Theoretical modeling study demonstrates reduced compromise probability in autonomous multi-agent systems, indicating enhanced protection through layered boundary verification.
As autonomous multi-agent runtimes transition from conversational prototypes to revenue-bearing infrastructure, the security assumptions that governed classical software systems no longer hold. Prompt injection, tool-call hijacking, credential escalation, and cross-tenant state corruption are not edge cases in multi-agent architectures — they are structural consequences of coupling non-deterministic reasoning to deterministic settlement rails. This paper formalizes Autonomous Micro-Enterprise Security (AMES): a security architecture and threat-bounded runtime model for verification-gated agent execution. We (1) formalize the adversarial surface of a multi-agent finite state machine as an explicit ingress vector set; (2) derive, under stated independence and boundary-isolation assumptions, a bound on the probability that an adversarially manipulated instruction reaches deterministic settlement; (3) describe a six-layer defense-in-depth runtime consistent with the AMEA reference architecture; and (4) present an illustrative, parameter-driven simulation — not a production benchmark — quantifying how the modeled compromise probability contracts under layered boundary verification. We discuss the relationship between AMES and the cryptographic attestation layer of AMEG, and outline a doctoral research agenda to test the model's predictions against real adversarial traces.
No takes yet. Share an insight, caveat, or question.
Ram Kumar Rajagopal (2026) studied this question.