OpenEvoShield: Dual Non-Stationary Continual Defense for Open-World Multi-Agent System Attacks
Quick Answer
OpenEvoShield introduces a co-evolutionary continual defense framework for LLM-based multi-agent systems, effectively countering dynamic attacks with a unique asymmetric rate controller and multi-granularity detector.
Quick Take
Experiments show it outperforms static defenses, detecting most unseen attacks while maintaining low false positive rates across five benchmarks.
Key Points
- OpenEvoShield employs an asymmetric rate controller to manage learning rates for attacks and normal behavior.
- The framework adapts to dual drift signals, enhancing defense against evolving threats.
- An energy-based multi-granularity detector classifies novel attacks as out-of-distribution.
- Experiments cover 100 deployment rounds across four MAS topologies, demonstrating robust performance.
- Most previously unseen attacks were detected with low false positive rates.
DeepSignal Analysis
What happened
OpenEvoShield is a proposed framework designed to enhance defenses in LLM-based multi-agent systems against dynamic attacks. It employs a co-evolutionary approach that includes an asymmetric rate controller and a multi-granularity detector. Experimental results indicate that it surpasses traditional static defenses in detecting unseen attacks while maintaining low false positive rates.
Key evidence
- OpenEvoShield utilizes an asymmetric rate controller to manage learning rates for attack and normal behaviors separately, addressing the dynamic nature of threats.
- The framework includes a normal-boundary updater that establishes a dynamic behavioral boundary, adapting to changes in agent behavior over time.
- In experiments across five benchmarks and four multi-agent system topologies, OpenEvoShield demonstrated superior performance in detecting previously unseen attacks compared to static and continual defense methods.
Why it matters
The introduction of OpenEvoShield is significant as it addresses the limitations of existing defenses that fail when faced with evolving threats in multi-agent systems. By adapting to both adversarial strategies and normal behavior changes, it aims to improve the resilience of systems deployed in critical applications. This advancement could lead to more robust AI systems capable of maintaining safety and reliability in unpredictable environments.
Paper Resources
📖 Reader Mode
~2 min readAbstract:LLM-based multi-agent systems (LLM-MAS) are increasingly deployed in safety-critical applications, where adversaries inject malicious instructions through inter-agent communication to propagate harmful behaviors. Unlike static threats, these attacks are doubly dynamic: adversaries refine injection strategies against deployed defenses while normal-agent behavior drifts with system expansion. Existing defenses treat deployment as a closed-world problem and degrade rapidly once either distribution shifts beyond training coverage. We propose OpenEvoShield, a co-evolutionary continual defense framework for LLM-MAS. An asymmetric rate controller (M1) decouples fast attack-side and slow normal-side learning rates from dual drift signals. A normal-boundary updater (M2) maintains a dynamic behavioral boundary at the slow rate, while an EWC-regularized policy ensemble (M3) fast-adapts without catastrophic forgetting. An energy-based multi-granularity detector (M4) fuses node-, subgraph-, and graph-level evidence to classify novel attacks as out-of-distribution. Experiments over 100 deployment rounds across five benchmarks and four MAS topologies show that OpenEvoShield outperforms static and continual baselines, detecting most previously unseen attacks while keeping false positive rates low.
| Comments: | 29 pages, 5 figures, 14 tables |
| Subjects: | Artificial Intelligence (cs.AI) |
| Cite as: | arXiv:2607.19351 [cs.AI] |
| (or arXiv:2607.19351v1 [cs.AI] for this version) | |
| https://doi.org/10.48550/arXiv.2607.19351 arXiv-issued DOI via DataCite |
Submission history
From: Zejian Chen [view email]
[v1]
Wed, 13 May 2026 04:28:46 UTC (1,573 KB)
— Originally published at arxiv.org
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from arXiv cs.AI
See more →HOBA: Hierarchical On-Policy Bidding Agents for Adaptive Online Advertising
HOBA (Hierarchical On-policy Bidding Agents) is a novel hierarchical reinforcement learning framework that enhances online advertising bidding systems by improving adaptability and reducing hyperparameter tuning costs. It utilizes a for hyperparameter inference, a SARSA agent for expert model selection, and a dynamic expert pool for bid execution, achieving a +3.6% increase in target cost during large-scale deployment and outperforming state-of-the-art baselines on AuctionNet.