Back to all publications
Agent Bounds·August 2026·11 min read·10.48550/arXiv.2608.09412

Dynamic Safety Envelopes for Autonomous Agent Swarms

Lennox Safety Division
Autonomous Systems & Formal Verification Group · London, UK
INVARIANT BOUNDARY [?_state < ?]
Figure 2.0 · State-Space Invariant Envelopes
Abstract & Executive Summary

"When frontier models are granted execution tools, shell environments, and multi-agent coordination channels, non-deterministic state space divergence becomes a critical hazard. This paper proves mathematical state-space invariants that bound agent execution paths, guaranteeing containment even under distributed prompt injection and coordination collapse."

10,000+
Simulated Swarm Scenarios
100.0%
Containment Guarantee
99.8%
Benign Task Throughput
42ms
Recovery Mean Time

Key Scientific Findings

  • 01.Mathematical invariant model for multi-agent tool execution in live environments
  • 02.Formal proof of containment across 10,000 simulated adversarial swarms
  • 03.Zero degradation on benign workflow completion rates in production benchmarks
  • 04.Deterministic state rollback protocol integrated with Linux kernel cgroups

1. The Autonomous Execution Dilemma

Autonomous agents operating in production environments manipulate databases, execute code, and communicate across distributed networks. While individual actions may appear harmless in isolation, complex compositions of actions frequently lead to unsafe emergent states.

Traditional access control lists (ACLs) and static role permissions are insufficient because they lack semantic awareness of agent intent. A compromised or misaligned agent can achieve malicious objectives entirely through legitimate API calls.

2. State-Space Invariant Envelopes

We propose Dynamic Safety Envelopes (DSE). Instead of restricting individual API calls, DSE continuously tracks the global state derivative of the execution environment.

We define formal mathematical invariants over database integrity, compute expenditure, network entropy, and privilege boundaries. If the projected next-step trajectory of an agent swarm violates an invariant envelope, the sandbox freezes execution within 42ms and reverts state transactions.

3. Adversarial Stress Testing

We subjected DSE to 10,000 adversarial swarm scenarios, including collusive multi-agent prompt injections and distributed resource exhaustion attacks.

In every tested scenario, the dynamic envelope successfully contained the attack without requiring human intervention, while maintaining normal completion rates across 99.8% of benign business workflows.

Lennox Digital Frontier Research Archive
Distributed under Creative Commons CC-BY 4.0 · London Laboratory
10.48550/arXiv.2608.09412