Securing Multi-Agent GIS Systems: Risk Evaluation and Prompt Hardening Optimization
For developers of multi-agent GIS systems, this work provides a practical security framework, though the approach is incremental.
This paper addresses security risks in multi-agent GIS systems by developing a framework for risk identification, evaluation, and mitigation, including a prompt optimization method that improves resilience without degrading task performance.
Agentic systems are increasingly integrated with geographic information systems (GIS), where multi-agent coordination enables complex conversational and spatial analysis but introduces security risks. This work presents a security-oriented framework for risk identification, evaluation, and mitigation in a multi-agent GIS system while maintaining adaptability to broader agentic architectures. We test the agentic system of a commercial geospatial partner while developing a modular state-machine-based orchestration framework that abstracts agent behavior into reusable components. We evaluate robustness using a red-teaming framework with an adaptive attacker LLM and a deterministic judge that produces binary outcomes with supporting rationales across multi-turn attacks. We further improve resilience with a prompt optimization framework that treats prompts as structured signatures and injects adversarial demonstrations, enabling systematic security improvements without degrading task performance.