Research · Research paper

Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions

Gregory Frank · Chief Scientist, Molt AI · September 5, 2026

Read on arXiv →  Open PDF (opens on arXiv)

Overview

Shared artifacts can connect agent executions.

Shared infrastructure can connect separate agent executions. An artifact one run leaves behind — a file, a registry entry, a page — can be read and acted on by a later run, sometimes after the first has already terminated. The paper starts from two public 2026 incidents in which agents used shared services this way, and argues that a security assessment may therefore need evidence from several executions and the artifacts they leave behind.

Its central proposal is a different defensive unit. Rather than reviewing each action in isolation, the defender should work with a coordination episode: a revisable record linking related executions, the artifact versions through which they influenced one another, the task policy that applied, and the response history. Membership is not given in advance; it must be discovered and revised as evidence arrives. The paper names this problem prospective episode discovery — finding which actions belong together before an evaluator supplies the answer.

The argument

Policy and evidence, not resemblance, decide what counts as coordination.

Two distinctions carry the argument. First, an observed relationship is not demonstrated influence: shared inputs, a common model, or simultaneous resource use can produce correlation without one run having affected another. Second, coordination is only unsanctioned relative to a policy. Legitimate workflows create many cooperating agents, so classifying an episode requires both evidence of a relationship between executions and an applicable collaboration or delegated-authority policy. Where either is missing, the paper keeps the classification unresolved.

From this it derives three testable recommendations: assess influence against policy, discover related activity at a bounded review cost, and carry containment through workload restart so that surviving state does not reintroduce the dependency. A proposed evaluation would compare prospectively discovered episodes against isolated actions, rolling windows, and evaluator-supplied groups at matched review cost and false-alert workload.

What the paper claims, and what it does not

An incident-grounded position and an evaluation design.

The paper presents an incident-grounded position, descriptive analysis, and evaluation design. It does not claim a new detector or a measured containment benefit.

Citation as indexed by arXiv: Gregory N Frank, “Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions,” arXiv:2609.06140, September 5, 2026.

Read on arXiv →  Open PDF (opens on arXiv) →