Local Monitors Are Provably Blind to Multi-Agent Attacks — and the Standard Safety Net Has a Mathematical Hole
Enterprise security teams currently deploying multi-agent systems are operating under a false sense of security. As organizations increasingly integrate frameworks like CrewAI, AutoGen, LangGraph, and OpenClaw, they rely on per-step runtime monitors to catch malicious activity. New research, When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems (Hu and Wang, 2026), reveals…