FlowLeak: Coverage-Guided Extraction of Dynamic Workflows in LLM-Based Multi-Agent Systems
Zhiyao Ren ⋅ Siyuan Liang ⋅ Yibing Zhan ⋅ Jun L Tan ⋅ Xiaobing Sun ⋅ Liangli Zhen ⋅ Baosheng Yu ⋅ Dacheng Tao
Abstract
Large language models (LLMs)-based multi-agent systems (MAS) coordinate specialized agents through prompts, tools, and communication topologies, making their hidden workflows valuable intellectual property and security-critical assets. Existing black-box MAS extraction methods implicitly assume that adversarial queries can traverse all agents, which holds for static workflows but breaks down in dynamic workflows whose execution paths depend on input semantics and intermediate states. We identify two key challenges in dynamic workflows: **branch overfitting**, where fully adversarial queries overfit to the same branch and extract only a subset of agents, and **stealthy coverage exploration**, where the adversary needs to achieve complete branch coverage with few redundant queries while not exposing the extraction task. To address these challenges, we propose *FlowLeak* that combines **Task-Preserving Payload Template**, which preserves legitimate task semantics while eliciting workflow information to mitigate branch overfitting, with **Coverage-Guided Branch Exploration**, which uses previously extracted workflow fragments to generate branch-targeted tasks and constrains workflow extraction as an auxiliary task requirement, thereby reducing exploration queries and making extraction harder to identify. Experiments on 102 MAS show that *FlowLeak* addresses both challenges and substantially improves dynamic workflow extraction (2.68$\times$ improvement). Furthermore, we show that the extracted workflow information from *FlowLeak* enhances downstream attacks, highlighting the security risks of MAS workflow extraction and our method.
Chat is not available.
Successful Page Load