Rodrigo Martinez Pinto · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.23114295
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Autonomous multi-agent architectures rely on dynamic natural language messaging between specialized sub-agents to execute complex enterprise workflows. However, this decentralized communication topology introduces structural vulnerability to indirect prompt injection and tool hijacking attacks, where compromised agent outputs trick downstream sub-agents into invoking unauthorized API functions. Existing defense mechanisms rely on secondary LLM-based content classification proxies, introducing non-deterministic failure modes and severe latency degradation (P99 > 180 ms). This paper introduces Bounded Execution State Machines (BESM), a zero-allocation deterministic guardrail architecture embedded directly into the inter-agent RPC layer. BESM models valid multi-agent execution graphs as formal finite state automata G = (V, E, Sigma, delta, S0, F), enforcing strict topological transition invariants prior to tool dispatch. Our empirical evaluation across 10,000 adversarial injection vectors demonstrates 100% attack containment with zero heap allocations, achieving an average execution latency of 0.42 ms and throughput exceeding 1.8 x 10^6 state validations per second per core. This work provides an open-source, deterministic foundation for enterprise multi-agent safety and scalable AI governance.
No comments yet — start the discussion below.