AI agents can coordinate an attack without running at the same time. Shared files can carry instructions or code from one execution to the next.</p>\n<p>In Counter-Swarm Doctrine, I ask how defenders can discover which actions belong together among ordinary agent activity, establish whether the coordination was authorized, and contain its effects across restarts.</p>\n<p>The paper proposes comparing isolated actions, rolling windows, supplied groups and discovered coordination episodes at matched review cost and false-alert workload. It also proposes testing whether harmful coordination returns after communication channels are closed and shared state is quarantined.</p>\n<p>Reported incidents and a reconstruction of public wiki records ground the argument. The contribution is an incident analysis and evaluation design; the proposed defenses still need testing.</p>\n<p>I'd welcome feedback from researchers building agent evaluations, monitoring systems and realistic tests of legitimate collaboration.</p>\n","updatedAt":"2026-09-09T14:07:05.581Z","author":{"_id":"6442d514e255a338677e981b","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/6442d514e255a338677e981b/zCizY2eCX3DhbuBciIqv9.jpeg","fullname":"Greg Frank","name":"gregfrank","type":"user","isPro":true,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":3,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.912257969379425},"editors":["gregfrank"],"editorAvatarUrls":["https://cdn-avatars.huggingface.co/v1/production/uploads/6442d514e255a338677e981b/zCizY2eCX3DhbuBciIqv9.jpeg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2609.06140","authors":[{"_id":"6aa167ead8c54e38c0a369e1","name":"Gregory N Frank","hidden":false}],"mediaUrls":["https://cdn-uploads.huggingface.co/production/uploads/6442d514e255a338677e981b/kh-j0bhuld96aMkcZ1fgX.png","https://cdn-uploads.huggingface.co/production/uploads/6442d514e255a338677e981b/sOSzlCVU5hobt_tDoBkjY.png","https://cdn-uploads.huggingface.co/production/uploads/6442d514e255a338677e981b/sC4VLyfmF9xPuH0BuqxN2.png"],"publishedAt":"2026-09-05T00:00:00.000Z","submittedOnDailyAt":"2026-09-09T00:00:00.000Z","title":"Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions","submittedOnDailyBy":{"_id":"6442d514e255a338677e981b","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/6442d514e255a338677e981b/zCizY2eCX3DhbuBciIqv9.jpeg","isPro":true,"fullname":"Greg Frank","user":"gregfrank","type":"user","name":"gregfrank"},"summary":"Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.","upvotes":2,"discussionId":"6aa167ead8c54e38c0a369e2","organization":{"_id":"6a36abba90b8224bd4e5b845","name":"moltaicorp","fullname":"Molt AI Corp","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/6a32525b92295777f28d46fe/729M5piYW5YgS9lyDlc1d.jpeg"}},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"6a2da6c8ca070ee12c6e396c","avatarUrl":"/avatars/0355287dcabaa67dbc7f0b10b87451f9.svg","isPro":false,"fullname":"Joe Mama","user":"JoeMama123123123","type":"user"},{"_id":"6270324ebecab9e2dcf245de","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/6270324ebecab9e2dcf245de/cMbtWSasyNlYc9hvsEEzt.jpeg","isPro":false,"fullname":"Kye Gomez","user":"kye","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"organization":{"_id":"6a36abba90b8224bd4e5b845","name":"moltaicorp","fullname":"Molt AI Corp","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/6a32525b92295777f28d46fe/729M5piYW5YgS9lyDlc1d.jpeg"},"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2609/2609.06140.md","query":{}}">
Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions
Abstract
Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.
Community
AI agents can coordinate an attack without running at the same time. Shared files can carry instructions or code from one execution to the next.
In Counter-Swarm Doctrine, I ask how defenders can discover which actions belong together among ordinary agent activity, establish whether the coordination was authorized, and contain its effects across restarts.
The paper proposes comparing isolated actions, rolling windows, supplied groups and discovered coordination episodes at matched review cost and false-alert workload. It also proposes testing whether harmful coordination returns after communication channels are closed and shared state is quarantined.
Reported incidents and a reconstruction of public wiki records ground the argument. The contribution is an incident analysis and evaluation design; the proposed defenses still need testing.
I'd welcome feedback from researchers building agent evaluations, monitoring systems and realistic tests of legitimate collaboration.
Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images
Cite arxiv.org/abs/2609.06140 in a model README.md to link it from this page.
Cite arxiv.org/abs/2609.06140 in a dataset README.md to link it from this page.
Cite arxiv.org/abs/2609.06140 in a Space README.md to link it from this page.
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.