Trust-Aware Adaptive Disclosure for Inference Privacy Preservation in Multi-Agent Networks Puspanjali Ghoshal∗
and Tobias J. Oechtering†
∗ R. C. Bose Centre for Cryptology and Security, Indian Statistical Institute Kolkata, India.
arXiv:2609.05340v1 [cs.MA] 4 Sep 2026
† Information Science and Engineering Department, KTH Royal Institute of Technology, Sweden.
Abstract—Agent based systems are increasingly deployed in information critical systems including healthcare management systems, and smart grids. In this paper, we consider a multiagent system where each agent has a latent goal that needs to be kept hidden from observing adversaries. More specifically, this paper studies privacy-preserving consensus in networked multi-agent systems under goal inference attacks. We propose a Trust-Aware Privacy Control framework that adapts message disclosure based on the dynamic trust relationships between agents. The proposed method controls information release using a trust-dependent stochastic policy. This enables a tradeoff between consensus performance and privacy preservation. Experiments demonstrate that the proposed method reduces adversarial goal inference accuracy compared to representative baselines, while maintaining competitive consensus utility, thereby highlighting the effectiveness of trust-aware mechanisms in privacy preservation of the agents in multi-agent systems. Keywords—Multi-Agent System (MAS), Inference Privacy, Trust
of trust-aware adaptation with inference-privacy guarantees remains underexplored. We propose a Trust-Aware Privacy Control (TAPC) mechanism that dynamically regulates the amount of information disclosed based on inter-agent trust. The key idea is to reduce information exposure to low-trust agents while preserving useful communication with trusted neighbours. The main contributions of this work are: • A trust-aware probabilistic information disclosure mechanism for privacy-preserving consensus is proposed, linking trust and information leakage. • A theoretical characterisation of trust-leakage relationships. • Experimental analysis demonstrating improved privacyutility tradeoffs. 2. R ELATED W ORK
1. I NTRODUCTION Multi-Agent Systems (MASs) are deployed for distributed inference tasks in multiple domains including sensor networks, and healthcare systems. In such systems, agents collaborate and communicate locally to achieve global objectives. Classical distributed algorithms like consensus and distributed optimization assume that the locally exchanged information is fully observable and trustworthy. In most real life scenarios, the local communication exposes sensitive latent information such as goals, preferences, or intentions. Studies have shown that the communication patterns can be exploited by adversaries to infer private attributes of the agents [7], [13]. For example, consider a network of energy producers in a smart grid setting. To maintain the stability of the grid, participants must exchange operational information and coordinate amongst themselves to meet demand requirements. However, individual production strategies, reserve capacities, or operating plans may reveal commercially sensitive information to competing participants. In such a scenario, participants are required to cooperate to achieve a common objective while limiting the amount of information disclosed to less trusted parties. There is, therefore, a need of decentralised privacy preserved coordination. Existing approaches relying on differential privacy or additive noise mechanisms [3], [9], degrade system performance. Recently, trust-aware coordination has been explored, where interaction is based on trust relationships [6], [8]. However, to the best of our knowledge, the integration
Machine learning–based inference attacks, including classification and sequence modeling techniques, effectively exploit message statistics and temporal dependencies [11], [12]. This motivates an interest in inference-aware communication design, which will reduce the information content of messages while preserving task performance. Privacy preservation in distributed MAS has been studied in the context of consensus, optimization, and distributed learning. Representative works include privacy-preserving distributed optimisation using stochastic noise mechanisms [5], and dimension reduction mechanisms for decentralized privacy preservation [4]. Although these methods provide quantifiable privacy guarantees, they ignore heterogeneity in trust or interaction reliability. Trust and reputation are two central concepts in agentic systems. Frameworks based on these two concepts improve robustness against unreliable, faulty, and malicious agents [6], [8]. Existing works based on the incorporation of trust in privacy preservation either require a central trust management authority [14], or have been applied in query based settings [10]. Thus, the relationship between trust and decentralized privacy leakage remains largely unexplored in literature. In contrast to existing work, this paper integrates trust with privacy-aware message generation. The proposed framework uses trust as a privacy control variable that governs selective disclosure. This allows the system to simultaneously adapt to network heterogeneity, preserve system performance, and reduce adversarial goal inference capability.
3. P ROBLEM F ORMULATION We consider a MAS comprising of N agents represented by the set A = {1, 2, . . . , N }. The communication topology is modeled as an undirected graph G = (V, E), where V = A denotes the set of agents and E ⊆ V × V represents communication links. Let Ni = {j : (i, j) ∈ E} denote the set of neighbours of agent i. Let xi (t) ∈ Rd denote the observable state of agent i at time instant t. Each agent possesses a latent goal variable gi ∈ Y, where Y = {1, 2, . . . , K} denotes a finite goal space. The latent goal may correspond to a destination, mission objective, optimization preference, or task intent. Unlike the observable state xi (t), the goal variable gi is private and must not be inferred by unauthorised entities. To accomplish a cooperative task, agent i transmits a message mij (t). The communication history of agent i over a time horizon T is given by HiT = {mij (t) : j ∈ Ni , t = 0, . . . , T } .
(1)
dependent. Accordingly, the communication history observed T T by an adversary can be represented as HA = HA (τ ). Therefore, the amount of information leaked about the latent goal is inherently influenced by the trust profile of the network. Specifically, agents disclose more information to highly trusted neighbours and increasingly obfuscated information to low-trust neighbours. Consequently, the communication history observed by an adversary becomes a function of the trust distribution within the network. C. Inference Privacy Metric The objective of the adversary is to infer latent goals from communication behavior. Let τ = {τij | (i, j) ∈ E} denote the network trust profile. The inference privacy loss T associated with agent i is defined as Li (τ ) = I gi ; HA , where I(·; ·) represent the mutual information metric. Since the communication history depends on the trust profile, the resulting leakage is indirectly influenced by τ . The average network-wide inference leakage is given by
A. Threat Model
N
We consider a passive inference adversary that observes communication exchanges and exploits temporal communication patterns to infer the hidden goals of participating agents. The adversary is assumed to possess complete knowledge of the communication protocol and network topology but cannot directly access the internal states or latent goals of the agents. Let OA ⊆ E denote the set of communication links observable to the adversary. The adversary collects the communication history T HA = {mij (t) : (i, j) ∈ OA ; t = 0, . . . , T } ,
(2)
T ), and constructs an estimate of the private goal ĝi = fA (HA where fA (·) denotes an inference model. The inference success probability is defined as
Pinf = Pr(ĝi = gi ).
(3)
A larger value of Pinf indicates a higher degree of privacy leakage. Low-trust agents are assumed to present a higher risk of information leakage and may also act as inference adversaries. B. Trust-Aware Communication Model Each agent maintains a trust score toward its neighbouring agents. Let τij ∈ [0, 1] denote the trust level assigned by agent i to neighbouring agent j. A larger value of τij indicates a higher degree of trust. The transmitted message is generated according to a trust-aware disclosure policy mij (t) = πi xi (t), gi , τij , (4) where πi (·, ·, ·) adjusts the amount of information disclosed based on the trust level of the receiver. Since the communication policy explicitly depends on the trust score τij , the resulting communication history is also trust
L(τ ) =
1 X Li (τ ). N i=1
(5)
A smaller value of L(τ ) implies stronger resistance against goal inference attacks. Mutual information metric quantifies the statistical dependence between an agent’s latent goal and the observable information, thereby capturing potential inference risks arising from communication patterns. The objective considered here is to limit the disclosure of goal-related information to untrusted agents. Mutual information characterizes average information leakage rather than worst-case leakage, providing a practical measure of inference risk. However, direct estimation of mutual information from high-dimensional communication histories is challenging in practice. Therefore, the experimental section adopts adversarial goal-classification accuracy defined in Equation (3) as an empirical surrogate for inference leakage. A random forest [1] classifier is trained to infer latent goals from observed communication histories. Lower accuracy indicates lower inference leakage. Similar attack-based evaluation methodologies are widely used in privacy-preserving systems to assess resistance against realistic inference attacks. D. Task Utility The agents collaborate to achieve a global objective characterized by the utility function U = U (x, m), where x = [x1 , . . . , xN ] and m = [m1 , . . . , mN ]. Depending on the application, U may represent consensus accuracy, formation stability, tracking performance, or distributed optimization efficiency. E. Problem Statement The proposed formulation follows a counter-adversarial design. The objective is to design a trust-aware communication policy that minimizes communication-based goal inference
while preserving cooperative task performance and communication efficiency. Let the communication overhead be defined as C(m) =
T X X
|mij (t)|,
(6)
t=0 (i,j)∈E
where |mij (t)| denotes the size of the message transmitted from agent i to agent j in bits. The trust-aware inference privacy preservation problem is formulated as
and consistency lie within [0, 1], the resulting trust score also satisfies τij (t) ∈ [0, 1]. Higher trust scores indicate a more reliable communication partner, whereas lower values indicate potentially risky agents that may facilitate privacy leakage. The network trust profile is represented by τ = {τij (t) | (i, j) ∈ E} . B. Trust-Based Disclosure Control To regulate information sharing, each communication link is assigned a disclosure coefficient. The disclosure coefficient associated with communication link (i, j) is defined as
min L(τ ) π
s.t.
γ αij (t) = τij (t),
U (x, m) ≥ Umin ,
(7)
C(m) ≤ Cmax , mij (t) = πi xi (t), gi , τij .
The optimization problem seeks a communication policy that minimizes the information an adversary can infer about the latent goals of agents while guaranteeing a minimum level of task utility and respecting communication constraints. 4. T RUST-AWARE P RIVACY C ONTROL F RAMEWORK We now illustrate the proposed trust-aware framework for mitigating goal inference attacks in multi-agent systems. The framework consists of four components: trust evaluation, adaptive disclosure control, privacy-preserving message generation, and leakage-aware optimization.
where γ > 0 is a sensitivity parameter. The coefficient satisfies 0 ≤ αij (t) ≤ 1. When αij (t) approaches one, a larger amount of task-relevant information is disclosed. Conversely, smaller values correspond to stronger privacy protection. C. Trust-Aware Message Generation The key idea of the proposed framework is to selectively disclose task-relevant information while limiting the amount of goal-related information exposed to potentially untrusted agents. Let zi (t) = ϕ (xi (t), gi ) denote a task-relevant feature extracted from the observable state and latent goal of agent i, where ϕ(·) is an application-dependent feature mapping. The transmitted message is generated as mij (t) = αij (t)zi (t) + (1 − αij (t)) ηi (t),
A. Trust Evaluation Model Each agent maintains trust scores for its neighbouring agents based on historical communication behavior and interaction outcomes. Let rij (t) denote the communication reliability of agent j as observed by agent i, and let sij (t) denote a behavioral consistency score. The communication reliability is defined as rij (t) =
(11)
succ Nij (t) , tot Nij (t)
(8)
succ tot where Nij (t) and Nij (t) denote the number of successful and total communication interactions, respectively, within a predefined observation window. To quantify behavioral consistency, each agent compares recent communication behavior with historical patterns. The consistency score is defined as
! W 1 X sij (t) = exp − |mij (t − k) − m̄ij (t)| , W
(9)
k=1
where W denotes the observation window and m̄ij (t) denotes the average communication behavior. The trust score assigned by agent i to agent j is computed as τij (t) = λrij (t) + (1 − λ)sij (t),
(10)
where 0 ≤ λ ≤ 1 controls the relative importance of reliability and behavioral consistency. Since both reliability
(12)
where ηi (t) denotes an obfuscation signal. In this work, Gaussian perturbation is adopted, ηi (t) ∼ N 0, σ 2 I , where σ 2 denotes the noise variance, resulting in a trust-dependent Gaussian disclosure mechanism. The focus of the proposed framework is the adaptive trust dependent disclosure policy. Alternative perturbation mechanisms may also be incorporated. Equation (12) ensures that highly trusted neighbours receive more informative messages, while low-trust neighbours receive increasingly obfuscated information. D. Leakage Upper Bound The disclosure coefficient directly affects the signal-to-noise ratio available to the adversary. Let Pz = E |zi (t)|2
(13)
denote the average power of the task-relevant feature. The effective signal-to-noise ratio observed on communication link (i, j) is SNRij =
2 αij Pz 2
(1 − αij ) σ 2
.
(14)
Under the proposed message-generation model, the adversarial observation process can be approximated as an additive white Gaussian noise (AWGN) channel with effective signalto-noise ratio given by Equation (14). Thus, the mutual information between the transmitted signal and the adversarial
observation is upper bounded by the Shannon channel capacity formula [2]. Therefore,
leakage upper bound is a monotonically increasing function of the trust score τij .
1 log (1 + SNRij ) . (15) 2 with equality achieved when the effective transmitted feature is Gaussian distributed. This equation establishes an explicit relationship between trust-aware disclosure and inference leakage. Since the latent goal influences the transmitted feature zi (t), the information available for goal inference cannot exceed the information contained in the observed communication channel. The complete algorithm is outlined in Algorithm 1.
Proof. Differentiating (11) with respect to τij gives
Li (τ ) ≤
Algorithm 1 Trust-Aware Privacy-Preserving Communication 1: for each communication round t do 2: for each link (i, j) ∈ E do 3: Compute reliability rij (t)
Compute consistency score sij (t) Update trust score using (10) Compute disclosure coefficient using (11) Generate noise ηi (t) Construct message using (12) 9: Transmit mij (t) 10: end for 11: end for 4: 5: 6: 7: 8:
The computational complexity is dominated by trust updates and message generation across communication links. Therefore, the overall complexity per communication round is O(|E|). 5. T HEORETICAL A NALYSIS
∂αij γ−1 . = γτij ∂τij Since γ > 0 and τij ∈ (0, 1], ∂αij > 0. ∂τij
∂Li ∂Li ∂αij = > 0. ∂τij ∂αij ∂τij
Since Pz > 0, σ 2 > 0, and 0 < αij < 1, it follows that ∂SNRij > 0. ∂αij Furthermore, the function f (x) = 12 log(1 + x) is strictly increasing for x ≥ 0. Therefore, ∂Li ∂Li ∂SNRij = > 0. ∂αij ∂SNRij ∂αij Hence, the leakage upper bound increases monotonically with the disclosure coefficient αij . Consequently, reducing disclosure lowers the information available to the adversary and decreases inference leakage. Theorem 1. (Trust-Leakage Relationship) For a fixed noise variance σ 2 and sensitivity parameter γ > 0, the inference
(18)
Therefore, the inference leakage upper bound increases monotonically with the trust score τij . Consequently, highly trusted communication links reveal more information to the receiver and potentially to an observing adversary. Thus, this theorem proves that for a specific communication link, increasing trust increases information disclosure and therefore leakage on that link. Corollary 1. (Effect of Sensitivity Parameter) For a fixed trust score τij ∈ (0, 1), increasing the sensitivity parameter γ reduces the inference leakage upper bound. Proof. Differentiating (11) with respect to γ yields ∂αij γ = τij ln(τij ). ∂γ
(19)
Since 0 < τij < 1, we have ln(τij ) < 0, which implies
Lemma 1. For fixed noise variance σ , the inference leakage upper bound is monotonically increasing with the disclosure coefficient αij .
∂SNRij 2αij Pz = 2 . ∂αij σ (1 − αij )3
(17)
Using the chain rule together with Lemma 1,
2
Proof. Differentiating Equation (14) with respect to αij yields
(16)
∂αij < 0. ∂γ
(20)
∂Li ∂Li ∂αij = < 0. ∂γ ∂αij ∂γ
(21)
Using Lemma 1,
Hence, increasing the sensitivity parameter γ decreases the inference leakage upper bound. Therefore, γ acts as a tunable privacy-control parameter that allows stronger privacy protection without modifying the trust evaluation mechanism. For the preliminary theoretical analysis of the proposed trust dependent framework, the leakage analysis has been carried out by considering a simplified instantaneous setting. Alternative message generation mechanisms along with the incorporation of dynamic temporal message history will be explored in future extensions. 6. E XPERIMENTS AND R ESULTS This section evaluates the proposed Trust-Aware Privacy Control (TAPC) framework against three representative baseline methods. Performance is evaluated in terms of consensus utility, inference leakage, and communication cost.
We consider a network of N = 50 agents interacting over a connected random geometric graph. Each agent is assigned a latent goal from a discrete set of size K = 6. The system evolves over T = 100 communication rounds. To assess privacy, the experimental evaluation employs an adversary that observes communication histories and performs goal inference using machine learning. The TAPC method introduces trust-dependent stochastic perturbation in message generation, while the baselines represent full disclosure (FD), uniform Gaussian noise (GN), and trust-thresholded communication (TOC). In the context of privacy-preserving consensus [7], [13], FD corresponds to the standard baseline where agents exchange unperturbed state information. Noisy communication mechanisms, represented in this work as GN, have been widely adopted for privacy in distributed settings [9]. In contrast, TOC builds on trust-aware communication strategies where information is released only to neighbours that satisfy a prespecified trust threshold [6], [8].
extracted from temporal communication histories. As shown in Figure 2, FD results in complete information leakage, while GN reduces leakage at the cost of degraded utility. TOC further reduces leakage by limiting communication on low-trust links. TAPC achieves the lowest leakage among all evaluated methods, demonstrating the effectiveness of trustaware stochastic masking.
1.0 Inference Leakage
A. Experimental Setup
0.8 0.6 0.4 0.2 0.0
B. Consensus Utility Consensus performance is measured using: U=
1 + N1
1 PN
i=1 ∥xi − x̄∥
,
Figure 3 illustrates the tradeoff between utility and leakage. FD lies at the high-utility but high-leakage extreme, while GN shifts toward lower leakage but reduced performance. TOC provides a balanced intermediate tradeoff, whereas TAPC achieves a strong Pareto-efficient operating point among the evaluated methods.
0.96
0.6 0.4 0.2 GN TOC Method
TAPC
D. Privacy–Utility Pareto chart
TAPC
Fig. 1: Consensus utility comparison across methods. C. Inference Leakage Analysis Inference leakage is computed using Equation (3) under a random forest adversary [1] trained on statistical features
Consensus Utility
Consensus Utility
Task Performance Accuracy
FD
GN TOC Method
Fig. 2: Inference leakage comparison across methods.
0.8
0.0
FD
(22)
where x̄ denotes the mean state. As shown in Figure 1, FD achieves the highest utility due to unrestricted communication. GN significantly degrades performance due to injected noise. TOC improves utility by selectively preserving structured communication on high-trust links. TAPC maintains competitive utility while incorporating stochastic privacy protection.
1.0
Inference Attack Accuracy
Privacy Utility Tradeoff
0.94 0.92
FD GN TOC TAPC
0.90 0.88 0.2
0.4 0.6 0.8 Inference Leakage
1.0
Fig. 3: Privacy-utility tradeoff between inference leakage and consensus utility.
E. Communication Cost With the number of agents fixed, all methods incur identical communication cost since each agent communicates over all edges at every iteration, isolating the effect of message design. The proposed TAPC method exhibits a steady increase in the communication cost as the number of agents increases. This is depicted in Figure 4.
Cost Scalability
Communication Cost
1e7 1.5 1.0 0.5 0.0
R EFERENCES
100 200 300 Number of Agents
400
Fig. 4: Cost scaling with respect to number of agents.
F. Results Summary Table I summarizes the performance for 50 agents. The experimental results demonstrate that TAPC achieves a strong balance between privacy and utility, consistently reducing inference leakage while maintaining competitive consensus performance compared to baseline methods. Method FD GN TOC TAPC
more effective than both uniform perturbation and deterministic trust filtering for mitigating information leakage in multiagent networks. This suggests that incorporating trust structure into privacy mechanisms provides a principled direction for improving secure coordination in distributed systems. The current theoretical analysis, however, considers a simplified instantaneous communication setting and establishes explicit relationships between trust, disclosure, and inference leakage. Future work will extend the framework to account for temporal dependencies and information aggregation across communication histories. We will further extend the proposed framework to time-varying, directed communication graphs. This would enable its application to dynamic networked systems. Second, the message generation framework will be changed from the preliminary Gaussian noise to alternative mechanisms and the theoretical guarantees on privacy leakage bounds and convergence rates would be strengthened appropriately. Finally, TAPC would be deployed in real-world multiagent applications to further validate its practical effectiveness.
Utility 0.960 0.872 0.909 0.920
Leakage 0.997 0.583 0.173 0.137
Cost 245000 245000 245000 245000
TABLE I: Performance comparison of different methods
7. C ONCLUSION AND F UTURE W ORK This paper proposes a Trust-Aware Privacy Control (TAPC) framework for multi-agent consensus systems under inferencebased privacy threats. Unlike conventional approaches that rely on uniform noise injection or hard trust thresholding, the proposed method introduces a trust-dependent stochastic masking mechanism that adaptively regulates information disclosure during inter-agent communication. Experimental evaluations demonstrate the efficiency of TAPC over representative baselines. TAPC achieves a balance between consensus performance and privacy preservation. The results highlight that adaptive trust-aware stochastic control is
[1] Leo Breiman. Random forests. Machine learning, 45(1):5–32, 2001. [2] Thomas M Cover and Joy A Thomas. Elements of information theory. 2012. [3] Ying Deng, Huimin Dong, and Bo Mao. Differential privacy-preserving consensus of multi-agent systems under replay attacks. In 2024 43rd Chinese Control Conference (CCC), pages 5627–5632. IEEE, 2024. [4] Puspanjali Ghoshal and Ashok Singh Sairam. Dynamic projection method: A learning based approach for preserving inference privacy. In GLOBECOM 2025-2025 IEEE Global Communications Conference, pages 6063–6068. IEEE, 2025. [5] Puspanjali Ghoshal and Ashok Singh Sairam. Utility aware adaptive privacy budget allocation for streaming multi-agent systems. In Proc. of the 25th International Conference on Autonomous Agents and Multiagent Systems, pages 681–689, 2026. [6] Jones Granatyr, Vanderson Botelho, Otto Robert Lessing, Edson Emı́lio Scalabrin, Jean-Paul Barthès, and Fabrı́cio Enembreck. Trust and reputation models for multiagent systems. ACM Computing Surveys (CSUR), 48(2):1–42, 2015. [7] Jian Hou, Jing Wang, Mingyue Zhang, Zhi Jin, Chunlin Wei, and Zuohua Ding. Privacy-preserving resilient consensus for multi-agent systems in a general topology structure. ACM Transactions on Privacy and Security, 26(3):1–22, 2023. [8] Mingde Huang, Yiming Wu, and Qiuxia Huang. Resilient and privacypreserving consensus for multi-agent systems. Information Sciences, 700:121843, 2025. [9] Zhenqi Huang, Sayan Mitra, and Nitin Vaidya. Differentially private distributed optimization. In Proceedings of the 16th international conference on distributed computing and networking, pages 1–10, 2015. [10] Chenguang Liu and Christine Julien. Pervasive context sharing in magpie: adaptive trust-based privacy protection. In International conference on mobile computing, applications, and services, pages 122–139. Springer, 2015. [11] Chuan Ma, Jun Li, Kang Wei, Bo Liu, Ming Ding, Long Yuan, Zhu Han, and H Vincent Poor. Trusted ai in multiagent systems: An overview of privacy and security for distributed learning. Proceedings of the IEEE, 111(9):1097–1132, 2023. [12] James Tu, Tsunhsuan Wang, Jingkang Wang, Sivabalan Manivasagam, Mengye Ren, and Raquel Urtasun. Adversarial attacks on multiagent communication. In Proceedings of the IEEE/CVF International Conference on Computer Vision, pages 7768–7777, 2021. [13] Yamin Wang, Hong Lin, James Lam, and Ka-Wai Kwok. Differentially private consensus and distributed optimization in multi-agent systems: A review. Neurocomputing, 597:127986, 2024. [14] Song Zhang, Yanbing Liu, Yunpeng Xiao, and Rui He. A trust based adaptive privacy preserving authentication scheme for vanets. Vehicular Communications, 37:100516, 2022.