Search papers, labs, and topics across Lattice.
This paper introduces FGLGuard, a federated graph learning approach designed to enhance the safety of LLM-based multi-agent systems by enabling operators to collaboratively train a graph attention detector without sharing sensitive data. By addressing the limitations of traditional centralized training, which fails under distribution shifts, FGLGuard allows each operator to utilize their own labeled episode graphs while only sharing model updates. The results show that federated training significantly improves performance on safety benchmarks, achieving near-centralized results while maintaining privacy and operational integrity across diverse domains.
Federated learning can outperform centralized models in multi-agent safety without compromising data privacy, achieving a remarkable 43% reduction in attack success rates.
Topology-guided safeguards for LLM-based multi-agent systems (MAS) train a GNN over the inter-agent communication graph to localize risky agents and intervene on the topology---but they assume one operator can pool all labeled traces. Across organizations that assumption breaks: episodes contain private prompts, tool outputs, and proprietary workflows, and no silo alone sees the full attack distribution. We cast privacy-preserving MAS safeguarding as graph federated learning and instantiate FGLGuard: each operator fits an edge-featured graph attention detector on its own judge-labeled episode graphs and shares only model updates. The method couples a proximal local objective for non-IID clients, domain-balanced aggregation, over-refusal-constrained threshold calibration, corroborated upstream scoring, and a guarded rewrite for blocked answers. Federation is not optional: off-the-shelf transfer collapses under distribution shift (AUROC 0.51 to 0.70 only after in-domain retraining), so a deployable guard must adapt on each site's private traces. On Agent-SafetyBench, R-Judge, and AgentDojo, federated FGLGuard exceeds the in-domain centralized ceiling on all three benchmarks without pooling any data---where unsupervised anomaly guards and local-only training fail. One guard federated across four different-domain operators comes within 0.03 AUROC of multi-domain centralization, while any single-domain guard collapses on the others. Live FGLGuard cuts AgentDojo's ground-truth attack-success rate by 43% at near-unguarded utility, zero API cost, and negligible capability loss.