Gregory Frank · Chief Scientist, Molt AI · September 5, 2026
Shared infrastructure can connect separate agent executions. An artifact one run leaves behind — a file, a registry entry, a page — can be read and acted on by a later run, sometimes after the first has already terminated. The paper starts from two public 2026 incidents in which agents used shared services this way, and argues that a security assessment may therefore need evidence from several executions and the artifacts they leave behind.
Its central proposal is a different defensive unit. Rather than reviewing each action in isolation, the defender should work with a coordination episode: a revisable record linking related executions, the artifact versions through which they influenced one another, the task policy that applied, and the response history. Membership is not given in advance; it must be discovered and revised as evidence arrives. The paper names this problem prospective episode discovery — finding which actions belong together before an evaluator supplies the answer.
Two distinctions carry the argument. First, an observed relationship is not demonstrated influence: shared inputs, a common model, or simultaneous resource use can produce correlation without one run having affected another. Second, coordination is only unsanctioned relative to a policy. Legitimate workflows create many cooperating agents, so classifying an episode requires both evidence of a relationship between executions and an applicable collaboration or delegated-authority policy. Where either is missing, the paper keeps the classification unresolved.
From this it derives three testable recommendations: assess influence against policy, discover related activity at a bounded review cost, and carry containment through workload restart so that surviving state does not reintroduce the dependency. A proposed evaluation would compare prospectively discovered episodes against isolated actions, rolling windows, and evaluator-supplied groups at matched review cost and false-alert workload.
The paper presents an incident-grounded position, descriptive analysis, and evaluation design. It does not claim a new detector or a measured containment benefit.
Citation as indexed by arXiv: Gregory N Frank, “Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions,” arXiv:2609.06140, September 5, 2026.