Header image

Session 3.3b Update: Poisoning the Hive Mind: Manipulating and Defending A2A Inference at the Tactical Edge

Tracks
Thursday, November 19, 2026
10:30 AM - 11:30 AM
Bradman Theatre

Presentation Outline

Agentic AI at the tactical edge depends on something fragile: the stream of inference and intent that nodes exchange to coordinate. As cheap microcontrollers begin running on-board agents that consult reasoning models and act on local hardware, this agent-to-agent (A2A) channel becomes the swarm's nervous system, and its highest-value attack surface. The instinctive defence, encrypting the channel, is necessary but structurally insufficient: encryption secures the pipe between nodes, while the threat is increasingly the nodes themselves. A compromised but properly authenticated endpoint emits perfectly encrypted manipulation. This presentation treats manipulation of inference streams as a distinct class of counter-autonomy: degrading, neutralising or redirecting a swarm by attacking its cognition rather than its airframe. Drawing on hands-on red-team research, it demonstrates the threat on a low-cost edge testbed, intercepting and altering A2A traffic to subvert coordinated behaviour, then turns that evidence into defence. Building on emerging multi-agent monitoring research and agentic-identity practice, the proposed answer is out-of-band, behavioural AAA applied to A2A: independent authentication, least-privilege authorisation with real-time revocation, and tamper-evident accounting a compromised node cannot forge. The contribution is what breaks when this enterprise pattern meets the military edge, and how to fix it: assurance that runs on cheap hardware, and authorisation that decides locally with no link home. Live experiments show the assurance layer detecting and containing manipulation under denied-comms conditions. As agentic swarms are fielded, the coordination layer becomes the centre of gravity for both attack and defence, and integrity assurance must be designed in, not bolted on.


Speaker

Agenda Item Image
Mr Paul Nevin
Principal Consultant
Guruswami Advisory

Biography

Paul Nevin has spent thirty years at the intersection of national security, cyber intelligence and applied AI, specialising in counter cyber espionage and the offensive use of AI by state-sponsored and criminal actors. His career has run from enterprise security architecture through senior government and defence roles into independent advisory and adversarial AI research. His current work is hands-on red-team research into agentic AI: he builds autonomous offensive agents, studies how they reason and develop attack strategy, and from that designs the defences. He has demonstrated both offensive and defensive agentic systems to senior Australian defence and government officials, and his recurring finding is that AI-assisted threats already outpace both human analysts and AI defenders under current architectures. He runs Guruswami Advisory, a vendor-neutral AI security and strategy practice, and participates in research into emerging AI centric threats.
loading