SwarmGov-ZT: Zero-Trust Runtime Governance for Trust-Aware Multi-Agent Cybersecurity Response

Tool-capable multi-agent systems can improve cybersecurity response, but collaboration also creates new failure modes: compromised agents can bias shared evidence, overconfident recommendations can propagate through a coalition, and apparently correct reasoning can still trigger unauthorized tools. This paper presents SwarmGov-ZT, a zero-trust runtime-governance framework that separates evidential trust from operational authority through identity-bound capability manifests, mission-scoped authorization, outcome-updated trust, evidence-weighted fusion, a governance risk score (GRS), a non-bypassable policy enforcement point (PEP), human approval thresholds, and append-only decision traces. The framework was evaluated in a controlled simulator using 30 fixed seeds and 4000 missions per seed (120,000 default-condition missions), with 25% compromised agents by default. In the final experiment, SwarmGov-ZT achieved 91.08% exact four-class governance-decision accuracy (95% CI half-width 0.17 percentage points), 92.83% macro-F1, and 93.91% policy compliance, while limiting policy violations to 6.09% and false mitigation to 2.83%. Relative to an equal-sized non-governed swarm, exact accuracy increased by 11.41 percentage points (paired dz = 9.93; one-sided Wilcoxon W = 465, p = 8.66 × 1. Per-class F1 scores were 91.84% for Permit, 89.31% for Modify, 91.08% for Escalate, and 99.11% for Deny. Under a 50% compromised-agent stress condition, exact accuracy remained 87.88%. Ablation results show that dynamic trust and hard governance rules provide the main measurable gains, whereas evidence weighting has a negligible marginal effect under the present synthetic evidence-quality distribution. These results support controlled mechanism feasibility and reproducibility under the stated simulator assumptions; they do not establish production-SOC or natural-language prompt-injection robustness.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-09-30
DOI
https://doi.org/10.3390/computers15100662
Primary Topic
Access Control and Trust
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

SwarmGov-ZT: Zero-Trust Runtime Governance for Trust-Aware Multi-Agent Cybersecurity Response

Pao Tsang-Long, Yu‐Cheng Kao, Wei-Yu Chen
Computers
Access Control and Trust
article

SwarmGov-ZT: Zero-Trust Runtime Governance for Trust-Aware Multi-Agent Cybersecurity Response

Pao Tsang-Long, Yu‐Cheng Kao, Wei-Yu Chen
article en

Abstract

Tool-capable multi-agent systems can improve cybersecurity response, but collaboration also creates new failure modes: compromised agents can bias shared evidence, overconfident recommendations can propagate through a coalition, and apparently correct reasoning can still trigger unauthorized tools. This paper presents SwarmGov-ZT, a zero-trust runtime-governance framework that separates evidential trust from operational authority through identity-bound capability manifests, mission-scoped authorization, outcome-updated trust, evidence-weighted fusion, a governance risk score (GRS), a non-bypassable policy enforcement point (PEP), human approval thresholds, and append-only decision traces. The framework was evaluated in a controlled simulator using 30 fixed seeds and 4000 missions per seed (120,000 default-condition missions), with 25% compromised agents by default. In the final experiment, SwarmGov-ZT achieved 91.08% exact four-class governance-decision accuracy (95% CI half-width 0.17 percentage points), 92.83% macro-F1, and 93.91% policy compliance, while limiting policy violations to 6.09% and false mitigation to 2.83%. Relative to an equal-sized non-governed swarm, exact accuracy increased by 11.41 percentage points (paired dz = 9.93; one-sided Wilcoxon W = 465, p = 8.66 × 1. Per-class F1 scores were 91.84% for Permit, 89.31% for Modify, 91.08% for Escalate, and 99.11% for Deny. Under a 50% compromised-agent stress condition, exact accuracy remained 87.88%. Ablation results show that dynamic trust and hard governance rules provide the main measurable gains, whereas evidence weighting has a negligible marginal effect under the present synthetic evidence-quality distribution. These results support controlled mechanism feasibility and reproducibility under the stated simulator assumptions; they do not establish production-SOC or natural-language prompt-injection robustness.

ComputersVol. 15(10)
Chinese Culture University (TW), Tatung University (TW)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.