English

Thought Virus: Viral Misalignment via Subliminal Prompting in Multi-Agent Systems

Multiagent Systems 2026-03-03 v1 Artificial Intelligence

Abstract

Subliminal prompting is a phenomenon in which language models are biased towards certain concepts or traits through prompting with semantically unrelated tokens. While prior work has examined subliminal prompting in user-LLM interactions, potential bias transfer in multi-agent systems and its associated security implications remain unexplored. In this work, we show that a single subliminally prompted agent can spread a weakening but persisting bias throughout its entire network. We measure this phenomenon across 6 agents using two different topologies, observing that the transferred concept maintains an elevated response rate throughout the network. To exemplify potential misalignment risks, we assess network performance on multiple-choice TruthfulQA, showing that subliminal prompting of a single agent may degrade the truthfulness of other agents. Our findings reveal that subliminal prompting introduces a new attack vector in multi-agent security, with implications for the alignment of such systems. The implementation of all experiments is publicly available at https://github.com/Multi-Agent-Security-Initiative/thought_virus .

Keywords

Cite

@article{arxiv.2603.00131,
  title  = {Thought Virus: Viral Misalignment via Subliminal Prompting in Multi-Agent Systems},
  author = {Moritz Weckbecker and Jonas Müller and Ben Hagag and Michael Mulet},
  journal= {arXiv preprint arXiv:2603.00131},
  year   = {2026}
}

Comments

18 pages, 10 figures, 2 tables. Code available at https://github.com/Multi-Agent-Security-Initiative/thought_virus

R2 v1 2026-07-01T10:56:18.331Z