Placement, Not Variance: Redefining the Axis of Security for Multi-Agent AI Systems
Abstract
Multi-agent AI systems (MAS) are typically hardened against adversarial content – prompt injection, misinformation, or corrupted tool output – by monitoring aggregate statistics such as how many agents are compromised or how heterogeneous their resistance levels are. We show, both theoretically and on a deployed MAS, that this is the wrong axis. We model a MAS as a weighted contact graph in which each agent’s empirical resistance to adopting false information induces a susceptibility weighted transmission matrix and cast propagation risk as an epidemic threshold on that graph. First-order spectral perturbation theory shows that the location of a weak (highly susceptible) agent relative to the graph’s Perron eigenvector, rather than the variance of the resistance distribution, determines the direction and magnitude of the threshold shift. We verify this by exhaustively enumerating all potential resistance level placements in a twelve agent system with a fixed resistance multiset on four canonical topologies. At a fixed mean resistance, changing the placement of high and low resistance levels swings the epidemic threshold by up to 4× more than changing the variance does. On star and dense-ring topologies specifically, the effect of adjusting placement is strictly non-zero while the effect of changing variance vanishes. A same-mean, same-variance counterexample isolates the effect from any moment-based confound. We then show that this is not merely an artifact of modeling the system. A chain-propagation diagnostic on a real deployed MAS confirms that a false fact injected at one agent measurably crosses agent boundaries in all ten trials, and aggregate measurements on the same live system match the model’s central prediction. In the regime the theory identifies as the “live cell,” local agent memory and high resistance heterogeneity, variance alone is a near-null predictor of cascade size (R2 = 0.01), while placement-aware spectral exposure predicts it well (pseudo-R2 = 0.93). Lastly, we connect these results to guarding and monitoring to show that placement-aware guard selection is not degree centrality in disguise, and under a fixed evaluation budget, placement-aware monitoring lowers cascade-miss rate at every budget tested.