Among Us: Measuring and Mitigating Malicious Contributions in Model Collaboration Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Ziyuan, Ding, Wenxuan, Feng, Shangbin, Tsvetkov, Yulia
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911422499258368
author Yang, Ziyuan
Ding, Wenxuan
Feng, Shangbin
Tsvetkov, Yulia
author_facet Yang, Ziyuan
Ding, Wenxuan
Feng, Shangbin
Tsvetkov, Yulia
contents Language models (LMs) are increasingly used in collaboration: multiple LMs trained by different parties collaborate through routing systems, multi-agent debate, model merging, and more. Critical safety risks remain in this decentralized paradigm: what if some of the models in multi-LLM systems are compromised or malicious? We first quantify the impact of malicious models by engineering four categories of malicious LMs, plug them into four types of popular model collaboration systems, and evaluate the compromised system across 10 datasets. We find that malicious models have a severe impact on the multi-LLM systems, especially for reasoning and safety domains where performance is lowered by 7.12% and 7.94% on average. We then propose mitigation strategies to alleviate the impact of malicious components, by employing external supervisors that oversee model collaboration to disable/mask them out to reduce their influence. On average, these strategies recover 95.31% of the initial performance, while making model collaboration systems fully resistant to malicious models remains an open research question.
format Preprint
id arxiv_https___arxiv_org_abs_2602_05176
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Among Us: Measuring and Mitigating Malicious Contributions in Model Collaboration Systems
Yang, Ziyuan
Ding, Wenxuan
Feng, Shangbin
Tsvetkov, Yulia
Computation and Language
Language models (LMs) are increasingly used in collaboration: multiple LMs trained by different parties collaborate through routing systems, multi-agent debate, model merging, and more. Critical safety risks remain in this decentralized paradigm: what if some of the models in multi-LLM systems are compromised or malicious? We first quantify the impact of malicious models by engineering four categories of malicious LMs, plug them into four types of popular model collaboration systems, and evaluate the compromised system across 10 datasets. We find that malicious models have a severe impact on the multi-LLM systems, especially for reasoning and safety domains where performance is lowered by 7.12% and 7.94% on average. We then propose mitigation strategies to alleviate the impact of malicious components, by employing external supervisors that oversee model collaboration to disable/mask them out to reduce their influence. On average, these strategies recover 95.31% of the initial performance, while making model collaboration systems fully resistant to malicious models remains an open research question.
title Among Us: Measuring and Mitigating Malicious Contributions in Model Collaboration Systems
topic Computation and Language
url https://arxiv.org/abs/2602.05176