intellectual property (IP). However, as MAS are increasingly deployed in real-world applications, their communication topology introduces a largely overlooked security concern. Existing research has primarily focused on attacks targeting communication content, such as malicious prompt propagation (Lee et al., 2025) 1

P REPRINT.

Adversarial Query

Adversarial Query Adversary

MAS Output

Black-box MAS Access

Adversary

Injection

Phantom Topology

Structural Vulnerability Exposure

MAS Output

Intellectual Property (IP) Threat

(a) Topology Inference Attack against MAS

(b) Our MIRAGE Defense

Figure 1: Comparison of topology inference attack and M IRAGE defense. (a) The topology inference attack against LLM-based MAS exploits semantic dependencies in observable reasoning traces to infer the genuine communication topology G. (b) M IRAGE constructs a phantom topology G ′ to mislead topology inference while preserving G for actual task execution. This design decouples topology exposure from task execution, effectively concealing the genuine communication topology. and communication manipulation (He et al., 2025b; Ju et al., 2026), while the confidentiality of the communication topology itself has received limited attention. Recently, CIA (Wu et al., 2026), as illustrated in Fig. 1(a), revealed that an adversary can infer the internal communication topology of an MAS solely through black-box interactions. Its key insight is that directly connected agent pairs tend to exhibit stronger semantic dependencies in their observable reasoning outputs, which can be exploited to reconstruct the underlying topology. Such topology leakage not only exposes proprietary system architectures but also reveals critical agents and communication pathways, enabling adversaries to launch targeted attacks that can compromise the security of the MAS. In light of this threat, an important research question arises: can we effectively protect the communication topology of an MAS from inference attacks without compromising its task performance? This problem is challenging because an effective defense method must reconcile two seemingly conflicting objectives: disrupting the semantic evidence that reveals the true topology while preserving the information flow required for task execution. Existing MAS defense studies primarily address content-level security (Zhang et al., 2024; Miao et al., 2025; Raza et al., 2026; Zhou et al., 2025), leaving systematic protection against communication topology inference attacks largely unexplored. To address this gap, we propose M IRAGE, a topology-concealment framework that separates the topology governing task execution from the topology exposed to adversaries. As shown in Fig. 1(b), M IRAGE proactively constructs a phantom topology G ′ that is structurally distinct from the genuine topology G. Specifically, M IRAGE consists of three stages: ① phantom topology synthesis, ② semantic edge realization, and ③ protected MAS execution. The first stage synthesizes the phantom topology G ′ under structural constraints to ensure sufficient divergence from G. The second stage materializes phantom edges as plausible, task-relevant semantic dependencies while suppressing the sourcespecific semantic signatures of genuine edges absent from G ′ . The final stage executes tasks strictly according to G while generating adversary-facing traces through a separate exposure view shaped toward the phantom topology G ′ . This design preserves the original communication structure for task execution while obscuring the genuine topology from inference attacks (Wu et al., 2026). We evaluate M IRAGE on four representative datasets across three domains: general reasoning (MMLU (Hendrycks et al., 2021)), mathematical reasoning (GSM8K (Cobbe et al., 2021) and SVAMP (Patel et al., 2021)), and code generation (HumanEval (Chen et al., 2021)). Experimental results show that M IRAGE substantially reduces the effectiveness of topology inference attacks while largely preserving the task utility of the protected MAS. The main contributions of this paper are summarized as follows: ⋄ Important Problem. This paper investigates the communication topology confidentiality problem in LLM-based MAS, highlighting the security and intellectual property risks posed by topology inference attacks and addressing an underexplored security dimension of multi-agent systems. ⋄ Novel Defense. The proposed M IRAGE separates task execution from adversary exposure through phantom topology synthesis, semantic edge realization, and dual-view protected execution. ⋄ Extensive Evaluation. Extensive experiments cover three representative MAS topology optimization frameworks and four benchmark datasets across diverse reasoning and code generation tasks: MMLU, GSM8K, SVAMP, and HumanEval. The results demonstrate that M IRAGE substantially reduces topology inference effectiveness while largely preserving the task utility. 2

P REPRINT.

2

P RELIMINARIES

This section introduces the essential background on LLM-based multi-agent systems and topology inference attacks, followed by the problem definition. Important notations are summarized in App. A. LLM-based MAS. An LLM-based MAS is formalized as S = (P, G), where P = {pi }ni=1 denotes the set of agent profiles, with each pi specifying the corresponding agent’s system prompt, callable tools, and other configuration details. The communication topology is represented as a directed acyclic graph (DAG) G = (A, E), where A = {ai }ni=1 is the set of agents and E is the set of directed communication edges. An edge (aj , ai ) ∈ E indicates that the output of agent aj is passed to agent ai as part of its input. By governing how information is propagated and aggregated across agents, the communication topology plays a central role in MAS performance (Zhang et al., 2025; Li et al., 2025; 2026). In practical deployments, a carefully optimized topology may therefore constitute valuable intellectual property for system developers. Given a task query q, the output of agent ai is defined as ri = LLM(pi , q, Oi ), where Oi = {rj | (aj , ai ) ∈ E} denotes the set of outputs received from its predecessor agents. The final output of the system S is produced by the designated decision agent an : rn = S(q) = LLM(pn , q, On ).

(1)

Topology Inference Attack. The topology inference attack aims to reconstruct the hidden communication topology G of an MAS S under black-box access, relying only on adversarial queries and the corresponding system responses. A representative attack is CIA (Wu et al., 2026), which first crafts specially designed adversarial queries to induce the MAS to expose the intermediate reasoning outputs of its agents, and then exploits the semantic dependencies among these outputs to infer the underlying communication edges. More details of the CIA attack are provided in App. B. Problem Definition. Given an LLM-based MAS S = (P, G) with a private topology G, we consider a black-box adversary that attempts to reconstruct G via topology inference. This work aims to protect G from topology inference while preserving its use for task execution. Specifically, we seek to construct a protected system Se that reshapes adversary-facing evidence such that the inferred topology Gb deviates from the genuine topology G. Formally, the defense aims to maximize the discrepancy between the inferred and genuine topologies, subject to bounded degradation in task utility: b G) max ∆topo (G, Se

s.t.

e ≥ U (S) − ϵ, U (S)

(2)

where Gb denotes the topology inferred by the adversary, ∆topo (·, ·) measures the discrepancy between two topologies, U (·) denotes task utility, and ϵ specifies the maximum allowable utility degradation.

3

T HREAT M ODEL

This section defines the threat model by specifying the adversary’s objectives and capabilities. Adversary’s Objectives. The adversary aims to reconstruct the true communication topology G of the target multi-agent system S. Successful topology inference may lead to two major security risks: ⋄ Structural Vulnerability Exposure. Once the communication topology G is revealed, the adversary can identify critical agents, such as those with high in-degree or betweenness centrality, and important communication pathways. Such structural knowledge can facilitate targeted attacks, including jailbreaking (Gu et al., 2024; Shahroz et al., 2025), prompt injection (Lee et al., 2025; He et al., 2025b; Arif et al., 2026), and other attacks (Kavathekar et al., 2026) against the MAS. ⋄ Intellectual Property (IP) Threat. A carefully optimized communication topology G often embodies substantial computational investment and expert design knowledge, making it a valuable proprietary asset of system developers (Li et al., 2026; Zhang et al., 2025; Li et al., 2025). Leakage of the topology may expose internal architectural design information, enable unauthorized replication of the system, and undermine the competitive advantage of the system owner. Adversary’s Capabilities. The adversary operates under a strict black-box setting. Specifically, the adversary can submit queries of its choice to the target system S and observe the corresponding final response S(q). The adversary has no direct access to internal information, including agent profiles P = {pi }ni=1 , system prompts, intermediate communication messages, or the true communication topology G. Nevertheless, the adversary may craft adversarial queries that induce the system to expose information related to intermediate agent outputs in its final response, which can subsequently be exploited for topology inference. Furthermore, the adversary cannot modify agent configurations, communication edges, or any other internal component of S during the attack process. 3

P REPRINT.

G = (A, E)

Target MAS

Constraint

Ep

Kρ0(G)

Eh

Anonymity Set

Phantom Topology G’

II: Semantic Edge Realization

Mϕ Ep

Phantom

Eh

Genuine

aj ai

Phantom Edge Ri

III: Protected MAS Execution

aj ai

Genuine Edge

Query

I: Phantom Topology Synthesis

Protected MAS Output

Adversary

Figure 2: Overview of M IRAGE. M IRAGE consists of three stages: ① phantom topology synthesis, ② semantic edge realization, and ③ protected MAS execution. Stage I constructs a phantom topology G ′ that deviates from the genuine topology G. Stage II realizes G ′ by shaping adversary-facing semantic dependencies. Stage III preserves G for task execution while exposing dependency evidence aligned with G ′ , thereby concealing the genuine topology with minimal impact on task utility.

4

M ETHODOLOGY

To defend against topology inference attacks, we propose M IRAGE, a topology-concealment framework that decouples the communication structure used for actual task execution from that exposed to the adversary. M IRAGE consists of three stages: ① Phantom Topology Synthesis, ② Semantic Edge Realization, and ③ Protected MAS Execution. The overall workflow is illustrated in Fig. 2 and Alg. 1. 4.1

P HANTOM T OPOLOGY S YNTHESIS

At this stage, M IRAGE carefully constructs a phantom topology G ′ = (A, E ′ ) to guide adversaryfacing evidence away from the genuine topology G. We preserve the original agent set A and perturb only communication edges, avoiding additional agents, roles, or execution traces. This edge-level design minimizes changes to the underlying MAS while more directly targeting the confidential communication structure. An effective phantom topology should sufficiently differ from G to hinder topology recovery while remaining structurally feasible as a legitimate MAS topology. Accordingly, we formulate its construction as a constrained topology reconstruction problem. Specifically, let π(·) denote the execution order induced by G. We first define the admissible edge space as Uπ = {(aj , ai ) | π(aj ) < π(ai )}, ensuring that candidate edges respect the execution order and do not introduce cycles. Accordingly, the feasible topology set is defined as Ω(G) = {H = (A, EH ) | EH ⊆ Uπ , ∀ai ̸= an , ai ⇝H an },

(3)

where ai ⇝H an indicates that a directed path exists from agent ai to the decision agent an under H. The first constraint ensures that the synthesized topology remains acyclic, while the second prevents isolated agents or branches that cannot contribute to the final decision. To quantify the structural deviation of a candidate topology from the true topology G, we define the structural camouflage ratio (SCR) as ρ(H, G) = 1 − |EH ∩ E|/|EH ∪ E|, where ρ ∈ [0, 1], with larger values indicating less structural overlap with G. In particular, ρ = 0 corresponds to identical topologies, whereas ρ = 1 indicates no shared communication edges. Rather than relying on a single predetermined surrogate, M IRAGE further introduces a topology anonymity set, inspired by the principle of kanonymity (Sweeney, 2002), to conceal G among multiple structurally feasible alternatives. Definition 1 (Topology Anonymity Set). Given a genuine topology G and a minimum structural deviation ρ0 , the topology anonymity set of G is defined as Kρ0 (G) = {H ∈ Ω(G) | ρ(H, G) ≥ ρ0 }. The corresponding anonymity level is characterized by Ktopo = |Kρ0 (G)|, i.e., the number of feasible topologies satisfying the minimum structural deviation from the genuine topology G. The topology anonymity set captures both structural deviation and candidate diversity: ρ0 controls deviation from the genuine topology, while Ktopo reflects the number of feasible alternatives. In practice, M IRAGE constructs Kρ0 (G) via order-preserving edge rewiring over Uπ while preserving connectivity to the decision agent and respecting the original execution order. A candidate satisfying ρ(H, G) ≥ ρ0 is selected as the phantom topology G ′ , inducing Ep = E ′ \ E and Eh = E \ E ′ for phantom and concealed genuine relations, respectively. 4.2

S EMANTIC E DGE R EALIZATION

Given the phantom topology G ′ , the next challenge is to make its structural relations observable to the adversary through semantic dependencies. Since topology inference attacks exploit semantic de4

P REPRINT.

pendencies among observable reasoning traces, merely constructing G ′ is insufficient: phantom edges must be manifested as plausible semantic dependencies, while genuine edges absent from G ′ should be obscured to suppress their source-target dependencies. M IRAGE therefore performs phantom structure injection in two directions: ① phantom edge materialization and ② genuine edge obfuscation. Both operations are applied to the adversary-facing context and do not alter the underlying communication topology used for task execution. More implementation details are provided in App. C. Phantom Edge Materialization. For each Algorithm 1 Overview of M IRAGE phantom edge (aj , ai ) ∈ Ep , M IRAGE cre- Input: MAS S = (P, G), query q, deviation threshates semantic evidence sph old ρ0 , generator Mϕ . j→i consistent with a dependency from agent aj to ai . Specifically, Output: Protected response S(q). e ph sj→i is generated by an LLM-based gener// I. P HANTOM T OPOLOGY S YNTHESIS ator Mϕ conditioned on the source agent’s 1: Construct Kρ0 (G) via edge rewiring. profile pj and execution output rj , the target 2: Select G ′ = (A, E ′ ) ∈ Kρ0 (G). agent’s profile pi , the query q, and the target’s 3: Ep ← E ′ \ E, Eh ← E \ E ′ . current task-relevant contextual state ci : // II. S EMANTIC E DGE R EALIZATION ph 4: for each agent ai ∈ A in execution order do sj→i = Mϕ (pj , rj , pi , q, ci ). (4) 5: Oi ←{rj |(aj , ai )∈E}; ri ←LLM(pi , q, Oi ). Here, ci denotes the task-relevant context 6: Materialize sph j→i for (aj , ai ) ∈ Ep . available to ai . To ensure effective phantom (m) edge materialization, the generated evidence 7: Generate Ri = {r̂i }M m=1 from ri . follows three principles: ① role consistency, 8: Select rei via dependency-aware obfuscation. 9: end for aligning the content with the source agent’s // III. P ROTECTED MAS E XECUTION capabilities; ② task relevance, providing useful information for the target agent; and ③ de- 10: Retain {ri } as the execution view. pendency plausibility, maintaining semantic 11: Build the exposure view using {sph ri }. j→i } and {e consistency with rj while forming a plausible e 12: Generate the protected response S(q). dependency toward ai without introducing e 13: return S(q). unsupported information or topology cues. Genuine Edge Obfuscation. Phantom edge materialization alone cannot conceal genuine edges that are absent from G ′ . For each agent ai , M IRAGE therefore suppresses the observable dependency evidence directly associated with its hidden genuine predecessors Pih = {aj | (aj , ai ) ∈ Eh }, while preserving the task-relevant semantics of its original execution trace ri . Specifically, M IRAGE adopts (m) controlled paraphrasing (Bandel et al., 2022) to generate a candidate set Ri = {r̂i }M m=1 from ri . The paraphrasing process varies the expression and organization of the original trace while preserving its task-relevant facts, reasoning, and conclusions. The protected trace is then selected according to   X rei = arg min Dsem (r̂, ri ) + λ Sdep (rj , r̂) , (5) r̂∈Ri

aj ∈Pih

where Dsem (·, ·) measures semantic distortion, Sdep (·, ·) measures semantic dependency, with higher values indicating stronger dependency, and λ balances semantic preservation and dependency suppression. By suppressing genuine dependency cues while preserving task-relevant semantics, genuine edge obfuscation complements phantom edge materialization to shift the observable dependency structure away from G and toward G ′ without altering the underlying task execution. 4.3

P ROTECTED MAS E XECUTION

Given G ′ , M IRAGE decouples task execution from adversary-facing exposure to preserve utility while concealing the genuine topology. Specifically, the protected MAS operates through two views: ⋄ Execution View. Each agent executes over the genuine topology G, receiving outputs only from its predecessors: Oi = {rj | (aj , ai ) ∈ E} and ri = LLM(pi , q, Oi ). The phantom topology does not participate in internal communication, and all genuine message passing remains governed by G. ⋄ Exposure View. Before exposure, M IRAGE obfuscates genuine dependencies in Eh to obtain rei and incorporates phantom evidence from Ep to construct riexp . The resulting semantic dependencies are shaped away from G and toward G ′ . This dual-view design retains G for task execution while exposing dependency evidence aligned with G ′ , thereby concealing the genuine communication topology with minimal impact on task utility. 5

ACC Metrics

F1

ACC Metrics

F1

0.63 0.52

0.72 0.44

0.8 0.6 0.4 0.2 0.0 AUC

0.83 0.68

Performance

0.75

No Defense Ours

0.39

0.91 0.48

0.8 0.6 0.4 0.2 0.0 AUC

0.85 0.64

Performance

0.73

No Defense Ours

0.42

0.89 0.51

F1

0.8 0.6 0.4 0.2 0.0 AUC

0.83 0.64

ACC Metrics

No Defense Ours

Performance

0.74 0.49

0.73 0.50

0.8 0.6 0.4 0.2 0.0 AUC

0.81 0.67

Performance

P REPRINT.

No Defense Ours

ACC Metrics

F1

(a) MMLU

(b) GSM8K

ACC Metrics

(c) SVAMP

F1

0.69 0.49

0.77

0.65

0.89

0.8 0.6 0.4 0.2 0.0 AUC

0.48

No Defense Ours

Performance

0.75 0.53

0.90

0.84 0.51

F1

0.8 0.6 0.4 0.2 0.0 AUC

0.63

ACC Metrics

No Defense Ours

Performance

0.79

0.81

0.87 0.71

0.48

F1

0.8 0.6 0.4 0.2 0.0 AUC

0.47

ACC Metrics

No Defense Ours

Performance

0.76 0.46

0.79 0.49

0.8 0.6 0.4 0.2 0.0 AUC

0.89 0.70

Performance

(a) MMLU (b) GSM8K (c) SVAMP (d) HumanEval Figure 3: Comparison of topology inference performance using G-Designer before defense (No Defense) and with M IRAGE (Ours) across four benchmark datasets in terms of AUC, ACC, and F1.

No Defense Ours

ACC Metrics

F1

(d) HumanEval

Figure 4: Comparison of topology inference performance using AGP before defense (No Defense) and with M IRAGE (Ours) across four benchmark datasets in terms of AUC, ACC, and F1.

5

E XPERIMENTS

In this section, we conduct extensive experiments to evaluate M IRAGE in protecting the communication topology of LLM-based MAS while preserving task utility across diverse tasks and communication topology configurations. Specifically, we investigate the following research questions: ⋄ RQ1: How effectively does M IRAGE defend against communication topology inference attacks? ⋄ RQ2: How well does M IRAGE preserve task utility while protecting communication topologies? ⋄ RQ3: How do the components and parameter settings of M IRAGE affect its defense effectiveness? ⋄ RQ4: How does M IRAGE conceal the genuine communication topology in representative cases? 5.1

E XPERIMENTAL S ETTINGS

Datasets. We evaluate M IRAGE on four datasets covering three representative task domains. For general reasoning, we use MMLU (Hendrycks et al., 2021), which evaluates knowledge and reasoning capabilities across diverse subject areas. For mathematical reasoning, we adopt GSM8K (Cobbe et al., 2021) and SVAMP (Patel et al., 2021), both of which require multi-step reasoning to solve mathematical word problems. For code generation, we use HumanEval (Chen et al., 2021), which evaluates the functional correctness of generated programs. Consistent with prior work (Wu et al., 2026), we sample 100 tasks from each dataset for evaluation. More details are provided in App. D. MAS Frameworks. Three representative topology optimization frameworks are adopted to construct the target MAS: G-Designer (Zhang et al., 2025), AGP (Li et al., 2025), and ARG-Designer (Li et al., 2026). These frameworks employ different topology optimization strategies, enabling evaluation of M IRAGE across diverse communication structures. More details are provided in App. D. Baselines. We first compare M IRAGE against the original MAS without any protection (No Defense). For a more comprehensive evaluation, we further consider three potential defenses commonly used against prompt injection attacks (Liu et al., 2024; Zhan et al., 2025): ① Instructional Prevention (Instruction), ② Delimiters, and ③ PPL Detection. These methods respectively represent instructionlevel prevention, input isolation, and detection-based defense. More details are provided in App. D. Metrics & Parameters. We evaluate M IRAGE in terms of topology protection and task utility. Following prior work (Wu et al., 2026), topology inference is measured by AUC, ACC, and F1 over candidate communication edges, where AUC closer to 0.5 and lower ACC/F1 indicate stronger protection. Task utility is measured by accuracy across the evaluated benchmark tasks. We select ρ0 , M , and λ from {0.2, 0.4, 0.6, 0.8, 1.0}, {1, 3, 5, 7, 9}, and {0.1, 0.3, 0.5, 0.7, 0.9}, respectively. More detailed implementation and parameter settings are provided in App. D. 6

ACC Metrics

F1

ACC Metrics

F1

0.76

0.82

No Defense Ours

ACC Metrics

0.52

0.57

0.89

0.8 0.6 0.4 0.2 0.0 AUC

0.55

No Defense Ours

Performance

0.85 0.60

0.63

0.92

0.97

0.8 0.6 0.4 0.2 0.0 AUC

0.58

No Defense Ours

Performance

0.89 0.71

0.98

0.90 0.69

F1

0.8 0.6 0.4 0.2 0.0 AUC

0.72

ACC Metrics

No Defense Ours

Performance

0.78 0.42

0.77 0.49

0.8 0.6 0.4 0.2 0.0 AUC

0.81 0.65

Performance

P REPRINT.

F1

(a) MMLU (b) GSM8K (c) SVAMP (d) HumanEval Figure 5: Comparison of topology inference performance using ARG-Designer before defense (No Defense) and with M IRAGE (Ours) across four benchmark datasets in terms of AUC, ACC, and F1.

Table 1: Comparison of topology inference performance under different defense methods using G-Designer across four benchmark datasets in terms of AUC, ACC, and F1. MMLU

Method I NSTRUCTION D ELIMITERS M IRAGE (Ours)

5.2

GSM8K

SVAMP

HumanEval

AUC

ACC

F1

AUC

ACC

F1

AUC

ACC

F1

AUC

ACC

F1

0.79 0.76 0.67

0.59 0.61 0.50

0.62 0.64 0.49

0.81 0.80 0.64

0.73 0.76 0.51

0.64 0.67 0.42

0.72 0.70 0.64

0.74 0.68 0.48

0.69 0.71 0.39

0.78 0.76 0.68

0.62 0.65 0.44

0.59 0.56 0.52

R ESULTS & D ISCUSSION

Defense Effectiveness (▷ RQ1). Table 2: Statistics of communication topologies generated by Figs. 3–5 comprehensively com- three topology optimization methods across four datasets. N̄ and pare topology inference perfor- Ē denote the average numbers of agents and edges, respectively. mance before (No Defense) and MMLU GSM8K SVAMP HumanEval after applying M IRAGE (Ours) Method across three representative topolN̄ Ē N̄ Ē N̄ Ē N̄ Ē ogy optimization strategies and G-Designer 7.00 8.99 5.00 8.19 5.00 8.15 6.00 11.38 four benchmark datasets. Our AGP 6.00 10.87 5.00 8.45 5.00 8.41 6.00 11.54 M IRAGE consistently reduces ARG-Designer 5.42 7.84 3.07 3.14 3.05 3.10 4.24 5.49 AUC, ACC, and F1, demonstrating its effectiveness in concealing the genuine communication topology. We further compare M IRAGE with existing defenses. As shown in Table 1, M IRAGE achieves consistently lower topology inference performance than I NSTRUCTION and D ELIMITERS. We additionally evaluate PPL-based detection. Fig. 6 reports its ROC curves and detection AUC, which measures the ability to distinguish topologyinference queries from benign inputs. Finally, Table 2 summarizes the topology statistics across different settings. Despite substantial variations in structural complexity, the results in Figs. 3–5 show that M IRAGE remains effective across all three topology optimization strategies. Overall, these results demonstrate the effectiveness and robustness of M IRAGE against topology inference attacks. Utility Preservation (▷ RQ2). Fig. 7 compares the task utility before and after applying M IRAGE across three topology optimization strategies and four benchmark datasets. Despite substantially reducing topology inference performance, M IRAGE largely preserves the original task utility across all evaluated settings, with only minor performance variations. This demonstrates that M IRAGE effectively conceals the underlying communication topology while introducing only minor task-utility degradation, achieving a favorable balance between topology protection and task utility. Ablation Study (▷ RQ3). We conduct an ablation study to systematically evaluate the contribution of the key components in M IRAGE using G-Designer on MMLU. As shown in Fig. 8(a), removing either phantom edge materialization (w/o PEM) or genuine edge obfuscation (w/o GEO) consistently increases AUC, ACC, and F1, indicating substantially degraded topology concealment performance and demonstrating that both components are essential for effective topology concealment. Parameter Analysis (▷ RQ3). We investigate the sensitivity of M IRAGE to three key parameters, ρ0 , M , and λ, using G-Designer on MMLU. As shown in Figs. 8(b)–(d), ρ0 exhibits a clear trade-off between topology concealment and task utility, while the benefit of increasing M gradually saturates beyond M = 5. For λ, moderate values provide a better balance between dependency suppression and semantic preservation. Overall, these results demonstrate that appropriate parameter settings enable M IRAGE to effectively conceal the communication topology while preserving task utility. 7

P REPRINT.

1.0 PPL Detection 0.8 Random Guess 0.6 0.4 AUC = 0.59 0.2 0.00.0 0.2 0.4 0.6 0.8 1.0 False Positive Rate

True Positive Rate

1.0 PPL Detection 0.8 Random Guess 0.6 0.4 AUC = 0.60 0.2 0.00.0 0.2 0.4 0.6 0.8 1.0 False Positive Rate

True Positive Rate

1.0 PPL Detection 0.8 Random Guess 0.6 0.4 AUC = 0.57 0.2 0.00.0 0.2 0.4 0.6 0.8 1.0 False Positive Rate

True Positive Rate

True Positive Rate

1.0 PPL Detection 0.8 Random Guess 0.6 0.4 AUC = 0.51 0.2 0.00.0 0.2 0.4 0.6 0.8 1.0 False Positive Rate

(a) MMLU (b) GSM8K (c) SVAMP (d) HumanEval Figure 6: Overall ROC curves of PPL-based attack detection across four benchmark datasets, with the corresponding detection AUC reported and random guessing shown as a reference.

G-

r P AG esigne D G AR

(a) MMLU

Original Ours

1.0 0.8 0.6 0.4 0.2 0.0 r igne Des

r P AG esigne D G AR

G-

(b) GSM8K

Original Ours

r P AG esigne D G AR

(c) SVAMP

1.0 0.8 0.6 0.4 0.2 0.0 r igne Des

Utility

1.0 0.8 0.6 0.4 0.2 0.0 ner esig D G

Utility

Original Ours

Utility

Utility

1.0 0.8 0.6 0.4 0.2 0.0 r igne Des

G-

Original Ours

r P AG esigne D G AR

(d) HumanEval

Figure 7: Comparison of task utility before defense (Original) and with M IRAGE (Ours) across three topology optimization strategies and four benchmark datasets, measured by task accuracy. Case Study (▷ RQ4). To intuitively demonstrate the topology concealment of M IRAGE, Fig. 9 visualizes representative communication topologies generated by G-Designer, AGP, and ARG-Designer, together with the corresponding topologies inferred by CIA (Wu et al., 2026) before and after defense. Without protection, CIA recovers most genuine communication edges, producing inferred structures highly similar to the ground-truth topologies. In contrast, after applying M IRAGE, the inferred topologies substantially deviate from the ground truth across all three topology optimization methods, with many genuine edges concealed or replaced by phantom relations. These cases visually confirm that M IRAGE substantially hinders the adversary from recovering the genuine communication structure.

6

R ELATED W ORK

This section reviews three lines of research closely related to our work: ① LLM-based multi-agent system, ② adversarial attacks against MAS, and ③ privacy and security protection for MAS. LLM-based Multi-Agent Systems. LLM-based multi-agent systems (MAS) coordinate multiple specialized agents through structured communication to solve complex tasks, demonstrating strong capabilities in software engineering (He et al., 2025a; Islam et al., 2024; Oueslati et al., 2026), scientific discovery (Ghareeb et al., 2026; Ghafarollahi & Buehler, 2025), and mathematical reasoning (Lei et al., 2024; Zhang & Xiong, 2025). Early systems typically adopt handcrafted communication structures, such as the sequential workflow in ChatDev (Qian et al., 2024) and role-based collaboration in CAMEL (Li et al., 2023) and MetaGPT (Hong et al., 2024). Recent studies further explore automated topology optimization to construct task-adaptive communication structures. Representative methods include G-Designer (Zhang et al., 2025), AGP (Li et al., 2025), and ARG-Designer (Li et al., 2026), which optimize agent connectivity through graph-based generation or pruning. As these optimized topologies increasingly encode substantial computational investment and system design knowledge, protecting them from unauthorized inference becomes an important yet underexplored problem. Adversarial Attacks against MAS. The growing adoption of LLM-based MAS has raised increasing concerns about their vulnerability to adversarial attacks (Yu et al., 2025). Existing studies primarily target agent behaviors and communication content, including prompt-based attacks (Lee et al., 2025; Shahroz et al., 2025; Arif et al., 2026), communication attacks (He et al., 2025b; Yan et al., 2026), and task disruption (Amayuelas et al., 2024), which inject malicious instructions or manipulate inter-agent interactions to compromise system behavior. Beyond content-level threats, CIA (Wu et al., 2026) reveals a distinct risk to topology confidentiality by reconstructing MAS communication topologies from semantic dependencies under black-box access. Despite the resulting security and intellectual property risks, defenses against topology inference remain largely unexplored. This work fills this gap by introducing M IRAGE to protect MAS communication topologies against black-box inference. 8

Full w/o PEM w/o GEO

0.2 0.0

AUC

ACC

Metrics

F1

(a) Ablation Study

AUC Utility 0.2

0.4

0.6 0

0.8

1.0

(b) Parameter ρ0

0.9 0.8 0.7 0.6 0.5 0.4

Performance

0.4

0.9 0.8 0.7 0.6 0.5 0.4

Performance

0.6

Performance

Performance

P REPRINT.

AUC Utility 1

3

5

M

7

(c) Parameter M

9

0.9 0.8 0.7 0.6 0.5 0.4

AUC Utility 0.1

0.3

0.5

0.7

0.9

(d) Parameter λ

G-Designer

Figure 8: Ablation and parameter analyses of M IRAGE under different experimental settings. (a) Effects of removing key defense components. (b)–(d) Effects of the structural deviation threshold ρ0 , number of paraphrase candidates M , and dependency suppression weight λ, respectively.

(b) No Defense

(c) Ours

(a) Ground-truth

(b) No Defense

(c) Ours

(a) Ground-truth

(b) No Defense

(c) Ours

ARG-Designer

AGP

(a) Ground-truth

Figure 9: Visualization of communication topologies under G-Designer, AGP, and ARG-Designer, comparing the ground-truth topology (Ground-truth) with those inferred by CIA before defense (No Defense) and with M IRAGE (Ours) across diverse topology structures. Privacy and Security Protection for MAS. Existing defenses for MAS mainly focus on contentlevel security (Zhou et al., 2025; Zhang et al., 2024; Raza et al., 2026; Miao et al., 2025; Liu et al., 2024; Zhan et al., 2025). Representative approaches protect inter-agent collaboration through attack detection, trust management, or communication safeguards, such as BlindGuard (Miao et al., 2025), TRiSM (Raza et al., 2026), and GUARDIAN (Zhou et al., 2025). However, these defenses protect message content or system behavior rather than the communication topology itself. Consequently, the confidentiality of MAS topologies remains largely overlooked. M IRAGE addresses this gap by concealing the genuine topology from black-box inference while preserving it for task execution.

7

C ONCLUSION

This paper investigates the emerging threat of communication topology inference in LLM-based multiagent systems. To mitigate this threat, we propose M IRAGE, a topology-concealment framework that decouples genuine task execution from adversary-facing exposure. M IRAGE consists of three stages: ① phantom topology synthesis, ② semantic edge realization, and ③ protected MAS execution. Specifically, it constructs structurally feasible phantom topologies and reshapes observable semantic dependencies through phantom edge materialization and genuine edge obfuscation, while preserving the genuine topology for task execution. Extensive experiments across multiple topology optimization methods and benchmark datasets demonstrate that M IRAGE substantially reduces topology inference effectiveness while largely preserving task utility. Overall, M IRAGE provides a practical and effective approach to protecting confidential MAS topologies against black-box inference attacks while largely preserving task utility. Further discussion of limitations and future directions is provided in App. E. 9

P REPRINT.

R EFERENCES Alfonso Amayuelas, Xianjun Yang, Antonis Antoniades, Wenyue Hua, Liangming Pan, and William Yang Wang. Multiagent collaboration attack: Investigating adversarial attacks in large language model collaborations via debate. In Findings of the Association for Computational Linguistics: EMNLP 2024 (EMNLP Findings), pp. 6929–6948, 2024. Nokimul Hasan Arif, Qian Lou, and Mengxin Zheng. Conjunctive prompt attacks in multi-agent llm systems. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 34175–34191, 2026. Jincheng Bai, Zhenyu Zhang, Jennifer Zhang, and Jason Zhu. Insight agents: An llm-based multiagent system for data insights. In Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval (SIGIR), pp. 4335–4339, 2025. Elron Bandel, Ranit Aharonov, Michal Shmueli-Scheuer, Ilya Shnayderman, Noam Slonim, and Liat Ein Dor. Quality controlled paraphrase generation. In Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 596–609, 2022. Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde De Oliveira Pinto, Jared Kaplan, Harri Edwards, Yuri Burda, Nicholas Joseph, Greg Brockman, et al. Evaluating large language models trained on code. arXiv preprint arXiv:2107.03374, 2021. Karl Cobbe, Vineet Kosaraju, Mohammad Bavarian, Mark Chen, Heewoo Jun, Lukasz Kaiser, Matthias Plappert, Jerry Tworek, Jacob Hilton, Reiichiro Nakano, et al. Training verifiers to solve math word problems. arXiv preprint arXiv:2110.14168, 2021. Huaming Du, Tao Hu, Yijie Huang, Yu Zhao, Guisong Liu, Tao Gu, Gang Kou, and Carl Yang. Traceable latent variable discovery based on multi-agent collaboration. In Proceedings of the ACM Web Conference 2026 (WWW), pp. 3732–3743, 2026. Alireza Ghafarollahi and Markus J Buehler. Sciagents: automating scientific discovery through bioinspired multi-agent intelligent graph reasoning. Advanced Materials, 37(22):2413523, 2025. Ali Essam Ghareeb, Benjamin Chang, Ludovico Mitchener, Angela Yiu, Caralyn J Szostkiewicz, Dmytro Shved, Gavin J Gyimesi, Jon M Laurent, Samantha M Wright, Muhammed T Razzak, et al. A multi-agent system for automating scientific discovery. Nature, 655:497–505, 2026. Xiangming Gu, Xiaosen Zheng, Tianyu Pang, Chao Du, Qian Liu, Ye Wang, Jing Jiang, and Min Lin. Agent smith: A single image can jailbreak one million multimodal LLM agents exponentially fast. In Forty-first International Conference on Machine Learning (ICML), pp. 16647–16672, 2024. Junda He, Christoph Treude, and David Lo. Llm-based multi-agent systems for software engineering: Literature review, vision, and the road ahead. ACM Transactions on Software Engineering and Methodology (TOSEM), 34(5):1–30, 2025a. Pengfei He, Yuping Lin, Shen Dong, Han Xu, Yue Xing, and Hui Liu. Red-teaming llm multi-agent systems via communication attacks. In Findings of the Association for Computational Linguistics: ACL 2025 (ACL Findings), pp. 6726–6747, 2025b. Dan Hendrycks, Collin Burns, Steven Basart, Andy Zou, Mantas Mazeika, Dawn Song, and Jacob Steinhardt. Measuring massive multitask language understanding. In 9th International Conference on Learning Representations (ICLR), 2021. Sirui Hong, Mingchen Zhuge, Jonathan Chen, Xiawu Zheng, Yuheng Cheng, Jinlin Wang, Ceyao Zhang, Steven Yau, Zijuan Lin, Liyang Zhou, et al. Metagpt: Meta programming for a multi-agent collaborative framework. In International Conference on Learning Representations (ICLR), 2024. Md Ashraful Islam, Mohammed Eunus Ali, and Md Rizwan Parvez. Mapcoder: Multi-agent code generation for competitive problem solving. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 4912–4944, 2024. 10

P REPRINT.

Tianjie Ju, Yiting Wang, Yi Hua, Xinbei Ma, Pengzhou Cheng, Haodong Zhao, Yulong Wang, Lifeng Liu, Jian Xie, Zhuosheng Zhang, et al. Flooding spread of manipulated knowledge in llm-based multi-agent communities. Science China Information Sciences (SCIS), 69(7):172103, 2026. Ishan Kavathekar, Hemang Jain, Ameya Rathod, Ponnurangam Kumaraguru, and Tanuja Ganu. Tamas: Benchmarking adversarial risks in multi-agent llm systems. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 31238–31268, 2026. Donghyun Lee, Mo Tiwari, and Brando Miranda. Prompt infection: Llm-to-llm prompt injection within multi-agent systems. In Computer Security. ESORICS 2025 International Workshops, pp. 511–520, 2025. Bin Lei, Yi Zhang, Shan Zuo, Ali Payani, and Caiwen Ding. Macm: Utilizing a multi-agent system for condition mining in solving complex mathematical problems. Advances in Neural Information Processing Systems (NeurIPS), 37:53418–53437, 2024. Boyi Li, Zhonghan Zhao, Der-Horng Lee, and Gaoang Wang. Adaptive graph pruning for multi-agent communication. In 28th European Conference on Artificial Intelligence (ECAI), pp. 4305–4312, 2025. Guohao Li, Hasan Hammoud, Hani Itani, Dmitrii Khizbullin, and Bernard Ghanem. Camel: Communicative agents for" mind" exploration of large language model society. Advances in Neural Information Processing Systems (NeurIPS), 36:51991–52008, 2023. Shiyuan Li, Yixin Liu, Qingsong Wen, Chengqi Zhang, and Shirui Pan. Assemble your crew: Automatic multi-agent communication topology design via autoregressive graph generation. In Proceedings of the AAAI Conference on Artificial Intelligence (AAAI), pp. 23142–23150, 2026. Xinyi Li, Sai Wang, Siqi Zeng, Yu Wu, and Yi Yang. A survey on llm-based multi-agent systems: workflow, infrastructure, and challenges. Vicinagearth, 1(1):9, 2024. Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. Formalizing and benchmarking prompt injection attacks and defenses. In 33rd USENIX Security Symposium (USENIX Security), pp. 1831–1847, 2024. Tianyi Ma, Yiyue Qian, Zheyuan Zhang, Zehong Wang, Xiaoye Qian, Feifan Bai, Yifan Ding, Xuwei Luo, Shinan Zhang, Keerthiram Murugesan, et al. Autodata: A multi-agent system for open web data collection. Advances in Neural Information Processing Systems (NeurIPS), 38: 173416–173448, 2025. Rui Miao, Yixin Liu, Yili Wang, Xu Shen, Yue Tan, Yiwei Dai, Shirui Pan, and Xin Wang. Blindguard: Safeguarding llm-based multi-agent systems under unknown attacks. arXiv preprint arXiv:2508.08127, 2025. Humza Naveed, Asad Ullah Khan, Shi Qiu, Muhammad Saqib, Saeed Anwar, Muhammad Usman, Naveed Akhtar, Nick Barnes, and Ajmal Mian. A comprehensive overview of large language models. ACM Transactions on Intelligent Systems and Technology (TIST), 16(5):1–72, 2025. Khouloud Oueslati, Maxime Lamothe, and Foutse Khomh. Refagent: A multi-agent llm-based framework for automatic software refactoring. In Proceedings of the 2026 IEEE/ACM 48th International Conference on Software Engineering (ICSE), pp. 92–104, 2026. Arkil Patel, Satwik Bhattamishra, and Navin Goyal. Are nlp models really able to solve simple math word problems? In Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (NAACL), pp. 2080–2094, 2021. Chen Qian, Wei Liu, Hongzhang Liu, Nuo Chen, Yufan Dang, Jiahao Li, Cheng Yang, Weize Chen, Yusheng Su, Xin Cong, et al. Chatdev: Communicative agents for software development. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 15174–15186, 2024. 11

P REPRINT.

Shaina Raza, Ranjan Sapkota, Manoj Karkee, and Christos Emmanouilidis. Trism for agentic ai: A review of trust, risk, and security management in llm-based agentic multi-agent systems. AI Open, pp. 71–95, 2026. Rana Shahroz, Zhen Tan, Sukwon Yun, Charles Fleming, and Tianlong Chen. Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks. In Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 9661–9674, 2025. Pengyang Shao, Lei Chen, Fei Liu, Yonghui Yang, Xun Yang, and Meng Wang. Multi-agent debate based concept augmentation for enhanced cognitive diagnosis. In Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 1 (SIGKDD), pp. 1287–1296, 2026. Noah Shinn, Federico Cassano, Ashwin Gopinath, Karthik Narasimhan, and Shunyu Yao. Reflexion: Language agents with verbal reinforcement learning. Advances in Neural Information Processing Systems (NeurIPS), 36:8634–8652, 2023. Latanya Sweeney. k-anonymity: A model for protecting privacy. International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems (IJUFKS), 10(05):557–570, 2002. Yongxuan Wu, Xixun Lin, He Zhang, Nan Sun, Kun Wang, Chuan Zhou, Shirui Pan, and Yanan Cao. CIA: Inferring the communication topology from llm-based multi-agent systems. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), 2026. Yunhao Xiao, Ying Wang, Michael Bewong, Selasi Kwashie, Xiaoxia Li, and Zaiwen Feng. A unified and time-efficient multi-agent framework for data discovery. In Proceedings of the ACM Web Conference 2026 (WWW), pp. 4268–4277, 2026. Bingyu Yan, Xiaoming Zhang, Ziyi Zhou, Chaozhuo Li, Ruilin Zeng, Yirui Qi, Tianbo Wang, and Litian Zhang. Attack the messages, not the agents: A multi-round adaptive stealthy tampering framework for llm-mas. In Proceedings of the AAAI Conference on Artificial Intelligence (AAAI), pp. 29784–29792, 2026. John Yang, Carlos E Jimenez, Alexander Wettig, Kilian Lieret, Shunyu Yao, Karthik Narasimhan, and Ofir Press. Swe-agent: Agent-computer interfaces enable automated software engineering. Advances in Neural Information Processing Systems (NeurIPS), 37:50528–50652, 2024. Miao Yu, Fanci Meng, Xinyun Zhou, Shilong Wang, Junyuan Mao, Linsey Pan, Tianlong Chen, Kun Wang, Xinfeng Li, Yongfeng Zhang, et al. A survey on trustworthy llm agents: Threats and countermeasures. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2 (SIGKDD), pp. 6216–6226, 2025. Qiusi Zhan, Richard Fang, Henil Shalin Panchal, and Daniel Kang. Adaptive attacks break defenses against indirect prompt injection attacks on llm agents. In Findings of the Association for Computational Linguistics: NAACL 2025 (NAACL Findings), pp. 7116–7132, 2025. Guibin Zhang, Yanwei Yue, Xiangguo Sun, Guancheng Wan, Miao Yu, Junfeng Fang, Kun Wang, Tianlong Chen, and Dawei Cheng. G-designer: Architecting multi-agent communication topologies via graph neural networks. In International Conference on Machine Learning (ICML), pp. 76678– 76692, 2025. Shaowei Zhang and Deyi Xiong. Debate4math: Multi-agent debate for fine-grained reasoning in math. In Findings of the Association for Computational Linguistics: ACL 2025 (ACL Findings), pp. 16810–16824, 2025. Zaibin Zhang, Yongting Zhang, Lijun Li, Hongzhi Gao, Lijun Wang, Huchuan Lu, Feng Zhao, Yu Qiao, and Jing Shao. Psysafe: A comprehensive framework for psychological-based attack, defense, and evaluation of multi-agent system safety. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (ACL), pp. 15202–15231, 2024. 12

P REPRINT.

Andrew Zhao, Daniel Huang, Quentin Xu, Matthieu Lin, Yong-Jin Liu, and Gao Huang. Expel: Llm agents are experiential learners. In Proceedings of the AAAI Conference on Artificial Intelligence (AAAI), pp. 19632–19642, 2024. Jialong Zhou, Lichao Wang, and Xiao Yang. Guardian: Safeguarding llm multi-agent collaborations with temporal graph modeling. Advances in Neural Information Processing Systems (NeurIPS), 38:7973–8001, 2025.

13

Record · ID 1122194 · SHA-256 13d5d9c3c74150c2
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.