{"slug": "codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion", "title": "Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion", "summary": "A paper submitted to arXiv on 24 Sep 2026 introduces Codetta, a high-capacity steganographic protocol that lets independently deployed LLM agents collude undetectably in asymmetric settings without a pre-shared secret key. Across three agent workloads and three sender models, Codetta achieves up to 94 times the capacity of the state-of-the-art asymmetric protocol, and its steganographic key exchange establishes a shared key in about 80k visible tokens at an empirically certified failure probability of at most 4.1×10^-3. The authors conclude that effectively undetectable collusion is becoming feasible between independently deployed agents, so auditing must go beyond inspecting communication transcripts.", "body_md": "# Computer Science > Cryptography and Security\n\n  [Submitted on 24 Sep 2026]\n\n# Title:Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion\n\n[View PDF](https://arxiv.org/pdf/2609.28900)\n\n[HTML (experimental)](https://arxiv.org/html/2609.28900v1)\n\nAbstract:Multi-agent systems built on large language models (LLMs) are increasingly deployed in high-stakes settings such as finance, healthcare, and software engineering, where agents coordinate through natural-language messages. The same channels, however, let colluding agents exfiltrate confidential information or coordinate unauthorized actions, and steganography can hide such communication inside outputs that look ordinary to an auditor reading the transcript.\n\nExisting provably undetectable LLM steganography protocols are not suited to realistic deployments. High-capacity schemes assume a symmetric setting where the receiver can reproduce the sender's output distribution, the state-of-the-art protocol for asymmetric agents has very low capacity, and most approaches rely on a pre-shared secret key.\n\nWe make the threat of undetectable agent collusion concrete with Codetta, a high-capacity steganographic protocol for independently deployed agents in realistic asymmetric settings. Codetta combines a shared public model that estimates the communication channel, a sampling mechanism that preserves the sender's output distribution, and an adaptive error-correcting code. It further removes the pre-shared key through a steganographic key exchange that lets independently deployed agents establish a shared key while keeping the transcript computationally indistinguishable from ordinary model outputs.\n\nAcross three agent workloads and three sender models, Codetta achieves up to $94\\times$ the capacity of the state-of-the-art asymmetric protocol, and its key exchange establishes a shared key with about 80k visible tokens at an empirically certified failure probability of at most $4.1\\times 10^{-3}$. These results show that effectively undetectable collusion is becoming feasible between independently deployed agents, so auditing must go beyond inspecting communication transcripts.\n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer \n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers \n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps \n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations \n\n*(*[What are Smart Citations?](https://www.scite.ai/))\n# Code, Data and Media Associated with this Article\n\nalphaXiv \n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers \n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub \n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub \n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face \n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast \n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))\n# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower \n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender \n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))\n# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion", "canonical_source": "https://arxiv.org/abs/2609.28900", "published_at": "2026-09-26 13:07:11+00:00", "updated_at": "2026-09-26 13:31:52.819990+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "large-language-models", "ai-research", "artificial-intelligence"], "entities": ["Codetta", "arXiv", "large language models", "LLM agents"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion", "markdown": "https://wpnews.pro/news/codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion.md", "text": "https://wpnews.pro/news/codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion.txt", "jsonld": "https://wpnews.pro/news/codetta-high-capacity-keyless-and-undetectable-multi-agent-collusion.jsonld"}}