ConceptioArchivearXiv CS
arXiv CSopen access

ACF: A Collaborative Framework for Agent Covert Communication under Cognitive Asymmetry

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

IEEE SIGNAL PROCESSING LETTERS, VOL. XX, NO. XX, XXXX 2026

1

ACF: A Collaborative Framework for Agent Covert Communication under Cognitive Asymmetry

arXiv:2604.08276v1 [cs.AI] 9 Apr 2026

Wansheng Wu, Kaibo Huang, Yukun Wei, Zhongliang Yang, and Linna Zhou

Abstract—As generative artificial intelligence evolves, autonomous agent networks present a powerful paradigm for interactive covert communication. However, because agents dynamically update internal memories via environmental interactions, existing methods face a critical structural vulnerability: cognitive asymmetry. Conventional approaches demand strict cognitive symmetry, requiring identical sequence prefixes between the encoder and decoder. In dynamic deployments, inevitable prefix discrepancies destroy synchronization, inducing severe channel degradation. To address this core challenge of cognitive asymmetry, we propose the Asymmetric Collaborative Framework (ACF), which structurally decouples covert communication from semantic reasoning via orthogonal statistical and cognitive layers. By deploying a prefix-independent decoding paradigm governed by a shared steganographic configuration, ACF eliminates the reliance on cognitive symmetry. Evaluations on realistic memoryaugmented workflows demonstrate that under severe cognitive asymmetry, symmetric baselines suffer severe channel degradation, whereas ACF uniquely excels across both semantic fidelity and covert communication. It maintains computational indistinguishability, enabling reliable secret extraction with provable error bounds, and providing robust Effective Information Capacity guarantees for modern agent networks. Index Terms—Generative steganography, asymmetric steganography, LLM agents, cognitive asymmetry, structural decoupling.

I. I NTRODUCTION OVERT communication is a pivotal technology for securing private data transmission through public Internet infrastructures. Its core technology, steganography, investigates the secure and efficient embedding of secret information into common carrier media (e.g. images [1], audio [2], video [3], and text [4]), thus ensuring security by concealing the very existence of the message. The rapid advancement of generative models has catalyzed a paradigm shift from traditional modification-based methods to generation-based methods [5]–[7]. Eliminating original carrier constraints, generative steganography provides expansive embedding freedom, achieving markedly higher covert capacities and broader applicability. In particular, the widespread proliferation of generative models—exemplified by Large Language Models (LLMs)—has saturated the Internet with diverse synthetic multimedia content. This abundance of data provides an ideal cover for generative steganography, which has fueled the rapid advancement of these techniques over the past two years.

C

The authors are with the School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China (e-mail: [email protected]; [email protected]; [email protected]; [email protected]; [email protected]).

Recently, the evolution of LLM-centric autonomous agents has pushed generative steganography to unprecedented heights. Unlike traditional passive models, agents possess perception, reasoning, and execution capabilities to independently perform complex tasks [8] within dynamic environments [9]– [11]. A primary agent can autonomously discover, negotiate, and coordinate specialized agent networks [12], [13] to execute domain-specific tasks via collective intelligence [14]. The evolution of these technologies is profoundly transforming the landscape of covert communication. Recently, researchers have introduced agent-oriented covert communication protocols [15], which aim to automate the entire communication workflow through autonomous content generation and intelligent agent behavior [16], [17]. However, existing agent-collaborative schemes face an insurmountable obstacle in realistic deployments [18], formally defined as the cognitive asymmetry challenge. Agents continuously update internal states and memories via environmental interactions (e.g., Retrieval-Augmented Generation [19]), inevitably causing encoder-decoder prefix discrepancies [20], [21]. Enforcing strict synchronization freezes the agent, paralyzing its autonomous capabilities [22], [23]. Conversely, natural evolution shatters the synchronized probability partitions demanded by symmetric steganography (e.g., DISCOP [24]), rendering exact extraction mathematically impossible [25]. While Bai et al. [26] circumvent prefix sharing via statistical hypothesis testing, introducing their static calibration into dynamic scenarios inevitably destroys adaptive reasoning. To overcome this, we propose the Asymmetric Collaborative Framework (ACF). ACF structurally decouples the covert channel from the agent’s dynamic reasoning via orthogonal statistical and cognitive layers, preserving provable security and semantic fidelity without prefix synchronization. Our main contributions are: Cognitive Asymmetry Formulation: We formalize cognitive asymmetry (ztenc ̸= ztdec ) as a structural constraint, highlighting the conflict between autonomous task fidelity and reliable secret recovery. • Asymmetric Collaborative Framework (ACF): We introduce ACF to structurally decouple statistical communication from cognitive reasoning, enabling synchronization-free extraction under dynamic state updates. • Robust Evaluation: Evaluations show ACF sustains effective information capacity under realistic asymmetric conditions, whereas symmetric baselines suffer severe channel degradation. •

IEEE SIGNAL PROCESSING LETTERS, VOL. XX, NO. XX, XXXX 2026

2

Cognitive Reasoning Layer

Encoder Agent Cognitive State 𝒑𝒓𝒊𝒗,𝒆𝒏𝒄 𝒑𝒖𝒃,𝒆𝒏𝒄 𝒛𝒆𝒏𝒄 ← 𝑲𝒕 ⊕ 𝑲𝒕 𝒕

RAG

MCP

...

...

Semantic Token Distribution 𝑷𝑴 𝒙 𝒛𝒆𝒏𝒄 ,𝒙 ∈ 𝑽 𝒕

Cognitive Asymmetry 𝒛𝒆𝒏𝒄 ≠ 𝒛𝒅𝒆𝒄 𝒕 𝒕

Decoder Agent Cognitive State 𝒑𝒖𝒃,𝒅𝒆𝒄 𝒑𝒓𝒊𝒗,𝒅𝒆𝒄 𝒛𝒅𝒆𝒄 ← 𝑲𝒕 ⊕ 𝑲𝒕 𝒕

Semantic Token Distribution 𝑷𝑴 𝒙 𝒛𝒅𝒆𝒄 ,𝒙 ∈ 𝑽 𝒕 Structural Decoupling

Statistical Communication Layer Asymmetric Stego Engine

Token 𝒙𝒕

Public Channel

𝒙𝒕

−𝟏 𝒙𝒕 = CDF𝒔,𝚷 𝒓, 𝑷𝑴 ⋅ 𝒛𝒆𝒏𝒄 𝒕

𝚷 𝓥, 𝚯 ⊥ 𝒛𝒕 Model-Free Extraction

𝒔ො ← 𝚲 𝑿𝟏:𝑻 ≥ 𝝉 𝑷𝒆 Shared Information

𝚯 𝒔𝒌, 𝒇, 𝑷𝒆 , 𝑹 Fig. 1. The Asymmetric Collaborative Framework (ACF). To overcome cognitive asymmetry (ztenc ̸= ztdec ), ACF structurally decouples statistical communication from dynamic cognitive reasoning. Governed by a shared configuration Θ, ACF executes dynamic cognitive sampling and enables prefixindependent, model-free, and robust secret extraction (Π ⊥ zt ).

The source code and datasets are publicly available at https: //github.com/Dwinovo/ACF-Stego. II. P ROBLEM F ORMULATION We formalize token generation to elucidate the inevitability of cognitive asymmetry in agent-driven steganography. a) Symmetric Steganography: At step t, a generative model M outputs token xt from vocabulary V conditioned on prefix zt . Symmetric steganography algorithms (e.g., METEOR [27], DISCOP [24], and Liao et al. [28]) embed secrets by mapping them to probability partitions of PM (· | zt ). Here ztenc and ztdec denote the context prefixes at the encoder and decoder side, respectively. Decoding demands strict cognitive symmetry: PM (· | ztenc ) = PM (· | ztdec ) ⇐⇒ ztenc = ztdec .

(1)

Marginal prefix discrepancy breaks this exact distribution matching, causing channel failure. b) Cognitive Asymmetry in Agents: Autonomous agents maintain a dynamic cognitive state Kt = Ktpub ∥ Ktpriv (where ∥ denotes context concatenation), comprising observable public history (Ktpub ) and localized private memory (Ktpriv ) [20], [21], [29], [30]. The prefix instantiates this holistic state (zt ← Kt ). As the encoder expands its state via environmental interactions, the decoder remains asynchronous. We formalize this inescapable discrepancy as cognitive asymmetry: ztenc = Ktpub,enc ∥ Ktpriv,enc ̸= Ktpub,dec ∥ Ktpriv,dec = ztdec .

(2)

This structural inequality stems from independent reasoning traces (private-state asymmetry) [20], [30], [31] and network/context limits (public-state asymmetry) [15], [32]. Thus, cognitive asymmetry violates the symmetric assumption (PM (· | ztenc ) ̸= PM (· | ztdec )), inducing severe bit errors and reducing mutual information, as empirically validated later in Table II.

III. A SYMMETRIC C OLLABORATIVE F RAMEWORK To resolve this conflict, we propose the Asymmetric Collaborative Framework (ACF) (Fig. 1), which decouples generation into two orthogonal modules: a statistical communication layer for steganographically controlled secret embedding, and a cognitive reasoning layer for dynamic semantic generation. a) Prefix-Independent Vocabulary Partitioning: Building upon Bai et al. [26], ACF integrates statistical hypothesis testing as a foundational decoding layer while restructuring the encoding paradigm to preserve dynamic reasoning. Given vocabulary V and a pre-shared configuration Θ = (sk, f, Pe , R) containing secret key sk, sampling function f , error bound Pe (controlled by security parameter k, e.g., Pe ∝ 2−k ), and mapping rule R, the framework constructs a deterministic partition mapping: Π : V × Θ → {0, 1},

(3)

dividing V into pseudo-random subsets V (s) = {x ∈ V | Π(x, Θ) = s} for s ∈ {0, 1}. This static partitioning is inherently prefix-independent. b) Asymmetric Encoding via Distribution Permutation: At step t, the encoder first computes the native distribution PM (· | ztenc ) over V, representing the semantic output under its dynamic cognition. To embed secret s, rather than truncating PM , the statistical layer constructs a Cumulative Distribution Function (CDF) permutation parameterized by s and Π. Drawing r ← Gsk from a shared pseudorandom generator keyed by sk, the zero-distortion output is: enc xt = CDF−1 s,Π (r, PM (· | zt )) ,

(4)

(s) where CDF−1 leads the cumulative s,Π reorders tokens so V mass; crucially, the marginal probability of any token xt remains strictly identical to that under the original distribution PM (· | ztenc ). Unlike Bai et al. [26], whose static encoding freezes the global context and truncates dynamic cognitive evolution, ACF isolates the steganographic permutation from

IEEE SIGNAL PROCESSING LETTERS, VOL. XX, NO. XX, XXXX 2026

3

TABLE I P ERFORMANCE E VALUATION ACROSS S TATIC AND DYNAMIC AGENT E NVIRONMENTS . ∼: SUSTAINED ROBUSTNESS VIA STRUCTURAL DECOUPLING ; † : CHANNEL DEGRADATION UNDER COGNITIVE ASYMMETRY. Cognitive Reasoning Layer

Method

Score (↑)

F1 (%) (↑)

Statistical Communication Layer Entropy (bits/token)

BER (%) (↓)

EIC (bits/103 tokens) (↑)

Detection Acc. (%) (↓)

Static Environment (Ideal Symmetric Prefix) Normal (No Stego) DISCOP METEOR ACF (k = 8) ACF (k = 12) ACF (k = 16)

0.31 ± 0.58 0.28 ± 0.57 0.31 ± 0.58 0.33 ± 0.58 0.31 ± 0.56 0.29 ± 0.55

3.63 ± 5.39 3.25 ± 4.82 3.25 ± 4.72 3.55 ± 5.12 3.36 ± 4.90 3.31 ± 4.73

Normal+RET DISCOP+RET METEOR+RET ACF+RET (k = 8) ACF+RET (k = 12) ACF+RET (k = 16)

0.89 ± 0.91 0.93 ± 0.89 0.97 ± 0.89 0.94 ± 0.91 0.93 ± 0.88 0.93 ± 0.90

7.50 ± 8.55 7.38 ± 8.30 7.43 ± 8.63 7.36 ± 8.03 7.27 ± 7.98 7.28 ± 8.11

0.65 ± 0.16 0.68 ± 0.17 0.67 ± 0.17 0.68 ± 0.19 0.68 ± 0.17 0.68 ± 0.19

— 0.00 ± 0.00 0.00 ± 0.00 4.04 ± 10.56 0.14 ± 1.52 0.00 ± 0.00

— 515.7546 352.9054 3.6450 2.0077 1.0368

— 54.17 55.56 55.56 52.78 54.17

— 0.0063† 0.0046† 2.6465 1.1846∼ 0.4282∼

— 51.39 59.72 54.17 58.33 48.61

Dynamic Agent Environment (Cognitive Asymmetry)

the cognitive intention PM , permitting natural agent reasoning while preserving authentic model statistics. c) Model-Free Prefix-Agnostic Decoding: Relying exclusively on Θ, the decoder executes lightweight statistical extraction without a model or prefix tracking. It replays Gsk to obtain rt at each step, computing a partition-based statistic over the received sequence X = (x1 , . . . , xT ): Λ(X) =

T X   (1−Π(xt , Θ))·f (rt )+Π(xt , Θ)·f (1−rt ) , (5) t=1

where rt ← Gsk are drawn sequentially from the shared pseudorandom generator. Since both parties are aware of the covert channel, cover-text detection is resolved at the session level, reducing each per-sequence decision to a binary test against threshold τ (Pe , T ) derived from Hoeffding’s inequality: ( 1, if Λ(X) ≥ τ (Pe , T ) ŝ = (6) 0, otherwise. where ŝ denotes the recovered secret bit. This prefix-agnostic paradigm guarantees robust recovery with provable error bounds under cognitive asymmetry, circumventing the catastrophic channel degradation suffered by symmetric baselines. IV. E XPERIMENTS a) Experimental Setup: We evaluate steganography under cognitive asymmetry using Qwen2.5 7B Instruct [33] on the LongMemEval s dataset [22], [23]. Initially, both agents retain only the 5 most recent dialogue turns. The encoder generates stego-text based on its local context and the current query, while the decoder extracts secrets relying exclusively on its independent context and the received text. To explicitly model cognitive asymmetry (ztenc ̸= ztdec ), we establish three progressive configurations: 1) Isolated discrepancy, where the encoder appends a private summary or the decoder truncates 2 historical turns; 2) Progressive asymmetry, incrementally truncating 0–4 decoder turns to test robustness; and 3) Memory-augmented (+RET), enabling the encoder to

— 50.25 ± 9.62† 49.75 ± 12.07† 1.49 ± 6.03 0.00 ± 0.00∼ 0.00 ± 0.00∼

70%

DISCOP METEOR ACF (k=8) ACF (k=16)

60% 50%

BER (%)

0.47 ± 0.18 0.48 ± 0.20 0.48 ± 0.19 0.48 ± 0.19 0.49 ± 0.20 0.49 ± 0.19

40% 30% 20% 10% 0%

0

1 2 3 Context Truncation ( Sessions)

4

Fig. 2. Impact of controlled cognitive asymmetry on Bit Error Rate (BER). Asymmetry is explicitly governed by truncating varying numbers of historical sessions (∆) from the decoder’s context.

dynamically retrieve from a 115k-token private memory pool to construct an extreme cognitive gap. Against DISCOP [24] and METEOR [27] baselines, we rigorously evaluate ACF under varying security parameters k, which mathematically dictates the decoding error bound Pe to control the capacityreliability trade-off. b) Evaluation Metrics: We evaluate the framework across semantic utility and statistical communication. Semantic utility relies on Gemini 2.0 Flash [34] as an LLM-as-aJudge (using a discrete 0–2 factual accuracy rubric) and a Question Answering token-level Task F1 score via normalized multiset intersection. Statistical communication is assessed via Bit Error Rate (BER) for extraction accuracy, generation entropy for distribution preservation, and Detection Accuracy of a fine-tuned BERT classifier for statistical indistinguishability. Crucially, because cognitive asymmetry often degrades symmetric decoding into random guessing, we calculate the actual usable throughput using our proposed Effective Information Capacity (EIC), rigorously grounded in the channel coding

Channel Reliability (1 BER) Semantic Utility (Score)

1.0

Normal Score Normal+RET Score

4

1.0 Semantic Utility (Score)

Channel Reliability (1 BER)

IEEE SIGNAL PROCESSING LETTERS, VOL. XX, NO. XX, XXXX 2026

0.8

0.8

0.6

0.6

0.4

0.4

0.2

0.2

0.0 DISCOP

DISCOP RET

METEOR

METEOR RET

ACF (k=16) ACF (k=16) RET

0.0

Fig. 3. Trade-off analysis between semantic utility and channel reliability under retrieval-induced cognitive asymmetry (+RET). TABLE II E XTRACTION R ELIABILITY U NDER I SOLATED C OGNITIVE D ISCREPANCIES . Method

Ideal BER (%)

Truncation BER (%)

Summary BER (%)

DISCOP METEOR

0.00 ± 0.00 0.00 ± 0.00

30.66 ± 26.64 25.79 ± 22.84

53.88 ± 5.58 49.30 ± 6.50

ACF (k = 8) ACF (k = 12) ACF (k = 16)

2.47 ± 8.27 0.00 ± 0.00 0.00 ± 0.00

2.47 ± 8.27 0.00 ± 0.00 0.00 ± 0.00

1.67 ± 6.71 0.00 ± 0.00 0.00 ± 0.00

theorem of Shannon [35]:  EIC =

 Total Embedded Bits × 103 · (1 − H2 (BER)), (7) Total Tokens

where H2 (p) is the binary entropy function and the capacity factor (1 − H2 (BER)) is derived under a binary symmetric channel (BSC) approximation. Since autonomous agents lack instantaneous Channel State Information (CSI) to dynamically adjust session encoding rates, the network constitutes an aggregated macroscopic channel. To reflect this architectural constraint, EIC calculates holistic expectations of nominal capacity and BER across all instances. This paradigm rigorously penalizes severe channel failures while isolating true communication reliability from the natural length variance of individual semantic responses. c) Impact of Controlled Asymmetry: Table II evaluates isolated cognitive discrepancies via decoder truncation or appended encoder summaries. Under both conditions, baselines suffer devastating extraction failures (BER up to 53.88%), whereas ACF (k = 16) maintains a 0.00% BER. Fig. 2 examines progressive asymmetry by incrementally truncating decoder sessions (∆). For ∆ ≥ 3, baseline BER rapidly degrades to random guessing (≈ 50%), while ACF preserves strict channel stability. Even at maximum severity, ACF (k = 8) anchors at 2.47% ± 8.27%, and ACF (k = 16) secures 0.00% BER. This BER invariance demonstrates that ACF achieves robust prefix-independent decoding, successfully decoupling secret extraction from dynamic cognitive states. d) Performance in Realistic Agentic Workflows: Table I and Fig. 3 evaluate realistic retrieval-induced asymmetry (+RET). While dynamic retrieval boosts baseline semantic scores (0.31 to 0.89), it collapses cognitive symmetry, driving DISCOP and METEOR BERs to ≈ 50% and yielding nearzero EICs (0.0063 and 0.0046 bits/103 tokens) that render

nominal bandwidth meaningless. By structurally decoupling cryptography from semantic generation, ACF overcomes this bottleneck. ACF+RET (k = 12) fully exploits dynamic cognition to achieve a 0.93 semantic score, 0.00% BER, and a stable 1.1846 EIC. As Fig. 3 illustrates, whereas baselines suffer a zero-sum trade-off between semantic reasoning and covert communication, ACF uniquely excels across both. This structural decoupling substantially addresses the fundamental paradox between autonomous evolution and strict statistical synchronization. e) Statistical Security Assessment: To validate computational indistinguishability, we adopt recent event-level steganalysis methodologies [15], training a dedicated classifier [36] via strict 5-fold cross-validation. The test accuracy separating Normal+RET from ACF+RET (k = 16) is 48.61%, functionally equivalent to random guessing. Furthermore, the generation entropy of ACF+RET (k = 16) (0.49 ± 0.19) closely aligns with the unmodified Normal+RET baseline (0.47 ± 0.18), suggesting the language distribution is wellpreserved. This multi-dimensional validation confirms that restricting sampling to the statistically valid subset V (s) ensures strict practical undetectability, closely mirroring the theoretical promises of zero-distortion steganography [24], [26], [27]. f) Capacity Trade-off and Applicable Scenarios: While ACF’s per-token capacity under ideal conditions is lower than symmetric baselines, this comparison is misleading in autonomous agent networks: symmetric methods suffer complete EIC collapse under cognitive asymmetry (0.0063 and 0.0046 bits/103 tokens), rendering them effectively inoperable in this scenario. ACF, by contrast, sustains a meaningful EIC of 1.1846 bits/103 tokens under the same conditions, making it the only viable option for covert communication in dynamic agent environments. For applications such as trigger signaling, command-and-control (C2) bit transmission, and identity authentication, where a small number of bits must be reliably delivered across cognitively asymmetric channels, ACF provides a decisive practical advantage that symmetric methods fundamentally cannot offer. In such settings, provable extraction correctness is the decisive metric, not raw embedding rate. V. C ONCLUSION In autonomous agent networks, cognitive asymmetry critically disrupts the strict prefix synchronization demanded by generative steganography. We propose the Asymmetric Collaborative Framework (ACF) to resolve this paradox. ACF structurally decouples statistical communication from dynamic reasoning via a shared steganographic configuration, achieving robust prefix-independent decoding. Evaluations on memoryaugmented workflows (up to 115k private tokens) show that while symmetric baselines suffer devastating channel failures (≈ 50% BER), ACF (k ≥ 12) achieves 0.00% BER. Concurrently preserving semantic fidelity and computational indistinguishability, ACF guarantees robust Effective Information Capacity (EIC). By liberating agents from brittle synchronization, ACF establishes a pragmatic covert communication regime for artificial intelligence networks, with future work targeting theoretical capacity elevation.

IEEE SIGNAL PROCESSING LETTERS, VOL. XX, NO. XX, XXXX 2026

R EFERENCES [1] Z. Yang, K. Chen, K. Zeng et al., “Provably secure robust image steganography,” IEEE Transactions on Multimedia, vol. 26, pp. 5040– 5053, 2023. [2] W. Su, J. Ni, X. Hu et al., “Efficient audio steganography using generalized audio intrinsic energy with micro-amplitude modification suppression,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 6559–6572, 2024. [3] C. Mou, Y. Xu, J. Song et al., “Large-capacity and flexible video steganography via invertible neural network,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2023, pp. 22 606–22 615. [4] Z.-L. Yang, X.-Q. Guo, Z.-M. Chen et al., “Rnn-stega: Linguistic steganography based on recurrent neural networks,” IEEE Transactions on Information Forensics and Security, vol. 14, no. 5, pp. 1280–1295, 2018. [5] Z. Yang, L. Xiang, S. Zhang et al., “Linguistic generative steganography with enhanced cognitive-imperceptibility,” IEEE Signal Processing Letters, vol. 28, pp. 409–413, 2021. [6] Z.-L. Yang, X.-Q. Guo, Z.-M. Chen et al., “RNN-Stega: Linguistic steganography based on recurrent neural networks,” IEEE Transactions on Information Forensics and Security, vol. 14, no. 5, pp. 1280–1295, May 2019. [7] Z. M. Ziegler, Y. Deng, and A. M. Rush, “Neural linguistic steganography,” in Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). Hong Kong, China: Association for Computational Linguistics, 2019, pp. 1210–1215. [8] Y. Qin, S. Liang, Y. Ye et al., “Toolllm: Facilitating large language models to master 16000+ real-world apis,” arXiv (Cornell University), 2023. [9] J. S. Park, J. C. O’Brien, C. J. Cai et al., “Generative agents: Interactive simulacra of human behavior,” in Proceedings of the 36th Annual ACM Symposium on User Interface Software and Technology (UIST), 2023, pp. 1–22. [10] L. Wang, C. Ma, X. Feng et al., “A survey on large language model based autonomous agents,” Frontiers of Computer Science, 2024. [11] X. Liu, H. Yu, H. Zhang et al., “Agentbench: Evaluating llms as agents,” arXiv (Cornell University), 2023. [12] Y. Shen, K. Song, X. Tan et al., “Hugginggpt: Solving ai tasks with chatgpt and its friends in hugging face,” arXiv (Cornell University), 2023. [13] S. Hong, M. Zhuge, J. Chen et al., “Metagpt: Meta programming for a multi-agent collaborative framework,” arXiv (Cornell University), 2023. [14] Q. Chen, C. Xin, Y. Cheng et al., “Communicative agents for software development,” Proceedings of the 62nd annual meeting of the association for computational linguistics (ACL), 2024. [15] K. Huang, Y. Wei, W. Wu et al., “Whispering Agents: An event-driven covert communication protocol for the Internet of Agents,” Aug. 2025. [16] Y. Wang, R. Song, R. Zhang et al., “LLSM: Generative linguistic steganography with large language model,” arXiv preprint arXiv:2401.15656, 2024. [17] J. Wu, Z. Wu, Y. Xue et al., “Generative text steganography with large language model,” Proceedings of the 32nd ACM International Conference on Multimedia, 2024. [18] K. Greshake, S. Abdelnabi, S. Mishra et al., “Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS), 2023, pp. 79–93. [19] Y. Gao, Y. Xiong, X. Gao et al., “Retrieval-augmented generation for large language models: A survey,” arXiv preprint arXiv:2312.10997, 2024. [20] C. Packer, S. Wooders, K. Lin et al., “MemGPT: Towards LLMs as operating systems,” arXiv preprint arXiv:2310.08560, 2023. [21] W. Zhong, L. Guo, Q. Gao et al., “MemoryBank: Enhancing large language models with long-term memory,” arXiv preprint arXiv:2305.10250, 2023. [22] D. Wu, H. Wang, W. Yu et al., “LongMemEval: Benchmarking chat assistants on long-term interactive memory,” arXiv preprint, 2024. [23] H. Tan, Z. Zhang, C. Ma et al., “MemBench: Towards more comprehensive evaluation on the memory of LLM-based agents,” in Findings of the Association for Computational Linguistics: ACL 2025. Vienna, Austria: Association for Computational Linguistics, 2025, pp. 19 336–19 352. [24] J. Ding, K. Chen, Y. Wang et al., “Discop: Provably secure steganography in practice based on ”distribution copies”,” in 2023 IEEE Symposium

5

on Security and Privacy (SP). San Francisco, CA, USA: IEEE, May 2023, pp. 2238–2255. [25] Y. Qi, K. Chen, K. Zeng et al., “Provably secure disambiguating neural linguistic steganography,” IEEE Transactions on Dependable and Secure Computing, 2024. [26] M. Bai, J. Yang, K. Pang et al., “Provably robust and secure steganography in asymmetric resource scenario,” in 2025 IEEE Symposium on Security and Privacy (SP). San Francisco, CA, USA: IEEE, May 2025, pp. 1438–1456. [27] G. Kaptchuk, T. M. Jois, M. Green et al., “Meteor: Cryptographically secure steganography for realistic distributions,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. Virtual Event Republic of Korea: ACM, Nov. 2021, pp. 1529– 1548. [28] G. Liao, J. Yang, W. Shao et al., “A framework for designing provably secure steganography,” in 34th USENIX Security Symposium (USENIX Security 25). USENIX Association, 2025, pp. 6837–6856. [29] R. Zeng, J. Fang, S. Liu et al., “On the structural memory of LLM agents,” arXiv preprint arXiv:2412.15266, 2024. [30] W. Xu, Z. Liang, K. Mei et al., “A-MEM: Agentic memory for LLM agents,” arXiv preprint arXiv:2502.12110, 2025. [31] S. Yao, J. Zhao, D. Yu et al., “ReAct: Synergizing reasoning and acting in language models,” in The Eleventh International Conference on Learning Representations (ICLR 2023), 2023. [32] G. Li, H. Hammoud, H. Itani et al., “CAMEL: Communicative agents for ”mind” exploration of large language model society,” in Advances in Neural Information Processing Systems 36 (NeurIPS 2023), 2023. [33] J. Bai, S. Bai, Y. Chu et al., “Qwen technical report,” arXiv preprint, 2023. [34] Gemini Team, “Gemini 2.5: Pushing the frontier with advanced reasoning, multimodality, long context, and next generation agentic capabilities,” arXiv preprint arXiv:2507.06261, 2025. [Online]. Available: https://arxiv.org/abs/2507.06261 [35] C. E. Shannon, “A mathematical theory of communication,” The Bell system technical journal, vol. 27, no. 3, pp. 379–423, 1948. [36] M. Sun, Y. Yin, Z. Xu et al., “Idiosyncrasies in large language models,” arXiv preprint arXiv:2502.12150, 2025.

Record · ID 2446 · SHA-256 29eef2b54e5f623b
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.