SwarmGov-ZT: Zero-Trust Runtime Governance for Trust-Aware Multi-Agent Cybersecurity Response
Wei-Yu Chen, Tsang-Long Pao, Yu-Cheng KaoTool-capable multi-agent systems can improve cybersecurity response, but collaboration also creates new failure modes: compromised agents can bias shared evidence, overconfident recommendations can propagate through a coalition, and apparently correct reasoning can still trigger unauthorized tools. This paper presents SwarmGov-ZT, a zero-trust runtime-governance framework that separates evidential trust from operational authority through identity-bound capability manifests, mission-scoped authorization, outcome-updated trust, evidence-weighted fusion, a governance risk score (GRS), a non-bypassable policy enforcement point (PEP), human approval thresholds, and append-only decision traces. The framework was evaluated in a controlled simulator using 30 fixed seeds and 4000 missions per seed (120,000 default-condition missions), with 25% compromised agents by default. In the final experiment, SwarmGov-ZT achieved 91.08% exact four-class governance-decision accuracy (95% CI half-width 0.17 percentage points), 92.83% macro-F1, and 93.91% policy compliance, while limiting policy violations to 6.09% and false mitigation to 2.83%. Relative to an equal-sized non-governed swarm, exact accuracy increased by 11.41 percentage points (paired dz = 9.93; one-sided Wilcoxon W = 465, p = 8.66 × 1. Per-class F1 scores were 91.84% for Permit, 89.31% for Modify, 91.08% for Escalate, and 99.11% for Deny. Under a 50% compromised-agent stress condition, exact accuracy remained 87.88%. Ablation results show that dynamic trust and hard governance rules provide the main measurable gains, whereas evidence weighting has a negligible marginal effect under the present synthetic evidence-quality distribution. These results support controlled mechanism feasibility and reproducibility under the stated simulator assumptions; they do not establish production-SOC or natural-language prompt-injection robustness.