Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across LLM Agents
TL;DR - This paper formalizes attribution of asynchronous attacks spanning independent LLM agents and introduces A²FV, a proxy-side fingerprinting protocol. It matters because session-level defenses can miss distributed adversarial campaigns.
- A²FV compares proxy-observable tool use, timing, and prompt residue without shared runtime state or attacker identities.
- The authors introduce SCD-v1, covering benign traffic, isolated attacks, multi-session campaigns, evasion, and leakage audits.
- A²FV achieves 0.82 pairwise AUC; adapted session detectors and chunked LLM judges perform near chance.
- Structural and stylometric residue provides the strongest signal, with separability persisting under controlled evasion tests.