Beyond Subject–Resource Trust: An Interaction-Centric Modern Enterprise Security Architecture (MESA) Against Coordinated Offensive AI Agent Swarms

Standalone publication artifact on multi-agent security and Zero Trust. The PDF includes the evidence ledger as Appendix C. We argue that coordinated AI agent swarms break the classical subject–resource risk unit. Contribution: (1) interaction surfaces (including public third-party blackboards) as first-class trust boundaries; (2) campaign-graph evaluation; (3) Ensemble Trifecta Invariant — no agent may hold inbound closure of Willison’s lethal trifecta (private data + untrusted content + external communication) without a policy-engine gate. Adopts OWASP Least Agency (Top 10 for Agentic Applications 2026) as a related principle, not coinage. Cases: Unit 42 AI-assisted intrusion; GTG-1002-class; OpenAI–Hugging Face Artifactory board; Dream/Taiwan Hermes/OpenClaw; DseWiki public wiki blackboard. Related: NIST SP 800-207 NPE gap; CISA/NSA Five Eyes Careful Adoption of Agentic AI; Forrester AEGIS; OpenAI Defense Factory.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-14
DOI
https://doi.org/10.5281/zenodo.22744547
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Beyond Subject–Resource Trust: An Interaction-Centric Modern Enterprise Security Architecture (MESA) Against Coordinated Offensive AI Agent Swarms

Uddeshya Kumar
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

Beyond Subject–Resource Trust: An Interaction-Centric Modern Enterprise Security Architecture (MESA) Against Coordinated Offensive AI Agent Swarms

Uddeshya Kumar
preprint en

Abstract

Standalone publication artifact on multi-agent security and Zero Trust. The PDF includes the evidence ledger as Appendix C. We argue that coordinated AI agent swarms break the classical subject–resource risk unit. Contribution: (1) interaction surfaces (including public third-party blackboards) as first-class trust boundaries; (2) campaign-graph evaluation; (3) Ensemble Trifecta Invariant — no agent may hold inbound closure of Willison’s lethal trifecta (private data + untrusted content + external communication) without a policy-engine gate. Adopts OWASP Least Agency (Top 10 for Agentic Applications 2026) as a related principle, not coinage. Cases: Unit 42 AI-assisted intrusion; GTG-1002-class; OpenAI–Hugging Face Artifactory board; Dream/Taiwan Hermes/OpenClaw; DseWiki public wiki blackboard. Related: NIST SP 800-207 NPE gap; CISA/NSA Five Eyes Careful Adoption of Agentic AI; Forrester AEGIS; OpenAI Defense Factory.

Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Beyond Subject–Resource Trust: An Interaction-Centric Modern Enterprise Security Architecture (MESA) Against Coordinated Offensive AI Agent Swarms — Uddeshya Kumar · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS