arXiv · 2609.26076
Selection-Invariant Communication Compilers for Privacy-Aware Multi-Agent LLM Workflows
Abstract
Structured multi-agent workflows exchange intermediate messages whose content and form can reveal private state even when the final output is safe. We identify selection-channel leakage: after authorization fixes what may be released, a private-state-aware choice among semantically valid realizations creates an additional inference channel. We introduce the selection-invariant communication compiler(SICC), which constrains this post-authorization representation kernel rather than prescribing templates. Any deterministic or independently public-randomized generator satisfying the invariant is valid; requirement-indexed canonical forms are one auditable implementation. We prove a compositional communication-layer guarantee: authorization, public-only form generation, and a dependency-safe utility gate make the emitted transcript reveal no information beyond the complete authorized view. Private-state-aware selection remains vulnerable after surface-disjoint and length-matched controls. Across 132 AgentLeak communication replays and 100 executable LangGraph tasks, deterministic SICC retains complete protocol utility without a positive excess-gain signal; independent public randomization preserves the same result in AgentLeak and 480 controlled cases.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jinghan Xu, Longze Fan, Zeyuan Wang, Xinjin Li, Hankai Liu. 2026-08-04. Selection-Invariant Communication Compilers for Privacy-Aware Multi-Agent LLM Workflows. https://arxiv.org/abs/2609.26076
Cite the original work for its findings. Save a collection to share your selection of sources.