Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of multi-agent covert communication, including low capacity, reliance on pre-shared keys, and susceptibility to detection, by proposing a high-capacity, keyless steganographic protocol tailored for asymmetric deployments. Methodologically, it pioneers the integration of adaptive error correction with large language model-based public channel estimation, leveraging computational indistinguishability to achieve undetectable agent collusion. Experimental results demonstrate that the proposed protocol successfully establishes a shared key within 80,000 tokens with a failure rate below 4.1×10⁻³, while achieving a 94-fold improvement in communication capacity over existing baselines. This work provides an efficient new paradigm for secure multi-agent collaboration.
📝 Abstract
Multi-agent systems built on large language models (LLMs) are increasingly deployed in high-stakes settings such as finance, healthcare, and software engineering, where agents coordinate through natural-language messages. The same channels, however, let colluding agents exfiltrate confidential information or coordinate unauthorized actions, and steganography can hide such communication inside outputs that look ordinary to an auditor reading the transcript. Existing provably undetectable LLM steganography protocols are not suited to realistic deployments. High-capacity schemes assume a symmetric setting where the receiver can reproduce the sender's output distribution, the state-of-the-art protocol for asymmetric agents has very low capacity, and most approaches rely on a pre-shared secret key. We make the threat of undetectable agent collusion concrete with Codetta, a high-capacity steganographic protocol for independently deployed agents in realistic asymmetric settings. Codetta combines a shared public model that estimates the communication channel, a sampling mechanism that preserves the sender's output distribution, and an adaptive error-correcting code. It further removes the pre-shared key through a steganographic key exchange that lets independently deployed agents establish a shared key while keeping the transcript computationally indistinguishable from ordinary model outputs. Across three agent workloads and three sender models, Codetta achieves up to $94\times$ the capacity of the state-of-the-art asymmetric protocol, and its key exchange establishes a shared key with about 80k visible tokens at an empirically certified failure probability of at most $4.1\times 10^{-3}$. These results show that effectively undetectable collusion is becoming feasible between independently deployed agents, so auditing must go beyond inspecting communication transcripts.
Problem

Research questions and friction points this paper is trying to address.

multi-agent collusion
LLM steganography
asymmetric agents
keyless communication
undetectable exfiltration
Innovation

Methods, ideas, or system contributions that make the work stand out.

Steganography
Multi-agent collusion
Large language models
Key exchange
Adaptive error-correcting code
🔎 Similar Papers
No similar papers found.