# Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion

> Source: <https://arxiv.org/abs/2609.28900>
> Published: 2026-09-26 13:07:11+00:00

# Computer Science > Cryptography and Security

  [Submitted on 24 Sep 2026]

# Title:Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion

[View PDF](https://arxiv.org/pdf/2609.28900)

[HTML (experimental)](https://arxiv.org/html/2609.28900v1)

Abstract:Multi-agent systems built on large language models (LLMs) are increasingly deployed in high-stakes settings such as finance, healthcare, and software engineering, where agents coordinate through natural-language messages. The same channels, however, let colluding agents exfiltrate confidential information or coordinate unauthorized actions, and steganography can hide such communication inside outputs that look ordinary to an auditor reading the transcript.

Existing provably undetectable LLM steganography protocols are not suited to realistic deployments. High-capacity schemes assume a symmetric setting where the receiver can reproduce the sender's output distribution, the state-of-the-art protocol for asymmetric agents has very low capacity, and most approaches rely on a pre-shared secret key.

We make the threat of undetectable agent collusion concrete with Codetta, a high-capacity steganographic protocol for independently deployed agents in realistic asymmetric settings. Codetta combines a shared public model that estimates the communication channel, a sampling mechanism that preserves the sender's output distribution, and an adaptive error-correcting code. It further removes the pre-shared key through a steganographic key exchange that lets independently deployed agents establish a shared key while keeping the transcript computationally indistinguishable from ordinary model outputs.

Across three agent workloads and three sender models, Codetta achieves up to $94\times$ the capacity of the state-of-the-art asymmetric protocol, and its key exchange establishes a shared key with about 80k visible tokens at an empirically certified failure probability of at most $4.1\times 10^{-3}$. These results show that effectively undetectable collusion is becoming feasible between independently deployed agents, so auditing must go beyond inspecting communication transcripts.

### References & Citations

Loading...

# Bibliographic and Citation Tools

Bibliographic Explorer 

*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))
Connected Papers 

*(*[What is Connected Papers?](https://www.connectedpapers.com/about))
Litmaps 

*(*[What is Litmaps?](https://www.litmaps.co/))
scite Smart Citations 

*(*[What are Smart Citations?](https://www.scite.ai/))
# Code, Data and Media Associated with this Article

alphaXiv 

*(*[What is alphaXiv?](https://alphaxiv.org/))
CatalyzeX Code Finder for Papers 

*(*[What is CatalyzeX?](https://www.catalyzex.com))
DagsHub 

*(*[What is DagsHub?](https://dagshub.com/))
Gotit.pub 

*(*[What is GotitPub?](http://gotit.pub/faq))
Hugging Face 

*(*[What is Huggingface?](https://huggingface.co/huggingface))
ScienceCast 

*(*[What is ScienceCast?](https://sciencecast.org/welcome))
# Demos

# Recommenders and Search Tools

Influence Flower 

*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))
CORE Recommender 

*(*[What is CORE?](https://core.ac.uk/services/recommender))
# arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? [**Learn more about arXivLabs**](https://info.arxiv.org/labs/index.html).
