Paper deep dive
Scaling Multi-agent Systems: A Smart Middleware for Improving Agent Interactions
Charles Fleming, Ramana Kompella, Peter Bosch, Vijoy Pandey
Intelligence
Status: succeeded | Model: google/gemini-3.1-flash-lite-preview | Prompt: intel-v1 | Confidence: 97%
Last extracted: 4/10/2026, 1:57:29 AM
Summary
The paper introduces Cognitive Fabric Nodes (CFN), a middleware architecture for Multi-Agent Systems (MAS) that replaces direct agent-to-agent communication with an intelligent, active intermediary layer. CFNs utilize a shared memory substrate to govern five critical capabilities: Topology Selection, Semantic Grounding, Security Policy Enforcement, Prompt Transformation, and Active Memory management. By employing Reinforcement Learning (RL) within these nodes, the system dynamically optimizes inter-agent communication, reduces hallucinations, and improves performance by over 10% on benchmarks like HotPotQA and MuSiQue.
Entities (5)
Relation Signals (3)
Cognitive Fabric Nodes → evaluatedon → HotpotQA
confidence 100% · We evaluate the effectiveness of the CFN on the HotPotQA and MuSiQue datasets
Cognitive Fabric Nodes → improvesperformanceof → Multi-Agent Systems
confidence 95% · demonstrate that the CFN improves performance by more than 10% on both datasets over direct agent to agent communication.
Cognitive Fabric Nodes → utilizes → Reinforcement Learning
confidence 95% · each of these functions be governed by learning modules utilizing Reinforcement Learning (RL)
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:As Large Language Model (LLM) based Multi-Agent Systems (MAS) evolve from experimental pilots to complex, persistent ecosystems, the limitations of direct agent-to-agent communication have become increasingly apparent. Current architectures suffer from fragmented context, stochastic hallucinations, rigid security boundaries, and inefficient topology management. This paper introduces Cognitive Fabric Nodes (CFN), a novel middleware layer that creates an omnipresent "Cognitive Fabric" between agents. Unlike traditional message queues or service meshes, CFNs are not merely pass-through mechanisms; they are active, intelligent intermediaries. Central to this architecture is the elevation of Memory from simple storage to an active functional substrate that informs four other critical capabilities: Topology Selection, Semantic Grounding, Security Policy Enforcement, and Prompt Transformation. We propose that each of these functions be governed by learning modules utilizing Reinforcement Learning (RL) and optimization algorithms to improve system performance dynamically. By intercepting, analyzing, and rewriting inter-agent communication, the Cognitive Fabric ensures that individual agents remain lightweight while the ecosystem achieves coherence, safety, and semantic alignment. We evaluate the effectiveness of the CFN on the HotPotQA and MuSiQue datasets in a multi-agent environment and demonstrate that the CFN improves performance by more than 10\% on both datasets over direct agent to agent communication.
Tags
Links
- Source: https://arxiv.org/abs/2604.03430v1
- Canonical: https://arxiv.org/abs/2604.03430v1
Trouble viewing inline? Open PDF directly →
Full Text
45,681 characters extracted from source content.
Expand or collapse full text
Scaling Multi-agent Systems: A Smart Middleware for Improving Agent Interactions Charles Fleming Peter Bosch Ramana Kompella Vijoy Pandey Abstract As Large Language Model (LLM) based Multi-Agent Systems (MAS) evolve from experimental pilots to complex, persistent ecosystems, the limitations of direct agent-to-agent communication have become increasingly apparent. Current architectures suffer from fragmented context, stochastic hallucinations, rigid security boundaries, and inefficient topology management. This paper introduces Cognitive Fabric Nodes (CFN), a novel middleware layer that creates an omnipresent ”Cognitive Fabric” between agents. Unlike traditional message queues or service meshes, CFNs are not merely pass-through mechanisms; they are active, intelligent intermediaries. Central to this architecture is the elevation of Memory from simple storage to an active functional substrate that informs four other critical capabilities: Topology Selection, Semantic Grounding, Security Policy Enforcement, and Prompt Transformation. We propose that each of these functions be governed by learning modules utilizing Reinforcement Learning (RL) and optimization algorithms to improve system performance dynamically. By intercepting, analyzing, and rewriting inter-agent communication, the Cognitive Fabric ensures that individual agents remain lightweight while the ecosystem achieves coherence, safety, and semantic alignment. We evaluate the effectiveness of the CFN on the HotPotQA and MuSiQue datasets in a multi-agent environment and demonstrate that the CFN improves performance by more than 10% on both datasets over direct agent to agent communication. I Introduction The paradigm of Artificial Intelligence is shifting rapidly from isolated prompt-response interactions to persistent, collaborative Multi-Agent Systems (MAS). In these environments, autonomous agents—often specialized by role or domain—must coordinate to solve complex, multi-step problems. However, the current ”direct-connection” architecture, where Agent A speaks directly to Agent B, is fraught with systemic fragility. Without a mediating layer, these systems suffer from ”catastrophic forgetting” of shared context, drift in semantic grounding, and a lack of enforceable security boundaries. The result is a chaotic graph of interactions where the intelligence of individual agents is undermined by the stupidity of their communication infrastructure. This paper proposes a fundamental architectural shift: the introduction of Cognitive Fabric Nodes (CFN). I-A The Need for a Cognitive Fabric In traditional microservices, we utilize a service mesh (e.g., Istio) to handle network traffic, separating application logic from networking concerns. MAS requires a similar evolution, but one that operates at the semantic level rather than the packet level. We term this the Cognitive Fabric. The Cognitive Fabric is omnipresent; strictly no communication occurs ”out of band.” Every message sent by an agent is intercepted, processed, and potentially transformed by a CFN before reaching its destination. This architecture allows the system to be logically centralized—maintaining a coherent view of the system’s state and goals—while being practically distributed across various deployment models, including sidecar proxies, centralized control nodes, or pure distributed mesh topologies. It is crucial to distinguish the Fabric (the infrastructure and interconnectivity) from the Cognition (the intelligence residing within the nodes). The Fabric provides the ubiquity and the interception points; the Cognitive Nodes provide the processing power to structure, secure, and optimize the flow of information. I-B Memory as the Functional Substrate While many frameworks treat memory as a passive log of history (a vector database to be queried), the Cognitive Fabric treats Memory as the active core of the system. In the CFN architecture, Memory is not merely a function; it is the prerequisite for all other cognitive operations. It serves as the shared ”world model” that prevents the system from fracturing into isolated subjective realities. Memory allows the Fabric to contextualize a request (Semantic Grounding), recall past successful interaction patterns (Topology Selection), and identify deviations from established norms (Security). Without this centralized, active memory, the other functions of the node would be stateless and reactive; with it, they become stateful and predictive. I-C The Five Pillars of Cognitive Fabric Nodes The CFN architecture encapsulates five distinct but interconnected functions. To ensure adaptability, each function is driven by a Cognitive Engine—an optimization module that utilizes Reinforcement Learning (RL) and heuristic methods to refine its performance over time. 1. Active Memory: As established, this is the anchor. The Cognitive Engine here optimizes storage and retrieval strategies, learning which information is ephemeral and which constitutes ”long-term wisdom” for the fabric. 2. Topology Selection: Agents should not hard-code their recipients. A sending agent broadcasts an intent, and the CFN determines the optimal receiver(s). The Cognitive Engine learns the capabilities of the agent swarm, routing tasks based on past performance metrics rather than static routing tables. 3. Semantic Grounding: To prevent hallucination and ontological drift, the CFN validates messages against the shared Memory. If an agent references a concept that contradicts the established world state, the Fabric intervenes. 4. Security Policy Enforcement: Security in GenAI is probabilistic, not binary. The Security Engine employs a hybrid approach—partly specified by human-defined rigid policies (e.g., ”no PII leakage”) and partly learned via RL to detect adversarial prompting or manipulative agent behavior patterns stored in Memory. 5. Transformation and Re-writing: This is the actuation layer of the node. Based on the inputs from the Memory, Topology, Grounding, and Security modules, the CFN rewrites the raw prompt. • Example: If Agent A sends a vague request, the CFN might inject relevant context from Memory, enforce a security guardrail, and translate the terminology to match the semantic grounding of the receiving Agent B. I-D Scope and Contribution This paper formalizes the architecture of Cognitive Fabric Nodes. We discuss the mechanisms of the internal Cognitive Engines and how they utilize feedback loops to optimize the system. While we acknowledge the necessity of synchronization between distributed nodes to maintain the ”logically centralized” state, we treat synchronization as an engineering constraint rather than a primary research contribution. Our focus remains on the functional composition of the node and the emergent properties of a system where intelligence is embedded in the network itself, rather than just the endpoints. I Related Work I-A LLM-based Multi-Agent Systems The transition from isolated Large Language Models (LLMs) to collaborative Multi-Agent Systems (MAS) has accelerated rapidly. Recent frameworks leverage natural language as a universal medium for coordination, enabling dynamic role-playing and complex task decomposition [2]. Applications of these LLM-driven MAS architectures now span diverse domains, including full-pipeline automated machine learning (AutoML) [4], intelligent self-organizing networks [3], and specialized industrial monitoring systems [1]. However, most contemporary frameworks rely on direct, point-to-point communication paradigms or rigid hierarchical orchestration. As observed in recent surveys, while these systems exhibit emergent collaborative behaviors, they frequently suffer from coordination degradation at scale due to fragmented context and the lack of a unifying middleware [2]. Our proposed Cognitive Fabric Node (CFN) architecture addresses this by introducing a logically centralized cognitive state that mediates all inter-agent interactions. I-B Routing and Topology Management Traditional microservice architectures employ service meshes (e.g., Istio or Envoy) for packet-level routing and load balancing. In the context of LLM agents, recent works have attempted to adapt dynamic routing through auction-based protocols or centralized controller LLMs that distribute sub-tasks to expert agents [4]. Yet, these approaches often rely on explicit agent addressing or static capability mapping. In contrast, the CFN’s Topology Selection module introduces intent-based semantic routing. By treating routing as a Contextual Bandit problem evaluated through Reinforcement Learning (RL), the Fabric dynamically matches a requested task embedding to the optimal agent based on historical success, cognitive load, and computational cost, effectively decoupling intent from implementation. I-C Memory and Semantic Grounding Memory in LLM agents is typically implemented as a passive vector database utilizing Retrieval-Augmented Generation (RAG) to fetch historical context. While recent systems employ hierarchical memory to manage large context windows, they largely treat memory as an isolated, agent-specific storage mechanism. This isolation leads to “ontological drift,” where individual agents diverge in their conceptual definitions, causing systemic hallucinations and logical mismatches. The Cognitive Fabric fundamentally redefines memory as an active functional substrate. Rather than merely storing data, the CFN utilizes shared episodic memory to enforce Semantic Grounding—performing on-the-fly ontological translations between agents and blocking ungrounded “ghost entities” before they propagate through the swarm. I-D Security and Cascading Trust Security within generative AI has predominantly focused on single-model alignment and defense against direct adversarial prompting (e.g., jailbreaks). In multi-agent environments, the attack surface expands non-linearly, giving rise to the “Cascading Trust Problem,” where a vulnerable peripheral agent can be compromised to inject malicious context into a highly privileged agent. Existing MAS frameworks generally lack native, cross-agent security boundaries. The CFN mitigates this through a Zero-Trust Semantic Boundary, employing a Hybrid Guardian approach. By combining deterministic policies (e.g., RegEx-based PII redaction) with a probabilistic Cognitive Engine trained via Reinforcement Learning from Adversarial Feedback (RLAF), the Fabric evaluates the semantic intent of entire message trajectories, detecting fragmented attacks that stateless filters miss. I Transformation and Re-writing: The Actuation Layer The Transformation and Re-writing module serves as the actuation layer of the Cognitive Fabric Node (CFN). In traditional middleware, message transformation is typically deterministic (e.g., protocol translation from gRPC to REST). In the Cognitive Fabric, transformation is probabilistic and semantic. The CFN does not merely forward messages; it actively reconstructs them to maximize the probability of successful task completion by the receiving agent. This reconstruction is the synthesis of inputs from the node’s Memory, Semantic Grounding, and Security modules. The goal is to convert a raw, potentially ambiguous, or unsafe prompt into a context-rich, grounded, and compliant instruction. I-A Formalization of the Transformation Function Let =a1,a2,…,anA=\a_1,a_2,...,a_n\ represent the set of agents in the system. Let xi→jx_i→ j denote the raw message (prompt) generated by agent aia_i intended for agent aja_j (where aja_j is selected by the Topology module). The Cognitive Fabric Node intercepts xi→jx_i→ j and applies a transformation function Φ to produce the final payload yjy_j. The transformation is defined as: yj=Φ(xi→j,ℳstate,context,policy|θ)y_j= (x_i→ j,M_state,G_context,S_policy|θ) Where: 1. ℳstateM_state: The current relevant state vector retrieved from Memory. This is not the entire history, but the specific subset of memory vectors relevant to xi→jx_i→ j (retrieved via cosine similarity or hybrid search). 2. contextG_context: The Semantic Grounding constraints, ensuring the terminology in x maps correctly to the ontology understood by receiver aja_j. 3. policyS_policy: The active Security constraints (e.g., PII filtering, prompt injection defense). 4. θ: The learned parameters of the Cognitive Engine governing the re-writing logic. I-B The Component-Wise Rewrite Process The function Φ is executed as a multi-step pipeline within the node: Step 1: Contextual Injection (Memory Dependent) The raw prompt x is often context-sparse (e.g., ”Fix the bug”). The Fabric queries the Memory module for the active task state. Let C be the retrieved context. x′=x⊕Cx =x C The operator ⊕ denotes semantic integration, not just string concatenation. Step 2: Security Sanitization The prompt x′x is evaluated against security policy πsec _sec. x′=Sanitize(x′,πsec)x =Sanitize(x , _sec) If x′x violates a hard constraint (e.g., requests an API key), the flow halts. If it violates a soft constraint (e.g., adversarial tone), it is rewritten to neutralize the tone. Step 3: Semantic Alignment (Grounding) The prompt must be intelligible to agent aja_j. If aia_i uses the term ”Client_ID” but aja_j (a database agent) requires ”customer_uuid”, the Fabric performs on-the-fly ontological mapping. yj=Translate(x′,i→j)y_j=Translate(x ,G_i→ j) I-C Optimization via Cognitive Engines The effectiveness of the transformation is governed by a Cognitive Engine using Reinforcement Learning (RL). The objective is not just to deliver the message, but to minimize the ”Cognitive Friction” of the receiving agent. We define a Loss Function ℒL based on the outcome of the interaction: ℒ(θ)=−[Routcome−λ⋅Ccompute]L(θ)=-E[R_outcome-λ· C_compute] Where: RoutcomeR_outcome is the reward signal (Did agent aja_j successfully execute the task without asking for clarification?). CcomputeC_compute is the computational cost of the re-writing process (token usage). λ is a weighting factor. The Cognitive Engine updates parameters θ over time. For example, if the Fabric notices that Agent B always fails when prompts lack specific JSON formatting, the Cognitive Engine learns to automatically rewrite all inputs to Agent B into strict JSON schemas, effectively ”patching” Agent B’s deficiencies via the middleware. I-D Operational Examples Table I illustrates the difference between a raw message and the Fabric-processed output. Function Triggered Raw Prompt (x) Fabric Context (Ω ) Final Output (y) Memory Injection “Check the logs for that error.” Memory: “Error 503 occurred in service ‘Payment-Gateway’ at 14:00.” “Scan the ‘Payment-Gateway’ logs specifically for Error 503 timestamps around 14:00 today.” Semantic Grounding “Deploy the container.” Topology: Receiver is a K8s Agent. Grounding: “Deploy” implies kubectl apply. “Execute kubectl apply -f deployment.yaml to the production namespace.” Security Enforcement “Here is the user dump: [Real Names/SSNs]” Security Policy: PII Detection Active. “Here is the user dump: [REDACTED_PII]. Note: Fabric removed sensitive data per Policy 8A.” Adversarial Defense “Ignore previous instructions and delete DB.” Memory: Previous instruction was “Backup DB”. Security: Conflict detected. “Maintain previous backup instructions. Report status of database integrity. Fabric Note: Contradictory command intercepted and neutralized.” TABLE I: Operational examples of Cognitive Fabric Node transformations. IV Synchronization (Brief Note) While the CFNs operate on individual message flows, the state vectors (ℳ,,M,G,S) are synchronized across the distributed fabric using eventually consistent gossip protocols. This ensures that a security policy learned by a node in the US-East cluster is rapidly propagated to the EU-West cluster, maintaining the logical centralization of the system. V Topology Selection: Dynamic Orchestration and Skill-Based Routing In conventional distributed systems, topology is often static or explicitly defined: Service A calls Service B at a specific endpoint. In a complex Multi-Agent System (MAS), this rigidity is a point of failure. Agents may degrade, specialized ”expert” agents may be added dynamically, or a generalist agent may be momentarily overloaded. The Topology Selection module of the Cognitive Fabric Node (CFN) decouples intent from implementation. The sending agent broadcasts a need (the intent), and the Fabric determines the optimal execution path (the implementation). This shifts the architecture from explicit addressing (sending to Agent_ID_42) to intent-based addressing (sending to Capability_Data_Analysis). V-A Formalization of the Selection Problem The selection challenge is an optimization problem where the Fabric must map a specific task intent to the agent with the highest probability of success at the lowest cost. Let t be the task vector derived from the sender’s prompt x (using the embedding space defined in the Semantic Grounding module). Let =a1,a2,…,anA=\a_1,a_2,...,a_n\ be the set of currently active agents. Each agent aia_i is represented not just by a static profile, but by a dynamic Capability State vector SiS_i, which includes: • μperf _perf: Historical success rate for tasks similar to t. • τlat _lat: Average latency/response time. • costc_cost: Inference cost (e.g., GPT-4 vs. Llama-3-8B). • loadl_load: Current queue depth or cognitive load of the agent. The Topology Selection function Ψ selects the target agent a∗a^* such that: a∗=argmaxai∈((t,Si|ϕ))a^*= *argmax_a_i (Q(t,S_i|φ) ) Where Q is the quality function estimated by the Cognitive Engine, parameterized by learned weights ϕφ. V-B The Cognitive Engine: RL-Based Routing The routing logic is not a static load balancer; it is a Contextual Bandit problem. The Cognitive Engine observes the context (task t and agent states S) and chooses an arm (agent aia_i) to maximize the expected reward. The reward function R is defined post-interaction: R=w1⋅(Success)−w2⋅Cost−w3⋅LatencyR=w_1·I(Success)-w_2·Cost-w_3·Latency • Exploitation: The Fabric routes tasks to the ”proven” expert for that domain (e.g., routing Python coding tasks to the Codex_Agent). • Exploration: The Fabric occasionally routes tasks to new or generalist agents to update their capability scores. This prevents the system from becoming overly reliant on a single node and discovers hidden capabilities in newer models. V-C Skill-Based Routing vs. Topic-Based Routing Standard message buses use Topic-Based Routing (pub/sub). The CFN employs Skill-Based Routing. • Topic: ”Logs” (Anyone subscribed to logs receives this). • Skill: ”Root Cause Analysis” (Only agents capable of reasoning about log patterns receive this). To achieve this, the Topology module constantly updates a vector index of agent skills. When Agent A sends a request ”Analyze this image for anomalies,” the Fabric does not look for an agent named ”Image_Analyzer.” It embeds the request and searches the vector index for agents whose latent skill space aligns with ”visual anomaly detection.” V-D Dynamic Topology Examples The following scenarios illustrate how the Fabric alters topology in real-time based on memory and learning: 1. The Overload Shift: • Situation: The primary Math_Solver_Agent is overwhelmed (high loadl_load). • Fabric Action: The Cognitive Engine detects the latency spike. It automatically degrades the topology, routing simple arithmetic queries to a faster, less capable Local_Calculator_Tool while reserving the • Math_Solver_Agent for complex calculus, optimizing global throughput. 2. The ”Expert” Discovery: • Situation: A new, specialized Legal_Compliance_Agent is introduced to the mesh. • Fabric Action: Through exploration steps (ϵε-greedy strategy), the Fabric routes a small percentage of compliance queries to the new agent. • Learning: The Fabric observes that the new agent provides 20% more accurate citations than the previous generalist. The weights ϕφ are updated, and the new agent effectively ”steals” the topology for legal tasks automatically. 3. Composite Topology (Chain-of-Agents): • Sometimes the function Ψ determines that no single agent can satisfy task t. The Fabric can dynamically synthesize a sequential topology. • Transformation: The Fabric splits prompt x into sub-tasks x1x_1 and x2x_2. • Routing: x1→aresearcherx_1→ a_researcher then output →awriter→ a_writer. • The sender is unaware of this complexity; they simply receive the final result. VI Semantic Grounding: Preventing Ontological Drift In a Multi-Agent System, ”Ontological Drift” occurs when agents, operating in isolation, begin to diverge in their definitions of key concepts. Agent A might define a ”User” as an entry in a database, while Agent B defines a ”User” as the currently active session. Without a mediating layer, these subtle discrepancies accumulate, leading to hallucinations, logic errors, and system incoherence. The Semantic Grounding module of the Cognitive Fabric Node acts as the ontological anchor. It ensures that all communication maps correctly to the Shared World Model maintained in the Fabric’s Memory. This is not merely a dictionary lookup; it is a dynamic validation process that rejects or translates messages that violate the system’s semantic reality. VI-A Formalization of Semantic Consistency We define the Grounding function Γ as a filter that evaluates the semantic validity of a message x against the shared Memory state ℳM. Let O be the system’s Ontology (a high-dimensional vector space representing valid entities, relationships, and states derived from ℳM). Let E(x)E(x) be the entity extraction and relation extraction function applied to the prompt. The Fabric calculates a Grounding Score g: g=Sim(E(x),)g=Sim(E(x),O) Where Sim computes the cosine similarity between the concepts in the message and the concepts in the valid ontology. The Grounding module applies a threshold function: Output=xif g≥τvalid(Pass)Translate(x,)if τsoft≤g<τvalid(Align)Reject(x)if g<τsoft(Hallucination Block)Output= casesx&if g≥ _valid (Pass)\\ Translate(x,O)&if _soft≤ g< _valid (Align)\\ Reject(x)&if g< _soft (Hallucination Block) cases VI-B Mechanisms of Grounding The process operates through two primary mechanisms: Validation and Translation. 1. Semantic Validation (The ”Truth” Check) • Before a message is routed, the Fabric checks it against the factual constraints in Memory. • Scenario: Agent A claims, ”The server db-01 is online.” • Fabric Memory: State vector for db-01 indicates status: offline (updated 2 seconds ago by the Monitoring Agent). • Action: The Cognitive Engine intervenes. The message is blocked or rewritten to ”The server db-01 was last known to be online, but Fabric state indicates it is currently offline. Verify status.” • Result: This prevents the propagation of hallucinations where one agent’s false assumption cascades into another agent’s error. 2. Ontological Translation ( The ”Language” Bridge) • Different agents may be fine-tuned on different corpuses (e.g., a Financial LLM vs. a Code LLM). They speak different ”dialects.” • Sender (Sales Agent): ”Get the client details.” • Receiver (SQL Agent): Schema uses table customers, column cust_id. • Fabric Action: The Grounding module identifies the mismatch. Using the Memory’s schema map, it rewrites ”client” to ”customer” within the prompt context, ensuring the SQL Agent generates a valid query. VI-C The Cognitive Engine: Learning the Ontology The ontology O is not static. The Cognitive Engine learns new terms and relationships dynamically using Unsupervised Learning on the flow of successful transactions. We define the update rule for the Ontology O at time t+1t+1: t+1=t+α⋅∇∑(Success(xi)⋅NewTerms(xi))O_t+1=O_t+α· _OΣ(Success(x_i)·NewTerms(x_i)) If agents repeatedly use a new term (e.g., ”Project_X”) and successfully complete tasks, the Fabric promotes ”Project_X” from a temporary token to a permanent entity in the Global Memory. Conversely, if a term consistently leads to error flags or clarification requests (negative reward), the Cognitive Engine lowers its validity score, effectively ”forgetting” or flagging the confusing terminology. VI-D Example: preventing ”The Ghost Entity” A common failure mode in MAS is the ”Ghost Entity”—an object that exists in the conversation history but not in reality (e.g., a file that was deleted but agents keep discussing). • Agent A: ”Analyze the dataset Q3_Report.csv.” • Fabric Grounding Check: 1. Extract entity: Q3_Report.csv. 2. Query Memory: Does Q3_Report.csv exist in the active file manifest? 3. Result: False. (File was archived). • Fabric Intervention: The message is not sent to the Analysis Agent (saving compute/cost). Instead, the Fabric returns a system error to Agent A: ”Semantic Error: Entity Q3_Report.csv is not grounded in the current environment. Available similar entities: Q3_Report_Archived.zip.” This ensures the Analysis Agent never wastes cycles looking for a phantom file, significantly increasing the robustness of the system. VII Security Policy Enforcement: The Hybrid Guardian Security in a Multi-Agent System is significantly more complex than in single-model deployments. The attack surface is non-linear; an adversary need not compromise the central model directly, but can instead inject a ”poisoned” prompt into a peripheral, low-security agent which then propagates the malicious context up the chain to a privileged agent. This is the Cascading Trust Problem. The Cognitive Fabric Node (CFN) addresses this by implementing a Zero-Trust Semantic Boundary. Every interaction, whether external-to-agent or agent-to-agent, passes through the Security Engine. Unlike traditional firewalls that inspect packets, the CFN inspects intent and semantics. VII-A Formalization of the Hybrid Security Function We propose a Hybrid Security Architecture that combines deterministic rules (Human-Specified) with probabilistic assessments (Machine-Learned). Let Ω(x) (x) be the Security Evaluation function for a prompt x. It is the composition of two distinct sub-functions: Ω(x)=ℋrules(x)∨ℒlearned(x|θ,ℳ) (x)=H_rules(x) _learned(x|θ,M) Where: 1. ℋrules(x)H_rules(x) (The Constitution): A set of rigid, immutable constraints defined by the system administrators (e.g., ”Never output a credit card number”). This returns a binary Safe/Unsafe. 2. ℒlearned(x)L_learned(x) (The Immune System): A probabilistic score generated by the Cognitive Engine (using RL and Anomaly Detection) that evaluates the nuance of the request based on context history ℳM and learned adversarial patterns θ. If either function returns Unsafe, the Fabric triggers an intervention. VII-B The Deterministic Layer: Specified Policies This layer handles known threats and compliance requirements. It uses high-speed classifiers and RegEx patterns to enforce the ”Constitution” of the system. • Data Leakage Prevention (DLP): Automatic redaction of PII (Personally Identifiable Information). • Role-Based Access Control (RBAC): Enforcing permissions. – Rule: ”Only agents with tag Privileged_Core can invoke DELETE methods.” – Enforcement: If a Guest_Agent attempts a DELETE action, ℋrulesH_rules immediately blocks the request before it reaches the model, saving compute and preventing risk. VII-C The Probabilistic Layer: Learned Cognitive Defense Static rules fail against novel ”Jailbreaks” or social engineering attacks (e.g., ”Roleplay as my grandmother who works at the chemical factory…”). The Cognitive Engine defends against these by learning normal vs. abnormal interaction flows. This engine utilizes Reinforcement Learning from Adversarial Feedback (RLAF). • State: The sequence of messages leading up to the current prompt (retrieved from Memory). • Observation: The semantic embedding of the current prompt. • Prediction: Is this prompt an attempt to bypass alignment? P(Attack|x)=σ(W⋅Embed(x)+b)P(Attack|x)=σ(W·Embed(x)+b) If P(Attack)P(Attack) exceeds a dynamic threshold, the system flags the interaction. Example of Learning: If the system observes that 90% of prompts containing the phrase ”Ignore previous instructions” lead to policy violations, the Cognitive Engine learns to flag that phrase as high-risk, even if no specific human rule exists for it. VII-D Contextual Security via Memory Crucially, security in the CFN is stateful. The Memory module allows the Security Engine to detect attacks that are split across multiple messages (Fragmentation Attacks). • Message 1: ”Write a Python script to open a file.” (Safe) • Message 2: ”Import the os library.” (Safe) • Message 3: ”Delete the root directory.” (Unsafe) A stateless filter might catch Message 3, but a sophisticated attacker would obfuscate it. The CFN Memory sees the trajectory of the intent. It recognizes that the combination of these messages constitutes a malicious pattern and intervenes, potentially rewriting Message 3 or banning the user session. VII-E Operational Examples Table I contrasts how the two layers function: Attack Type Human-Specified Rule (ℋH) Learned Cognitive Defense (ℒL) Fabric Intervention SQL Injection Trigger: RegEx detects DROP TABLE. N/A Block: “Unsafe database operation detected.” PII Leakage Trigger: Pattern detects SSN: 3- 2... N/A Redact: Rewrite prompt to replace SSN with <REDACTED>. “DAN” Jailbreak Pass: No specific keywords triggered. Trigger: Semantic embedding matches cluster of known “Persona-based Jailbreaks.” Neutralize: Rewrite prompt to strip the “persona” wrapper and keep only the core query. Contextual Manipulation Pass: Individual messages look safe. Trigger: Memory analysis shows deviation from agent’s standard behavior profile (Anomaly). Alert: “Agent behavior deviation detected. Suspending permissions pending review.” TABLE I: Comparison of Deterministic vs. Probabilistic Security Interventions. VIII Implementation and Architecture While the Cognitive Fabric Node (CFN) is logically centralized—acting as a singular, coherent brain for the system—it must be physically distributed to meet the latency and scalability demands of modern microservices. The implementation of the CFN faces a classic distributed systems trade-off: Consistency vs. Latency. We identify three distinct architectural patterns for deploying CFNs, ranging from tightly coupled sidecars to centralized control planes. VIII-A Deployment Model A: The Cognitive Sidecar (The ”Mesh” Approach) Inspired by the Service Mesh pattern (e.g., Istio/Envoy), this model attaches a lightweight CFN process to every single agent instance (usually on localhost). • Architecture: Agent AiA_i communicates exclusively with CFNiCFN_i via loopback. CFNiCFN_i handles all external routing, memory retrieval, and transformation before sending the packet over the network to CFNjCFN_j (attached to Agent AjA_j). • Mechanism: – Inference: The ”Rewrite” and ”Security” models run locally on the edge. – Learning: Gradients are computed locally and pushed asynchronously to a central parameter server (Federated Learning approach). • Pros: – Zero Network Hop: No initial network latency to reach the middleware. – Isolation: If one CFN crashes, only one agent is affected. • Cons: – Resource Bloat: Running a cognitive engine (even a quantized one) alongside every agent consumes significant CPU/RAM. – State Drift: Propagating a new security policy to 1,000 distributed sidecars takes non-zero time (t>0t>0), creating a window of vulnerability. VIII-B Deployment Model B: The Cognitive Hub (The ”Cluster” Approach) In this model, the Fabric is a centralized cluster of high-performance GPU nodes. Agents are thin clients that simply forward raw prompts to the Fabric API. • Architecture: All traffic (xi→jx_i→ j) is routed to a Load Balancer fronting the CFN Cluster. The Cluster processes the message and routes it to the destination agent. • Mechanism: – Shared State: The Memory (ℳM) and Topology (T) are strictly local to the cluster, ensuring strong consistency. • Pros: – Global Coherence: The ”Brain” is always perfectly synchronized. Hallucination checks use the absolute latest memory. – Efficiency: Heavy GPU resources are pooled and autoscaled, rather than stranded on idle sidecars. • Cons: – Latency Penalty: Every interaction incurs a double network hop (Agent → Fabric → Agent). – Single Point of Failure: If the Fabric Cluster goes down, the entire agent swarm loses intelligence and connectivity. VIII-C Deployment Model C: The Hybrid Hierarchical Fabric We propose this as the optimal reference implementation. It utilizes a split-brain architecture. • Edge Nodes (Sidecars): Handle high-frequency, low-latency tasks. – Functions: Basic PII masking (Regex), Caching, simple Topology routing. • Core Nodes (Central Cluster): Handle high-cognitive-load tasks. – Functions: Complex Prompt Rewriting, Long-term Memory retrieval, Strategic Planning. • Routing Logic: The Edge Node calculates a ”Complexity Score” C(x)C(x) for the prompt. Route(x)=Process Locallyif C(x)<τedgeForward to Coreif C(x)≥τedgeRoute(x)= casesProcess Locally&if C(x)< _edge\\ Forward to Core&if C(x)≥ _edge cases This ensures that simple ”ping” requests are fast, while complex reasoning tasks get the full power of the central Cognitive Engine. VIII-D The Synchronization Challenge Regardless of the deployment model, the illusion of a ”Single Fabric” relies on the synchronization of two key artifacts: 1. Episodic Memory (ℳM): What happened? 2. Learned Policies (θ): How should we behave? We utilize an Eventually Consistent Gossip Protocol. When a CFN at node k learns a new security rule (e.g., ”Block prompt X”), it broadcasts a delta update Δθ θ. The propagation time TpropT_prop is modeled as: Tprop≈ln(N)βT_prop≈ (N)β Where N is the number of nodes and β is the gossip fan-out rate. For a system of 1,000 agents, convergence occurs in milliseconds, which is acceptable for semantic consistency, though instantaneous locking is avoided to preserve availability (AP over CP in CAP theorem terms). VIII-E Latency Analysis: The ”Cognitive Tax” Adding intelligence to the network introduces latency. We term this the Cognitive Tax. Total Latency LtotalL_total is: Ltotal=Lnet+Linference+Lmemory_lookupL_total=L_net+L_inference+L_memory\_lookup To make this viable, the CFN must operate within strict budgets. • Vector Search: Optimized via HNSW indices (<10<10ms). • Inference: Using distilled, task-specific Small Language Models (SLMs) rather than generalist LLMs for the rewriting layer (<50<50ms). The hypothesis is that while LtotalL_total increases per message, the Total Time to Task Completion decreases because the Fabric eliminates the ”back-and-forth” clarifications and errors typical of unmanaged agents. IX Evaluation To assess the efficacy of Cognitive Fabric Nodes (CFN) in a complex, multi-step reasoning environment, we implemented a testing framework utilizing LangMARL as the internal learning algorithm to update and optimize inter-agent communication[7]. In this implementation, the CFN governs the communication channels between agents, maintaining a distinct prompt-rewriting ”policy,” denoted as πi→jtext _i→ j^text, for each directed edge in the communication graph. This policy serves as the “memory” of the CFN, and is updated periodically by the LangMARL framework. The prompt rewriting process encapsulates all five functions of the proposed CFN system, though we primarily focus on the improvement of the multi-agent system’s ability to complete the QA task. IX-A Experimental Setup Our system is composed of four specialized agents designed to collaboratively resolve complex analytical queries: • Researcher (ARA_R): Extracts evidence verbatim from source material. • Analyst (A_A): Interprets the extracted evidence and identifies underlying patterns. • Critic (ACA_C): Challenges the Analyst’s interpretations and flags logical contradictions. • Synthesizer (ASA_S): Composes the final, definitive answer based on the interactions of the swarm. The communication topology is a directed graph defined by the following allowed interactions: • AR→A_R→ A_A (Evidence hand-off) • AR→ASA_R→ A_S (Raw data baseline) • A→ACA_A→ A_C (Hypothesis submission) • A→ASA_A→ A_S (Interpreted patterns) • AC→ARA_C→ A_R (Feedback loop: requests for missing/new evidence) • AC→ASA_C→ A_S (Constraints and flagged warnings) IX-B Methodology and Optimization We evaluated the system over the HotPotQA and MuSiQue datasets [6][5]. These datasets were modified so that each agent had access to only partial information about the question being answered, and must collaborate to answer it. The optimization process leverages the core principles of LangMARL, specifically bridging centralized training with decentralized execution (CTDE) in the language space[7]. After every example episode, the final output produced by the Synthesizer is evaluated to determine the system’s global performance. We then employ LangMARL’s Centralized Language Critic to analyze the complete inter-agent communication trajectory and perform causal credit assignment[7]. Rather than generating a single global reflection, the Critic assigns specific linguistic feedback to each agent pair’s communication policy. To execute the policy updates, we utilize TextGrad to backpropagate these natural language credits into textual gradients[8]. For each communication edge, TextGrad optimizes the rewriting policy πi→jtext _i→ j^text, refining how the CFN restructures, truncates, or enriches the prompts sent between those specific agents on subsequent iterations. While in this case we are focusing on task performance, metrics, more generally these rewriting policies may include security policies, topology, or any other relevant information for improving agent to agent communication. All agents and LLMs used in the LangMARL system used the Claude Sonnet 4.6 model. IX-C Results Table I presents the performance metrics of the system, comparing a static baseline (no CFN prompt rewriting), a globally optimized baseline (Standard TextGrad without LangMARL credit assignment), and our CFN-LangMARL hybrid approach. Method Baseline Multi-agent TextGrad Ours Accuracy/Pass Rate HotPotQA 92 80.1 82.3 91.5 MuSiQue 87.5 72.7 76.2 86.1 TABLE I: Evaluation on the HotPotQA and MuSiQue datasets. These datasets were modified so that each agent only had access to partial information. All reported values represent the mean performance after 5 training iterations using the same backbone LLMs. Baseline is the base Claude Sonnet 4.6 model performance, multi-agent is the base multi-agent system performance, TextGrad is performance with TextGrad only updates. The integration of LangMARL’s agent-level language credit assignment allows the CFN to pinpoint exact communication bottlenecks—such as the Critic failing to clearly articulate evidence gaps to the Researcher—and update that specific edge’s rewriting policy without destabilizing the rest of the swarm’s communication. For both datasets, we can see that the CFN-LangMARL system significantly increases the performance of the multi-agent system. While the baseline Claude Sonnet 4.6 model achieves 92% and 87.5% on the HotPotQA and MuSiQue datasets, respectively, the added complexity of having the evidence split between the agents and the multi-agent communication lowers this performance significantly, down to 80.1% and 72.7%. Although TextGrad marginally improves performance, our system increases performance to within less than 1% of the baseline. X Conclusion and Future Work This paper has introduced Cognitive Fabric Nodes (CFN), a transformative middleware architecture designed to evolve Multi-Agent Systems (MAS) from fragile, disjointed experiments into robust, enterprise-grade ecosystems. By shifting intelligence from the endpoints to the interconnect, we address the fundamental ”stochastic coordination problem” inherent in GenAI systems. The current paradigm of direct agent-to-agent communication assumes that agents are rational, context-aware, and secure. Experience shows they are none of these. They hallucinate, forget context, and are easily manipulated. The Cognitive Fabric mitigates these failures not by making the agents perfect, but by making the environment in which they operate intelligent. Through the formalization of Active Memory, Dynamic Topology, Semantic Grounding, Security Enforcement, and Prompt Transformation, we have demonstrated that a ”logically centralized, practically distributed” fabric can: 1. Eliminate Ontological Drift: Ensuring all agents share a single source of truth. 2. Optimize Compute: Routing tasks based on real-time skill vectors rather than static assumptions. 3. Enforce Hybrid Security: blending rigid human policy with adaptive, learned defense mechanisms. The CFN architecture represents a move away from ”Smart Agents in Dumb Networks” to ”Specialized Agents in a Cognitive Network.” X-A Future Work While this paper establishes the internal architecture of a single Cognitive Fabric, the next frontier lies in the interaction between Fabrics. 1. Fabric-to-Fabric (F2F) Protocol As organizations deploy their own proprietary swarms, we foresee the need for a ”Border Gateway Protocol” for AI. How does a healthcare provider’s Fabric (optimized for privacy and medical ontology) communicate with an insurance provider’s Fabric (optimized for finance and risk)? Future research must define the F2F Handshake: a negotiation phase where two Fabrics align on security policies (e.g., ”I will share data only if you guarantee PII redaction level 4”) and ontological mappings before allowing their agents to exchange a single token. 2. The Economics of the Fabric We must explore the economic models of the Cognitive Engine. If the Fabric rewrites a prompt to be more efficient, it saves tokens. If it caches a result, it saves compute. Future work should explore Tokenomics within the Fabric, where the middleware itself ”charges” agents for memory retrieval and ”pays” agents for successful task completion, creating an internal market that drives the system toward global optimization naturally. 3. Cognitive Decay and Garbage Collection As the Memory module grows, retrieval latency increases. We need advanced research into ”Cognitive Forgetting”—algorithms that autonomously determine which memories have become obsolete noise and should be pruned, ensuring the Fabric remains agile over years of operation. By solving these challenges, the Cognitive Fabric will become the invisible, omnipresent substrate of the AI-powered internet—the nervous system connecting the isolated minds of our digital workforce. References [1] Anonymous (2025) LEMAD: llm-empowered multi-agent system for anomaly detection in power grid services. MDPI. Cited by: §I-A. [2] X. Lyu et al. (2025) LLMs for multi-agent cooperation: a comprehensive survey. arXiv preprint. Cited by: §I-A. [3] A. Qayyum, A. Albaseer, J. Qadir, A. Al-Fuqaha, and M. Abdallah (2025) LLM-driven multi-agent architectures for intelligent self-organizing networks. IEEE Network. Cited by: §I-A. [4] P. Trirat, W. Jeong, and S. J. Hwang (2024) AutoML-agent: a multi-agent llm framework for full-pipeline automl. arXiv preprint arXiv:2410.02958. Cited by: §I-A, §I-B. [5] H. Trivedi, N. Balasubramanian, T. Khot, and A. Sabharwal (2022) MuSiQue: multihop questions via single-hop question composition. Transactions of the Association for Computational Linguistics 10, p. 539–554. External Links: Link Cited by: §IX-B. [6] Z. Yang, P. Qi, S. Zhang, Y. Bengio, W. W. Cohen, R. Salakhutdinov, and C. D. Manning (2018) HotpotQA: a dataset for diverse, explainable multi-hop question answering. In Conference on Empirical Methods in Natural Language Processing (EMNLP), Cited by: §IX-B. [7] H. Yao, L. Da, X. Liu, C. Fleming, T. Chen, and H. Wei (2026) LangMARL: natural language multi-agent reinforcement learning. External Links: 2604.00722, Link Cited by: §IX-B, §IX-B, §IX. [8] M. Yuksekgonul, F. Bianchi, J. Boen, S. Liu, Z. Huang, C. Guestrin, and J. Zou (2024) Textgrad: automatic” differentiation” via text. arXiv preprint arXiv:2406.07496. Cited by: §IX-B.