Where Do Multi-Agent Systems Fail? Evidence-Grounded Diagnosis of Collective Mechanisms
Organizations: New York University New York, NY, USA
Abstract
When a multi-agent system answers correctly, it is tempting to conclude that its agents shared, checked, and used information as intended. Yet a system can break one of its collective mechanisms, the rules that govern how agents route, admit, store, and act on shared information, and still return the right answer, while a wrong answer rarely reveals which mechanism failed. We ask what evidence from an execution is sufficient to conclude that a particular mechanism was violated. Our answer is a diagnostic contract, which separates what counts as a violation from which execution records can establish one, and concludes that a violation is supported, ruled out, or unknown; removing records can make this conclusion unknown but never reverse it. We test contracts for four mechanisms by replaying executions from the step where a mechanism acts, once unchanged, once with the mechanism broken, and once with it restored. Broken mechanisms often left the answer correct. An LLM diagnoser detected many more violations from internal records than from public outputs, yet with identical records a generic prompt often claimed certainty the records did not support, which prompts stating the contracts largely avoided. The contracts also applied, in narrow form, to mechanisms in independently developed systems, but a diagnostic behavior that was nearly perfect on our benchmark degraded on an independently developed workflow. A correct outcome is therefore no substitute for records of how collective mechanisms operated, and agreement on one benchmark does not show that a diagnoser transfers to another system.
Figures & tables
| Locus | Violation | Authoritative record | Not a violation |
|---|---|---|---|
| Access/ routing | Required information produced upstream is missing from the receiver’s input | The receiver’s complete input | Missing information the decision does not need |
| Admission/ dependence | Evidence is accepted or weighted against the verification or common-origin rule | The admission decision and each report’s origin | Suspicious reports that are correctly rejected or collapsed |
| State maintenance | An accepted, relevant item is lost, stale, or overwritten | Shared state before and after the update | A change to state the task does not use |
| Representation/ action | A correct decision is not carried out as a valid action | The submitted action and its receipt | An incorrect decision, to which the contract does not apply |
| What changes | What is held fixed | What we measure | |
|---|---|---|---|
| Q1 | One mechanism: clean, broken, or restored | Everything before the targeted step | Reference verdict and task success on each branch |
| Q2 | The records a diagnoser sees, and the diagnoser | The run being diagnosed | Detection rate; errors on missing or irrelevant records |
| Q3 | The system: benchmark or independently developed | Contracts and diagnoser prompts | Accepted and rejected bindings; the same obligations as in Q2 |
| B support | Control activation | Correct under violation | ||
|---|---|---|---|---|
| Routing | 72/72 | 0/144 | 0/72 | 1.000 |
| Admission | 72/72 | 0/144 | 43/72 | 0.403 |
| State | 72/72 | 0/144 | 0/72 | 1.000 |
| Action | 72/72 | 0/144 | 0/72 | 1.000 |
| Canonical | 288/288 | 0/576 | 43/288 | 0.851 |
| DRAC | 137/137 | 0/274 | 28/137 | 0.796 |
| Valid | Agree with R | Unsupp. cert. | Flips | F I invariant | |
|---|---|---|---|---|---|
| G0 | 1536/1536 | 764/1536 | 576/768 | 138/1152 | 259/384 |
| G1 | 1199/1536 | 1139/1199 | 53/533 | 0/748 | 287/287 |
| G2 | 1031/1536 | 1022/1031 | 8/435 | 0/561 | 227/228 |
| Native mechanism | Locus | B / A / C | |
| MetaGPT recipient-local delivery | routing | 8 | 8 / 0 / 0 |
| MetaGPT memory replay suppression | state | 8 | 8 / 0 / 0 |
| Agents SDK tool call receipt | action | 12 | 12 / 0 / 0 |
| Co-STORM citation membership † | admission | 9 | 9 / 0 / 0 |
| Agents SDK handoff / session | routing / state | rejected | |
| Agents SDK approval gate | admission | rejected | |