ShadowMesh: An Execution-Validated Causal Graph Learning Architecture for Detecting Hidden Agent Coalitions, Tracing Malicious Interaction Paths, and Supporting Trustworthy Autonomous Cyber Defense Governance

Authors

  • Mohammed Al-Naeem Department of Computer Networks and Communications, College of Computer Sciences & Information Technology, King Faisal University, Al Ahsa, 31982, Saudi Arabia.

DOI:

https://doi.org/10.56979/1101/2026/1491

Keywords:

Autonomous Cyber Defense, Multi-Agent Security, Malicious Coalition Detection, Temporal Graph Learning, Causal Explainability, CybORG, Security Operations Center

Abstract

Autonomous cyber-defense agents can shorten security-operations-center response time by coordinating telemetry collection, triage, remediation, and reporting. Their collaborative behavior, however, also creates an integrity risk: a compromised or strategically misaligned subgroup can suppress alerts, inject corroborating but misleading evidence, or coordinate unsafe response actions while each individual action appears operationally plausible. This study introduces ShadowMesh, an empirical CybORG-based causal temporal graph framework for detecting and attributing covert collusion in autonomous multi-agent cyber defense networks. The framework was executed across reproducible benign, competitive, and four malicious-coalition behaviors, yielding 2,400 mission episodes and 28,800 temporally aligned graph windows from agent-action sequences, message metadata, tool-call records, and system observations. ShadowMesh uses typed temporal interaction graphs, masked evidence channels for incomplete telemetry, a causal temporal graph transformer, and coalition-level risk scoring to jointly determine whether collusion exists, which coalition pattern is active, which agents are implicated, and which interaction paths support the alert. Episode-disjoint 70/15/15 splits, five controlled random seeds, and stress conditions involving communication delay, missing logs, noisy tool records, heterogeneous agents, and unseen missions were evaluated through actual repeated CybORG executions. The complete model achieved a macro-F1 of 97.2%, a false-positive rate of 1.1%, coalition-attribution accuracy of 96.4%, and a median decision delay of 1.72 s, outperforming static graph, temporal graph, and non-causal variants. Performance remained at or above 93.1% macro-F1 under the reported delay, missing-log, noisy-record, and unseen-mission stress conditions. These results are empirical outcomes of repeated CybORG experiment executions rather than illustrative or fixed numerical arrays; although they are not field-SOC deployment measurements, they demonstrate how causal relational evidence can provide a defensible monitoring layer for autonomous SOC ecosystems where reliable agent accountability is as important as detection accuracy.

Downloads

Published

2026-06-01

How to Cite

Mohammed Al-Naeem. (2026). ShadowMesh: An Execution-Validated Causal Graph Learning Architecture for Detecting Hidden Agent Coalitions, Tracing Malicious Interaction Paths, and Supporting Trustworthy Autonomous Cyber Defense Governance. Journal of Computing & Biomedical Informatics, 11(01). https://doi.org/10.56979/1101/2026/1491