cs.CROct 6, 2026

SwarmReconGuard: Black-Box Detection of Distributed Collective Reconnaissance by Individually Benign-Looking Agent Populations

Authors: Vahid Tavakkoli, Kabeh Mohsenzadegan, Kyandoghere Kyamakya

Organizations: Institute for Smart System Technologies, University of Klagenfurt, Klagenfurt, Austria

Abstract

Autonomous and agentic clients can distribute reconnaissance across many identities so that each request remains valid, low-rate, and benign-looking while the population collectively acquires broad system knowledge. We formalize this threat as Distributed Collective Reconnaissance (DCR) and present SwarmReconGuard, a reproducible black-box benchmark in which the defender observes only service-boundary telemetry. The Docker-isolated study evaluates 11 benign and attack behaviors across 10-10,000 virtual identities, comprising 440 test runs and 3,666,300 requests, with complete telemetry integrity. We compare semantic, Gaussian, conditional, graph, kernel, hybrid, and CUSUM-based detectors. Gaussian likelihood-ratio detection achieves 100%\% detection with 0%\% observed false positives on known attacks but only 3%\% on unseen policies. CUSUM yields 36.1%\% overall detection at 1.25%\% false positives, while hybrid CUSUM reaches 85.7%\% detection with 0%\% observed false positives at 10,000 identities. Results expose a major policy-generalization gap and motivate exposure-aware, scale-aware defenses.

Figures & tables

Explore similar work

CardsList
  1. Stateful Online Monitoring Catches Distributed Agent Attacks

    May 29, 2026Davis Brown, Samarth Bhargav, Arav Santhanam +7Diverse AttacksCybersecurity

  2. Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents

    Jul 22, 2026Or Zion Eliav, Eyal Lenga, Shir Bernstien +1Penetration TestingArtificial Intelligence Agents

  3. Towards Optimal Agentic Architectures for Offensive Security Tasks

    Apr 20, 2026Isaac David, Arthur GervaisTopology