Pith. sign in

Paper Citation Record · LEDGER

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures

As of 18 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2608.00718.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00718 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-15T15:21:10.198301Z

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-18T06:34:40.430872+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved16
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9c75200f-a698-4f47-a64a-f0bf7187bcca · outbound

This paper cites A survey on large language model based autonomous agents,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures A survey on large language model based autonomous agents,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.050150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.050150Z digest=sha256:0e09314edc67934a5553fe446b961c2e36a19518e69f145ef0c30004440ccbba

Observation 7ad6c78e-05b6-4f3a-97df-5de191dd9add · outbound

This paper cites Autogen: Enabling next-gen llm applications via multi-agent conversations,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Autogen: Enabling next-gen llm applications via multi-agent conversations,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.055930Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.055930Z digest=sha256:e6c258da9f0ea0a325f2463ceb26264f1aa19182f1af429fdd65d5c6a52066b3

Observation 19b79064-35aa-4ac1-945f-86014d68d124 · outbound

This paper cites Langchain,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Langchain,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.697928Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.061043Z digest=sha256:0971ca823f1907962ca52beaff65986dc38562654919e1f015eea729e45eeab3

Observation 32c978f4-7a71-4808-a16f-9c8b54dfb8ff · outbound

This paper cites Gaia: a benchmark for general ai assistants,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Gaia: a benchmark for general ai assistants,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.066037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.066037Z digest=sha256:499cd90e29bfed0245b19e7ccf77e1c4de6b9ba510eda84ff97c5a941be6be52

Observation f8057482-a793-4683-b741-75b8155fde69 · outbound

This paper cites SWE-bench: Can Language Models Resolve Real-World GitHub Issues?.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures SWE-bench: Can Language Models Resolve Real-World GitHub Issues?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.071558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.071558Z digest=sha256:c1f06a6d1f4afd45804b365e15f2a982fe59d544adb5d413c1e1760920c50ce9

Observation 9790e6ee-106e-4444-835c-bdb3eb1b8239 · outbound

This paper cites Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast,

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.667432Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.077284Z digest=sha256:82e328212f8ee78d4a4000b17a3993636ab49d1d7d6468edcd527bed5185d699

Observation 032f3d8d-4b5a-4368-a791-26a9cac76b8f · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.082569Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.082569Z digest=sha256:7aa0abd9d7f48e358c98b19bb49c9b67f59549e83c9691191da0dc2d9c98046e

Observation 433188f8-48e3-4a14-adb7-f254b4811c27 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.649389Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.087640Z digest=sha256:963e1d17dc2951a5566220938a6fb5a518bc505efe5c46c831c39d5c749f482c

Observation 1d671167-1bc3-4aad-b901-35efc656267a · outbound

This paper cites {PoisonedRAG}: Knowledge corruption attacks to{Retrieval-Augmented}generation of large language models,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures {PoisonedRAG}: Knowledge corruption attacks to{Retrieval-Augmented}generation of large language models,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.632447Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.092972Z digest=sha256:b560586f92f684161f543f7c6d6c4982b380558c600a5a72706d6510eccf5c38

Observation c470a0e1-0f96-4143-adff-26ae77737033 · outbound

This paper cites The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.097661Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.097661Z digest=sha256:63a6ea451a5e25015224cdedc38da14b955223aa4fbc43c55abedd7e12f34299

Observation 5c7f2d26-5329-49f3-be99-5d649822860c · outbound

This paper cites Trism for agentic ai: A review of trust, risk, and security management in llm-based agentic multi-agent systems,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Trism for agentic ai: A review of trust, risk, and security management in llm-based agentic multi-agent systems,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.613142Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.102843Z digest=sha256:d8536ffc48e871a11be184725887ee77668dfb2bdafc88846f9d323c9965133c

Observation 16b69702-f144-4a76-9b1f-60b8dd6f9511 · outbound

This paper cites Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.107915Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.107915Z digest=sha256:938a880305917894631015b2d6da5694139b03c3d7813a0b5f8b2dd5700847ac

Observation 3a7de3e8-c61e-440d-a4d0-7444fa2e6e59 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Ai agents under threat: A survey of key security challenges and future pathways,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.113080Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.113080Z digest=sha256:0567b1ce3093f976e2036c9aee698007aa56ed8cdb29dc1d65ed94a6469e7aff

Observation 6e71bfcf-8514-47b0-a6c7-9df787256ac9 · outbound

This paper cites The emerged security and privacy of llm agent: A survey with case studies,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The emerged security and privacy of llm agent: A survey with case studies,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.117767Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.117767Z digest=sha256:8ed269db3e5733ebb52298851d827537c35d2c5c43c1232c55cab71cf81d78bd

Observation 7713eb91-9e44-4cb3-8fae-bbbfeb5cf02b · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Formalizing and benchmarking prompt injection attacks and defenses,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.122785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.122785Z digest=sha256:782f5b0fc96b8fcb0a4533b2c7725b7ca637e2c00e5716b29a5f685b663e531d

Observation 3f8e5408-860e-4838-8009-ea9b2e915428 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.556685Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.128824Z digest=sha256:67f895a60a59f6497f2980367a76012165b345284716fef606e8f6ceec94b8bc

Observation 16e07227-31ea-42d6-ab06-626635e65dcc · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.136135Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.136135Z digest=sha256:1f25995f94b260f8721b22f6e468b7a09e8d27b5ca4ee3ad1b93fd3387606fb0

Observation 36c5ff14-0e72-461d-a2be-a9f61fbdf582 · outbound

This paper cites TRAIL: Trace Reasoning and Agentic Issue Localization.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures TRAIL: Trace Reasoning and Agentic Issue Localization

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.141337Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.141337Z digest=sha256:748939d0406db4624e314b98f1da738699bab90fe0b6ce532018aee7c30c60f0

Observation 2705ec38-bc05-47ce-b692-4ba22db0802f · outbound

This paper cites Gpt-5 mini,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Gpt-5 mini,

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.539460Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.146788Z digest=sha256:93df0ac9d1cb004fbc1dec6d43ff7473b119cdcc46c0de44599a381987244c94

Observation 747392b1-ebb6-4342-8549-6fc2c0f8f762 · outbound

This paper cites Claude sonnet 4.5,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Claude sonnet 4.5,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.514039Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.151796Z digest=sha256:45cb09e6d795cae1bbbef284fef3094d6c71082e8c2bd88120bb6fec0c50df6c

Observation 119ae632-4252-4263-b37c-d6b2316ba46c · outbound

This paper cites Kimi k2.5,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Kimi k2.5,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.495478Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.156704Z digest=sha256:399a3e8b96e4efec6f126a564b1dc04d92e678be8c57b60d53df1e9fa51972f9

Observation 789da312-d8c1-4147-abb6-8a554a5255bd · outbound

This paper cites Practical byzantine fault tolerance,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Practical byzantine fault tolerance,

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.478284Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.161477Z digest=sha256:c8439aaef2d0fda7c1eac05a47474a1e2801f82eeb5d668d62a85543f5676e0d

Observation 44ad6d21-94f7-47b1-b9c7-72acdf0a1d7b · outbound

This paper cites Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.166487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.166487Z digest=sha256:1056426586cfc5d7353e6e86e4bcc0c43f17bfcfec51e30329fa3c918649aaae

Observation 94092aae-9710-436a-8486-5647ef7e4673 · outbound

This paper cites Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.172332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.172332Z digest=sha256:2995c184caa1a06f56bb12bbe8c248a771ff449490896f49efc589044ca45b78

Observation 224bc76c-c2a3-4e1c-9444-032c718705c2 · outbound

This paper cites Secret collusion among ai agents: Multi- agent deception via steganography,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Secret collusion among ai agents: Multi- agent deception via steganography,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.462074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.177425Z digest=sha256:f2fec0d3e22e9d60119a604323f1448af859bb0245d30e6dabdbeee4309f9091

Observation 09799ee7-bede-4133-a95f-4a22a85bdebd · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.443889Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.182557Z digest=sha256:5165f12463e9978ece646ad2f1db142dc870be7137406caea3a73270406b9e3f

Observation 91332909-a426-4871-a9df-4a28654b5784 · outbound

This paper cites Psysafe: A comprehensive framework for psychological- based attack, defense, and evaluation of multi-agent system safety,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Psysafe: A comprehensive framework for psychological- based attack, defense, and evaluation of multi-agent system safety,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.426117Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.187512Z digest=sha256:97b9a1bb67c490d72b35f688f5eb07e3fe7ba42fbab9abc2b50b4cf5eef1afb8

Observation 60b68910-3e3b-4683-ad27-bd0fb2648e82 · outbound

This paper cites AutoDefense: Multi-Agent LLM Defense against Jailbreak Attacks.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures AutoDefense: Multi-Agent LLM Defense against Jailbreak Attacks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.192438Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.192438Z digest=sha256:c3bbfc4f8c0bf60113143b2059b506824138759ae2fd27fa604c26a4c09ef329

Observation f7b82da2-f717-4841-88c5-1a53ad6b72f0 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.198301Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.198301Z digest=sha256:938f165b2240e1bfda4bda1bb198067dc586a9b72755ffca0c221071c9d79c38

Pith citing papers

No inbound Pith citation observations are available.