MedSentry: Understanding and Mitigating Safety Risks in Medical LLM Multi-Agent Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Kai, Zhen, Taihang, Wang, Hewei, Liu, Kailai, Li, Xinfeng, Huo, Jing, Yang, Tianpei, Xu, Jinfeng, Dong, Wei, Gao, Yang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916761701449728
author Chen, Kai
Zhen, Taihang
Wang, Hewei
Liu, Kailai
Li, Xinfeng
Huo, Jing
Yang, Tianpei
Xu, Jinfeng
Dong, Wei
Gao, Yang
author_facet Chen, Kai
Zhen, Taihang
Wang, Hewei
Liu, Kailai
Li, Xinfeng
Huo, Jing
Yang, Tianpei
Xu, Jinfeng
Dong, Wei
Gao, Yang
contents As large language models (LLMs) are increasingly deployed in healthcare, ensuring their safety, particularly within collaborative multi-agent configurations, is paramount. In this paper we introduce MedSentry, a benchmark comprising 5 000 adversarial medical prompts spanning 25 threat categories with 100 subthemes. Coupled with this dataset, we develop an end-to-end attack-defense evaluation pipeline to systematically analyze how four representative multi-agent topologies (Layers, SharedPool, Centralized, and Decentralized) withstand attacks from 'dark-personality' agents. Our findings reveal critical differences in how these architectures handle information contamination and maintain robust decision-making, exposing their underlying vulnerability mechanisms. For instance, SharedPool's open information sharing makes it highly susceptible, whereas Decentralized architectures exhibit greater resilience thanks to inherent redundancy and isolation. To mitigate these risks, we propose a personality-scale detection and correction mechanism that identifies and rehabilitates malicious agents, restoring system safety to near-baseline levels. MedSentry thus furnishes both a rigorous evaluation framework and practical defense strategies that guide the design of safer LLM-based multi-agent systems in medical domains.
format Preprint
id arxiv_https___arxiv_org_abs_2505_20824
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MedSentry: Understanding and Mitigating Safety Risks in Medical LLM Multi-Agent Systems
Chen, Kai
Zhen, Taihang
Wang, Hewei
Liu, Kailai
Li, Xinfeng
Huo, Jing
Yang, Tianpei
Xu, Jinfeng
Dong, Wei
Gao, Yang
Multiagent Systems
Artificial Intelligence
As large language models (LLMs) are increasingly deployed in healthcare, ensuring their safety, particularly within collaborative multi-agent configurations, is paramount. In this paper we introduce MedSentry, a benchmark comprising 5 000 adversarial medical prompts spanning 25 threat categories with 100 subthemes. Coupled with this dataset, we develop an end-to-end attack-defense evaluation pipeline to systematically analyze how four representative multi-agent topologies (Layers, SharedPool, Centralized, and Decentralized) withstand attacks from 'dark-personality' agents. Our findings reveal critical differences in how these architectures handle information contamination and maintain robust decision-making, exposing their underlying vulnerability mechanisms. For instance, SharedPool's open information sharing makes it highly susceptible, whereas Decentralized architectures exhibit greater resilience thanks to inherent redundancy and isolation. To mitigate these risks, we propose a personality-scale detection and correction mechanism that identifies and rehabilitates malicious agents, restoring system safety to near-baseline levels. MedSentry thus furnishes both a rigorous evaluation framework and practical defense strategies that guide the design of safer LLM-based multi-agent systems in medical domains.
title MedSentry: Understanding and Mitigating Safety Risks in Medical LLM Multi-Agent Systems
topic Multiagent Systems
Artificial Intelligence
url https://arxiv.org/abs/2505.20824