Shattered Intent: Payload Sharding Attacks on Multi-Agent LLM Systems
Shuo Ji ⋅ Junfeng Fang ⋅ Bryan Hooi
Abstract
Multi-agent systems (MAS) decompose complex tasks across specialized agents, with each agent accessing only the inputs assigned to its role. We show that this structure creates a vulnerability we term \emph{payload sharding}, where a malicious payload is split into individually benign shards distributed across agents. We instantiate the attack as \textsc{Mosaic}, which decomposes a payload along intent, logic, and target boundaries aligned with the plan-code-execute workflow of code-generating MAS. Shards are synthesized by an iterative procedure that generates a cover context, decouples logic from sensitive parameters, and verifies via LLM auditing and static analysis that each shard appears benign in isolation. \textsc{Mosaic} achieves $92.9\%$ ASR across five LLMs and five MAS architectures, exceeding the strongest prior attack by $14.9\%$. Under defenses, it retains $77.8\%$ ASR against LlamaFirewall and $63.0\%$ against LLM-based cross-artifact auditing.
Chat is not available.
Successful Page Load