Beyond Subject–Resource Trust: An Interaction-Centric Modern Enterprise Security Architecture (MESA) Against Coordinated Offensive AI Agent Swarms
Working paper on multi-agent security and Zero Trust. We argue that coordinated AI agent swarms break the classical subject–resource risk unit. Contribution: (1) interaction surfaces (including public third-party blackboards) as first-class trust boundaries; (2) campaign-graph evaluation; (3) Ensemble Trifecta Invariant — no agent may hold inbound closure of Willison’s lethal trifecta (private data + untrusted content + external communication) without a policy-engine gate. Adopts OWASP Least Agency (Top 10 for Agentic Applications 2026) as a related principle, not coinage. Cases: Unit 42 AI-assisted intrusion; GTG-1002-class; OpenAI–Hugging Face Artifactory board; Dream/Taiwan Hermes/OpenClaw; DseWiki public wiki blackboard. Related: NIST SP 800-207 NPE gap; CISA/NSA Five Eyes Careful Adoption of Agentic AI; Forrester AEGIS; OpenAI Defense Factory.
Authors
- Uddeshya Kumar
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-14
- DOI
- https://doi.org/10.5281/zenodo.22743176
- Primary Topic
- Access Control and Trust
- Type
- preprint