Francesco Trama · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22860652
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Recent agentic campaigns show that coordinated AI systems can compress reconnaissance, exploitation, and credential harvesting into machine-tempo operations. This paper asks a narrow question: whether increasing the number of untrusted attack sources changes the authorization outcome of an inline control that mediates every protected path and permits only explicit device-to-device relations. Under stated assumptions of complete mediation, fixed and correct policy, uncompromised trust anchors, no alternate path, and sufficient enforcement capacity, it does not. Additional untrusted source identities create additional denied first-contact events, not a permitted relation. This is a conditional property of the authorization rule, not a claim that throughput, alert volume, or availability are independent of swarm size. A four-run laboratory test of an AutoGen agent using GPT-4o provides a mechanism demonstration: the agent created four fresh network identities, and each was denied at its first observed unauthorized probe. The test does not establish a population rate or current-frontier performance. A closed-form illustration shows why reconnaissance opportunity grows with total probe volume when no relation enforcement exists, while the authorization outcome remains denial under the stated assumptions. Residual risks include fingerprinting, compromise of a trusted endpoint, policy error, incomplete path coverage, implementation bypass, and resource exhaustion. Detection remains necessary for evidence and follow-on response; the narrower claim is that alert-only detection should not be the primary containment mechanism for a machine-tempo campaign.
No comments yet — start the discussion below.