{"id":"https://openalex.org/W7160938716","doi":"https://doi.org/10.48550/arxiv.2605.10481","title":"Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems","display_name":"Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems","publication_year":2026,"publication_date":"2026-05-11","ids":{"openalex":"https://openalex.org/W7160938716","doi":"https://doi.org/10.48550/arxiv.2605.10481"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.10481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.10481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.10481","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100689729","display_name":"Tianxiao Li","orcid":"https://orcid.org/0000-0002-8789-6000"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Tianxiao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135935298","display_name":"Yixing Ma","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ma, Yixing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135956267","display_name":"Haiquan Wen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wen, Haiquan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135950649","display_name":"Zhenglin Huang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Huang, Zhenglin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031210225","display_name":"Qianyu Zhou","orcid":"https://orcid.org/0000-0002-5331-050X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Qianyu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135994573","display_name":"Zeyu Fu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fu, Zeyu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5045854934","display_name":"Guangliang Cheng","orcid":"https://orcid.org/0000-0002-1428-8848"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cheng, Guangliang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10456","display_name":"Multi-Agent Systems and Negotiation","score":0.8151000142097473,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10456","display_name":"Multi-Agent Systems and Negotiation","score":0.8151000142097473,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11010","display_name":"Logic, Reasoning, and Knowledge","score":0.06679999828338623,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10906","display_name":"AI-based Problem Solving and Planning","score":0.014499999582767487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/constraint","display_name":"Constraint (computer-aided design)","score":0.7875000238418579},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.6104000210762024},{"id":"https://openalex.org/keywords/position","display_name":"Position (finance)","score":0.4699000120162964},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.44999998807907104},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.4325000047683716},{"id":"https://openalex.org/keywords/corporate-governance","display_name":"Corporate governance","score":0.33379998803138733},{"id":"https://openalex.org/keywords/relaxation","display_name":"Relaxation (psychology)","score":0.33000001311302185}],"concepts":[{"id":"https://openalex.org/C2776036281","wikidata":"https://www.wikidata.org/wiki/Q48769818","display_name":"Constraint (computer-aided design)","level":2,"score":0.7875000238418579},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6280999779701233},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.6104000210762024},{"id":"https://openalex.org/C198082294","wikidata":"https://www.wikidata.org/wiki/Q3399648","display_name":"Position (finance)","level":2,"score":0.4699000120162964},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.44999998807907104},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.4325000047683716},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.4251999855041504},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4065999984741211},{"id":"https://openalex.org/C39389867","wikidata":"https://www.wikidata.org/wiki/Q380767","display_name":"Corporate governance","level":2,"score":0.33379998803138733},{"id":"https://openalex.org/C2776029896","wikidata":"https://www.wikidata.org/wiki/Q3935810","display_name":"Relaxation (psychology)","level":2,"score":0.33000001311302185},{"id":"https://openalex.org/C42259789","wikidata":"https://www.wikidata.org/wiki/Q1392940","display_name":"Fail-safe","level":2,"score":0.3095000088214874},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.2928999960422516},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.2888999879360199},{"id":"https://openalex.org/C8505890","wikidata":"https://www.wikidata.org/wiki/Q605095","display_name":"Budget constraint","level":2,"score":0.28529998660087585},{"id":"https://openalex.org/C2779795794","wikidata":"https://www.wikidata.org/wiki/Q7315343","display_name":"Reset (finance)","level":2,"score":0.25609999895095825},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.25519999861717224},{"id":"https://openalex.org/C31084985","wikidata":"https://www.wikidata.org/wiki/Q372650","display_name":"Common knowledge (logic)","level":5,"score":0.25099998712539673}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.10481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.10481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.10481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.10481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"sustainable_development_goals":[{"score":0.7886170744895935,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Modern":[0],"LLM":[1],"based":[2],"agents":[3,228],"are":[4,155,159,189],"no":[5],"longer":[6],"passive":[7],"text":[8],"generators.":[9],"They":[10],"read":[11],"repositories,":[12],"call":[13,105],"tools,":[14],"browse":[15],"the":[16,35,70,102,110,223],"web,":[17],"execute":[18],"code,":[19],"maintain":[20],"memory,":[21,122],"communicate":[22],"with":[23,65],"other":[24],"agents,":[25],"and":[26,128,151,167],"act":[27],"through":[28,51,121,225],"long":[29],"horizon":[30],"workflows.":[31],"This":[32],"shift":[33],"moves":[34],"unit":[36],"of":[37,116],"safety.":[38],"A":[39],"system":[40],"may":[41],"produce":[42],"a":[43,91,177],"compliant":[44],"final":[45,152],"answer":[46],"while":[47,195],"leaking":[48],"private":[49],"information":[50],"an":[52,62,76],"internal":[53],"message,":[54],"delegating":[55],"authority":[56],"beyond":[57],"its":[58],"original":[59],"scope,":[60],"calling":[61],"external":[63],"tool":[64,125,147],"sensitive":[66],"context,":[67],"or":[68,114],"losing":[69],"evidence":[71],"needed":[72],"to":[73,210,218],"reconstruct":[74],"why":[75],"action":[77],"was":[78],"allowed.":[79],"We":[80,104,171],"argue":[81],"that":[82,135],"many":[83],"emerging":[84],"failures":[85],"in":[86],"LLM-based":[87,181],"multi-agent":[88,137,182],"systems":[89,213],"share":[90],"common":[92],"structure:":[93],"safety":[94,204,220],"critical":[95],"constraints":[96,117,162,188],"do":[97],"not":[98,142,209],"remain":[99,163],"operative":[100],"throughout":[101],"trajectory.":[103],"this":[106,185],"phenomenon":[107],"constraint":[108],"drift:":[109],"loss,":[111],"distortion,":[112],"weakening,":[113],"relaxation":[115],"as":[118,176,191],"they":[119,158],"pass":[120],"delegation,":[123],"communication,":[124],"use,":[126],"audit,":[127],"optimization.":[129],"The":[130,206],"position":[131],"taken":[132],"here":[133],"is":[134,208],"safe":[136],"behavior":[138],"must":[139],"be":[140],"maintained,":[141],"merely":[143],"asserted.":[144],"Prompts,":[145],"guardrails,":[146],"schemas,":[148],"access":[149],"control,":[150],"output":[153],"checks":[154],"necessary,":[156],"but":[157,217],"insufficient":[160],"unless":[161],"fresh,":[164],"inherited,":[165],"enforceable,":[166],"auditable":[168],"across":[169,222],"execution.":[170],"propose":[172],"Constraint":[173],"State":[174],"Governance":[175],"research":[178],"paradigm":[179],"for":[180],"systems.":[183],"In":[184],"paradigm,":[186],"safety-critical":[187],"maintained":[190,203],"explicit":[192],"execution":[193],"state,":[194],"constraint-native":[196],"reinforcement":[197],"learning":[198],"improves":[199],"utility":[200],"only":[201],"within":[202],"boundaries.":[205],"goal":[207],"freeze":[211],"agentic":[212],"under":[214],"rigid":[215],"rules,":[216],"make":[219],"operational":[221],"trajectories":[224],"which":[226],"modern":[227],"actually":[229],"act.":[230]},"counts_by_year":[{"year":2026,"cited_by_count":3}],"updated_date":"2026-07-01T06:00:48.157686","created_date":"2026-05-13T00:00:00"}
