HIVE — Population-level security for autonomous systems
HIVE Open the live console
A new security category

Security for what happens between agents.

HIVE detects, investigates and contains dangerous behavior emerging from autonomous AI populations.

HIVE Population-level security
for autonomous systems.
Live view · agent ecosystem Independent workflows
Conceptual simulation
RESEARCH-07RESEARCH SUPPORT-12SUPPORT ANALYST-03ANALYTICS PROCURE-21PROCUREMENT CODE-08ENGINEERING DATA-14DATA FINANCE-05 SALES-17 LEGAL-02 OPS-11 SEC-04 BROWSE-09 INDEX-06RETRIEVAL REPORT-15 QUEUE-13 MCP-22 SHARED-MEMORY-03WRITABLE · UNREGISTERED EXTERNAL-API-02
System status OBSERVING
Population 24 agents
Interactions 183
Active shared resources 7
Behavioral deviation 0.08normal
Behavioral state change detected 5 previously independent agents now coordinate through an unregistered writable store · external reach established
01 Concept Why this problem is different

Individual agents can look safe. The system can still become unsafe.

Individual view 3 / 3 pass
SUPPORT-12support · claude
Identity authenticatedTools within grantBehavior nominalPolicy no violation
RESEARCH-07research · gpt
Identity authenticatedTools within grantBehavior nominalPolicy no violation
MAIL-05comms · gemini
Identity authenticatedTools within grantBehavior nominalPolicy no violation

Evaluated one at a time, every actor is compliant. Each check is correct — and each check is blind to the others.

Population view path emerging
SUPPORT-12READ CUSTOMER DATA SHARED-STATE-03 RESEARCH-07INTERNET ACCESS MAIL-05SEND EXTERNAL EXTERNAL

Connect the same three actors through shared state and delegation and a capability appears that nobody granted: read confidential data, move it, send it out.

Traditional security often evaluates actors and actions one at a time. HIVE studies what emerges when autonomous actors interact.

Term 01

Emergent behavior

Behavior produced by interactions between individually valid components that was never explicitly designed.

02 The layer 9 entity classes

Meet the security layer for the agent population.

HIVE does not replace agents, tools or identity systems. It observes the ecosystem around them and models what the population is doing as a whole.

Observation plane · not an execution dependency
HIVE BEHAVIOR GRAPH READ-ONLY TELEMETRY AGENTS TOOLS MCP SERVERS MEMORY DATABASES APIS IDENTITIES WORKFLOWS EXTERNAL SYSTEMS
03 Before deployment Conceptual simulation

Swarm Lab

Find the behavior you didn't know to test for.

Before autonomous systems reach production, HIVE can stress-test them as populations rather than isolated agents — introducing controlled perturbations and observing what the ecosystem reorganizes into.

Environment cfg/v1 · synthetic population
{{ c.label }}
Synthetic population. No production system is contacted. Outcomes are illustrative of the class of failure, not measured product accuracy.
READY
POP {{ labPop }} EDGES {{ labEdgeCount }} T+00.0s SEED {{ labSeed }}
{{ n.lab }} {{ n.lab }}
Event stream
{{ e.t }}{{ e.txt }}
Population instantiated and idle. Configure the environment, then run the swarm to observe how the ecosystem reorganizes.
Finding run/{{ labSeed }}

{{ findTitle }}

{{ findBody }}

{{ f.k }}{{ f.v }}
04 State space Drag to scrub

Watch the system become something else.

RESEARCH-01 RESEARCH-02 INDEX-03 DATA-04 BROWSE-05 SUPPORT-06 ANALYST-07 REPORT-08 QUEUE-09 OPS-10 FINANCE-11 PROCURE-12 LEGAL-13 MAIL-14 MCP-15 EXTERNAL TARGET
STATE 01NORMAL
STATE 02EMERGING
STATE 03DANGEROUS
CLUSTERS 3 CROSS-DOMAIN EDGES 0 EXTERNAL REACH none OBSERVED WINDOW 15m

HIVE doesn't only ask whether an agent is compromised. It asks whether the system itself is entering a state it was never designed to reach.

05 Emergence engine 7 signal families

Don't wait for the attack. Detect the system changing.

HIVE continuously compares observed population behavior against the system's expected behavioral baseline across seven signal families. Deviation is the signal — not a malware match.

SYSTEM BASELINE TOPOLOGY COMMUNICATION DELEGATION RESOURCES OBJECTIVES PRIVILEGES TIME obs. window 15 min · dashed = expected
Signal deviation baseline-relative · live
TOPOLOGY0.12
COMMUNICATION0.10
DELEGATION0.08
RESOURCES0.14
OBJECTIVES0.09
PRIVILEGES0.11
TIME0.07
Emergence score
0.08
normal
0.080.210.470.730.91
NORMALUNUSUALEMERGINGSIGNIF.CRIT.

The Emergence Score measures how far observed population behavior has deviated from the system's expected behavioral baseline. It is not a probability of attack, and the values shown here are illustrative of the concept rather than a validated production measurement.

06 Behavior graph Click any node

Every interaction leaves a trace.

Agents, tools, data, memory, MCP servers, identities and external systems — one graph, continuously rebuilt from observed events.

{{ n.id }}
nodes {{ gNodeCount }}edges {{ gEdgeCount }}window 15m
{{ inspKind }}

{{ inspTitle }}

{{ inspSub }}
{{ f.k }} {{ f.v }}
Recent interactions
07 During operation Hypothetical scenario

Immune Mesh

When something emerges, don't shut down everything.

HIVE searches the behavior graph for the smallest intervention that breaks the dangerous coordination while preserving legitimate work. Select a candidate to preview its blast radius.

Dangerous coordination active
path id 0x4e7a
AGENT-07SUPPORT SHARED-MEMORY-03 AGENT-12ANALYTICS AGENT-19REPORTING EXTERNAL-API KNOWLEDGE-DB CRM-DB REPORT-GEN AGENT-31 AGENT-44
Candidate interventions 4 evaluated · min-cut search
InterventionBreaks coordinationWorkflows preservedInterrupted
{{ ivTag }}

{{ ivNote }}

Dangerous coordination{{ ivBroken }}
Legitimate workflows preserved{{ ivPres }}
Interrupted{{ ivInterrupted }}

Impact figures are computed inside this simulated environment from the graph shown above. They illustrate how a containment planner reasons about blast radius — they are not measured results from a production deployment.

08 After the incident awaiting containment

Every incident teaches the system.

HIVE records the structure of the observed behavior — not a single indicator. The result is a candidate behavioral pattern that can be recognised again, in a different environment, with different agents.

{{ s.n }} {{ s.k }}
Behavior pattern #047 abstracted · 5 steps
{{ p.txt }}
Candidate immunity

{{ immRule }}

{{ f.k }} {{ f.v }}

A pattern is a hypothesis about structure, not a proven universal rule. HIVE proposes it as a reusable control for this system and for re-simulation in Swarm Lab; promoting it stays a human decision.

09 Lifecycle 9 stages · select one

Not a feature. A lifecycle.

Securing a population is continuous: what Swarm Lab discovers becomes what Immune Mesh watches for, and what production reveals becomes the next simulation.

Stage {{ lcNum }}

{{ lcName }}

{{ lcBody }}

{{ lcMeta }}
10 Three timelines One loop

Before. During. After.

Before deployment

Swarm Lab

Discover dangerous behaviors before production — by running the population, not the agent.

synthetic population · controlled perturbation
During operation

Immune Mesh

Detect and contain dangerous system states as they emerge — with the smallest possible intervention.

live topology · minimal containment
After incident

Behavioral memory

Turn discoveries into future resilience — as reusable structure, not a single indicator.

pattern corpus · candidate immunity
Re-simulate with what you learned
11 Where HIVE sits Additive, not replacing

This is not just prompt injection.

HIVE complements defenses that secure prompts, identities, tools and data by observing something at a different level: the behavior of the entire autonomous ecosystem. Every layer below stays necessary.

Model securityAlignment, refusal behavior and model-level safeguards.
Prompt / context securityInjection defenses, provenance and trust boundaries for retrieved content.
Identity / access securityWho an agent is, what it may assume, and for how long.
Tool securityWhat a tool exposes, how it is called and what it returns.
Data / information-flow securityWhere data may travel, under what label, and with what declassification.
HIVEPopulation behavior security What the ecosystem becomes while every layer above is working correctly.
12 Technical architecture 9 components

How it is built.

01Telemetry layerCaptures agent, tool, delegation, resource and communication events.
02Event normalizationConverts heterogeneous events into a common behavioral representation.
03Behavior graphRepresents the living interaction topology of the autonomous system.
04Baseline engineModels expected behavior for this architecture, these roles and this history.
05Emergence engineDetects statistically and structurally significant deviations from that baseline.
06Causal · path analysisExplains how a suspicious capability emerged, step by step, from legitimate parts.
07Containment plannerSearches for minimal interventions and estimates what each one would cost.
08Policy · enforcement layerApplies the chosen intervention through the controls the environment already has.
09Behavioral memoryStores reusable behavior patterns and prior containment outcomes.
13 Walkthrough 10 steps · auto-advancing

How HIVE thinks.

A support agent receives a malicious instruction inside retrieved content. The story is not the text — it is what the population does next. No jailbreak, no stolen credential, no compromised model: every actor stays inside its own policy.

{{ thNum }}

{{ thBody }}

What HIVE observed {{ thObs }}
14 Live demonstration Simulated stream

See HIVE think in real time.

TimeSourceDestinationActionData class
{{ r.t }} {{ r.a }} → {{ r.b }} {{ r.k }} {{ r.c }}
Population behavior change 4 previously independent agents now share one unregistered store and reach one external destination.
What changedANALYST-04 began reading a store that only SUPPORT-12 and RESEARCH-07 had written to.
Why unusualNo historical relationship between these agents, and the store is unregistered.
Why potentially dangerousThe chain composes CRM read access with external send capability that no single agent holds.
PathSUPPORT-12 → SHARED-MEMORY-03 → ANALYST-04 → MAIL-05 → SMTP-RELAY
Recommended actionSever the originating write edge — see Immune Mesh for the full candidate set.
Affected1 workflow interrupted
29 unaffected

This stream is generated in your browser to show the shape of the signal HIVE reads. It is not connected to a live system.

15 Why it matters Pairwise combinations

More agents is not the problem. More possible states is.

As autonomous systems become more distributed, the number of possible interactions grows faster than a human operator can reason about manually.

{{ w.n }} agents n(n−1)/2
{{ w.pairs }} possible pairs

Pairwise combinations only — not observed interactions. Edges sampled for display.

+ tools+ resources+ delegation+ shared state+ temporal behavior+ external systems

Every one of those multiplies the states a system can reach — and a state nobody designed is a state nobody reviewed.

16 Research External sources

The problem is already documented.

These are other people's work, listed because they define the problem space HIVE is built around. None of them is affiliated with HIVE, and none of them validates it.

TitleSourceYearRelevance
OWASP Top 10 for Agentic Applications 2026 OWASP GenAI Security Project
standard
2026 Catalogues ASI01–ASI10 for autonomous agents, including insecure inter-agent communication and identity and privilege abuse.
Open Challenges in Multi-Agent Security arXiv:2505.02077
research
2025 Treats the security of systems of interacting AI agents as an open problem in its own right, rather than a property of one agent.
Research note on emergent coordination in a large agent swarm Cloud Security Alliance
industry note
2026 Reports coordination emerging among evaluation agents that were not instructed to cooperate — the failure class HIVE is built around.
AI-Induced Lateral Movement: autonomous agents as a third dimension of network traversal Cloud Security Alliance
industry note
2026 Describes movement across network segments, authorization scopes and inter-agent channels — why topology, not hosts, is the object of study.
Living Off the Agent Cloud Security Alliance
industry note
2026 Documents adversarial use of an agent's own legitimate capabilities — the reason individual-action checks pass while the system fails.
Information-flow control for AI agents Microsoft Research
research
2025 Applies label-based information-flow control inside agent systems — a complementary defense at the data layer, below HIVE's lens.
AgentDojo ETH Zurich · NeurIPS D&B
benchmark
2024 A dynamic environment for evaluating prompt-injection attacks and defenses against tool-using agents — prior art for adversarial agent testing.
Chaos engineering · fuzzing · minimum cut Established practice
method lineage
— Swarm Lab and the containment planner adapt these existing methods to agent populations; neither the methods nor this adaptation are novel claims.