{"id":"82660591-a1eb-47f9-b774-c6df88e7e5ec","arxiv_id":"2607.12742","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"At Stackelberg equilibrium, the defender’s re-key cadence for CKKS-encrypted multi-agent control is set by the control-theoretic fragility of the agent graph topology.","lead":"The paper models encrypted multi-agent control under an advanced persistent threat as a two-phase game and argues that re-keying cadence should track the control graph’s fragility. A generalist may care because it ties network topology stability to the real cost of keeping cloud-coordinated agents private under approximate FHE.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.5","headline":"Abstract-only review leaves the Stackelberg equilibrium and topology-to-cadence mapping uncheckable; the residual-detector separation is the clearest load-bearing premise that cannot be verified.","rationale":"The Reader correctly flags that an abstract-only review cannot support ACCEPT/CONDITIONAL/REJECT and that the residual-detector separation plus rational stealth is the weakest structural premise visible. That premise is load-bearing for the two-phase game and therefore for the topology-determined re-key cadence. No stronger internal inconsistency can be demonstrated without the body; manufacturing one would violate good-faith review. Hence the verdict stays UNVERDICTED, confidence remains low, and the concrete test is simply the first verification that becomes possible once the full text is available. Agreement with the Reader is complete on both the identified soft spot and the information-theoretic reason for non-verdict.","tokens_in":2192,"tokens_out":561,"duration_ms":4635,"concrete_test":"When the full paper appears, extract the residual-detector definition and the Stackelberg payoff functions; verify whether the detector statistic is formally independent of CKKS decryption noise (or of any passive-phase leakage term). Independently re-derive the equilibrium re-key interval for a path graph versus a complete graph under the stated dynamics; if the interval ratio does not match the claimed fragility ordering, or if the detector couples to noise, the cadence claim fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that, at Stackelberg equilibrium of the active detection-evasion timing game, the defender re-keys on the laziest cadence that denies a stealthy adversary, and that cadence is set by control-theoretic fragility of the multi-agent graph (marginally-stable graphs re-key far more often). Because only the abstract is available, neither the game payoff structure, the residual-detector model, the mapping from graph spectrum/fragility to re-key interval, nor any equilibrium derivation can be inspected. The single most load-bearing premise visible is the clean separation: the residual detector “sees only the manipulation,” so the passive key-recovery leakage from CKKS decryption noise does not trigger detection and the rational adversary optimally remains stealthy rather than attacking overtly. If that separation fails (detector also registers passive leakage, or adversary is not rational/stealthy), the two-phase timing game is ill-posed and the claimed equilibrium cadence does not follow. No equations, proofs, or experiments exist in the provided material to confirm the separation or the topology dependence, so the claim remains uncheckable rather than internally refuted.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript models the security of multi-agent control under approximate FHE (CKKS) as a two-phase advanced persistent threat game: a passive reconnaissance phase driven by key-recovery leakage from decryption noise, followed by an active stealthy-manipulation phase. The phases are separated by a residual detector that, by assumption, observes only active manipulation. The passive phase is said to reduce to a known flooding tradeoff; the active phase is cast as a detection-evasion timing game whose Stackelberg equilibrium has the defender re-keying at the laziest cadence that still denies the adversary. That cadence is claimed to be set by the control-theoretic fragility of the multi-agent graph topology, so that marginally stable graphs must re-key far more often than well-connected ones. A three-way tension among FHE precision, control accuracy, and re-key cadence is asserted to define a securability window between a floor and a static-suffices ceiling, with re-keying presented as the price of precision efficiency. The broader framing is that security for an approximate cryptosystem inside a feedback loop is a dynamic game whose defender move is the scheme’s own refresh.","tokens_in":2443,"tokens_out":1179,"duration_ms":18861,"significance":"If the Stackelberg equilibrium derivation and the topology-to-cadence mapping are correct, the paper would supply a concrete, control-theoretic rule for re-keying policy in encrypted multi-agent systems, moving the literature beyond honest-but-curious cloud models and purely static analyses of approximate FHE. Explicitly treating re-keying (rather than bootstrapping) as the defender’s response to accumulated leakage, and identifying a precision–accuracy–cadence design window, would be practically useful. The reduction of the passive phase to a known flooding tradeoff and the game-theoretic (rather than fitted) character of the central claim are strengths if fully substantiated. The broader claim that any system that must repeatedly decrypt to act faces an analogous dynamic game is a potentially transferable framing contribution.","major_comments":[{"comment":"Only the abstract is available for this review; the Stackelberg equilibrium of the active detection-evasion timing game, the payoff structure, and the claimed mapping from multi-agent graph fragility to re-key cadence are therefore uncheckable. Without the equilibrium derivation, lemmas, or any supporting analysis, the central claim that the defender’s optimal cadence is set by topology cannot be assessed for correctness.","section":"Abstract (full text unavailable)"},{"comment":"The load-bearing separation premise—that a residual detector “sees only the manipulation” and does not register passive key-recovery leakage from CKKS decryption noise—is asserted but not justified in the available text. If the detector also observes passive leakage, or if the adversary is not rational/stealthy, the two-phase game is ill-posed and the equilibrium re-key cadence does not follow. This axiom must be stated formally and defended (or relaxed) before the equilibrium claim can be accepted.","section":"Abstract (residual-detector separation)"},{"comment":"The claim that the passive phase “reduces to the known flooding tradeoff” is stated without a reduction argument, reference to the precise prior result, or error analysis. Because the active-phase equilibrium is said to rest on this reduction, the reduction itself is load-bearing and must be supplied with explicit assumptions and bounds.","section":"Abstract (passive-phase reduction)"},{"comment":"The three-way precision–accuracy–cadence window (securability floor to static-suffices ceiling) is asserted as the region in which the game lives, yet no quantitative characterization, inequalities, or numerical illustration appears in the available material. Without that characterization the design claim remains programmatic rather than demonstrated.","section":"Abstract (three-way tension / securability window)"}],"minor_comments":[{"comment":"The abstract uses “measured residual detector” without defining what is measured or how the residual is formed; a one-sentence clarification would help readers who are not already in the encrypted-control literature.","section":"Abstract"},{"comment":"“Laziest cadence that denies the stealthy adversary” is evocative but informal; once the full text is available, a precise mathematical definition (e.g., maximal re-key interval that keeps adversary value below a threshold) should appear early.","section":"Abstract"},{"comment":"The broader applicability claim (“applying beyond control to any system that must repeatedly decrypt to act”) is interesting but currently unsupported; even a short discussion paragraph or related-work pointer would strengthen it.","section":"Abstract (closing sentence)"}],"recommendation":"uncertain","confidential_remarks":"This is an abstract-only review; the full manuscript was not available. I cannot responsibly recommend accept, minor_revision, major_revision, or reject on the basis of the abstract alone. The central claims are coherent and potentially significant, but every load-bearing step (detector separation, passive-phase reduction, Stackelberg derivation, topology-to-cadence map, precision–accuracy–cadence window) is currently uninspectable. Once the full paper is supplied, a normal technical review should be possible; until then the only defensible recommendation is uncertain. Scope appears appropriate for a cs.CR / cyber-physical security venue if the technical content materializes."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The punchline is simple: this paper treats re-keying under an APT for CKKS-encrypted multi-agent control as a two-phase Stackelberg timing game, and claims the equilibrium cadence is set by the control-theoretic fragility of the communication graph. Marginally stable topologies must re-key far more often than well-connected ones. That link is the thing worth knowing.\n\nWhat is actually new is the packaging. Static FHE security and honest-but-curious encrypted control are already on the table; the authors fold CKKS decryption-noise leakage, residual detection that is claimed to see only active manipulation, re-keying (not bootstrapping) as the defender’s refresh, and multi-agent graph spectrum into one detection-evasion game. The passive phase is said to reduce to the known flooding tradeoff; the active phase yields a laziest-safe re-key schedule. They also flag a three-way window among FHE precision, control accuracy, and re-key cadence, with a securability floor and a static-suffices ceiling. That framing is coherent and useful for the subfield.\n\nThe soft spots are exactly what you expect from an abstract-only read. No equations, no payoff structure, no residual-detector model, no spectral mapping, and no equilibrium derivation are visible, so the central claim cannot be checked. The load-bearing premise is the clean separation: the detector sees only manipulation, not passive key-recovery leakage, and the adversary therefore stays stealthy. If that fails, the two-phase game is ill-posed. Circularity looks low; they are not fitting free parameters and calling it prediction. Soundness is simply unverified rather than refuted.\n\nThis is for people who already work on encrypted control, secure multi-agent CPS, or approximate FHE in feedback loops. A control theorist who cares about topology and a crypto person who cares about refresh costs will both get something. It does not rewrite either field, but it gives a concrete design rule if the math holds.\n\nI would send it to a serious referee. The idea is sharp enough and the problem is real enough that the full paper deserves the scrutiny, even if heavy revision follows. Bring it to reading group only if someone has already pulled the PDF and can walk through the game and the graph argument; otherwise park it until the proofs are in hand.","headline":"Clean Stackelberg framing that ties CKKS re-key cadence to multi-agent graph fragility, but abstract-only so the equilibrium and detector separation stay uncheckable.","tokens_in":3088,"tokens_out":584,"would_cite":false,"duration_ms":11843,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Re-key cadence for encrypted multi-agent control is set by graph fragility: marginally stable fleets must re-key far more often.","keywords":["encrypted control","CKKS","fully homomorphic encryption","re-keying","Stackelberg game","multi-agent systems","graph topology","advanced persistent threat"],"falsifier":"On a concrete multi-agent topology, measure whether an adversary that also exploits passive decryption-noise leakage can force a materially shorter re-key interval than the paper's equilibrium predicts for that graph's fragility.","tokens_in":3032,"feed_emoji":"🔐","tokens_out":580,"duration_ms":4150,"temperature":0.7,"pith_summary":"Encrypted multi-agent control over CKKS-style approximate fully homomorphic encryption must decrypt to actuate, so encryption noise becomes an unavoidable key-recovery leak. The paper models the resulting security problem under an advanced persistent threat as a two-phase game: passive reconnaissance followed by active manipulation, separated by a residual detector that sees only the active phase. Because overt attacks are caught, a rational adversary stays stealthy; the defender's only reset is re-keying (not bootstrapping). At the Stackelberg equilibrium of the resulting detection-evasion timing game the defender re-keys on the laziest schedule that still denies the adversary, and that schedule is fixed by the control-theoretic fragility of the multi-agent graph. Marginally stable topologies must re-key far more often than well-connected ones. A three-way tension among FHE precision, control accuracy and re-key cadence therefore defines a securability window in which re-keying is simply the price of using an efficient approximate cryptosystem inside a feedback loop.","feed_headline":"Graph fragility sets how often encrypted fleets must re-key","feed_subtitle":"Marginally stable multi-agent topologies force far more frequent key refresh than well-connected ones","key_machinery":"A two-phase Stackelberg detection-evasion timing game whose phases are cleanly separated by a residual detector that observes only active manipulation; the defender's sole reset action is re-keying, which erases accumulated leakage and forces the equilibrium re-key interval to be set by graph fragility.","core_discovery":"At the Stackelberg equilibrium of the active detection-evasion timing game the defender re-keys on the laziest cadence that denies a stealthy adversary, and that cadence is dictated by the control-theoretic fragility of the multi-agent graph topology: marginally stable graphs must re-key far more frequently than well-connected ones.","pith_inferences":[],"forward_implications":[],"fun_headline_variants":["Graph fragility sets re-key cadence for encrypted multi-agent fleets","Marginally stable topologies force far more frequent re-keying","Stability buys time: re-key rate set by multi-agent graph fragility","Re-key schedule against stealthy APT fixed by control-graph fragility","Stackelberg equilibrium: fragile graphs re-key far more often"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The residual detector is assumed to see only active manipulation and not the passive key-recovery leakage from decryption noise, so the two phases cleanly separate and a rational adversary optimally stays stealthy.","fun_headline_variants_meta":{"raw":{"variants":["Graph fragility sets re-key cadence for encrypted multi-agent fleets","Marginally stable topologies force far more frequent re-keying","Stability buys time: re-key rate set by multi-agent graph fragility","Re-key schedule against stealthy APT fixed by control-graph fragility","Stackelberg equilibrium: fragile graphs re-key far more often"]},"model":"grok-4.5","effort":"low","cost_usd":0.004086,"raw_usage":{"total_tokens":1323,"prompt_tokens":867,"num_sources_used":0,"completion_tokens":96,"cost_in_usd_ticks":40860000,"prompt_tokens_details":{"text_tokens":867,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":360,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":867,"tokens_out":96,"duration_ms":4151,"temperature":1.0,"reasoning_tokens":360,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-15T03:41:57.814182+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"On a concrete multi-agent topology, measure whether an adversary that also exploits passive decryption-noise leakage can force a materially shorter re-key interval than the paper's equilibrium predicts for that graph's fragility.","supporting_citations":[],"review_version":1}