Pith. sign in

Paper Citation Record · LEDGER

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures

As of 18 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2608.00718.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00718 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-15T15:21:10.198301Z

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-18T06:34:40.430872+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved16
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9c75200f-a698-4f47-a64a-f0bf7187bcca · outbound

This paper cites A survey on large language model based autonomous agents,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures A survey on large language model based autonomous agents,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.050150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.050150Z digest=sha256:d747aacb05d108bfa6cfa4f9fcea60077477ae547de102fcffd44fd20e82b702

Observation 7ad6c78e-05b6-4f3a-97df-5de191dd9add · outbound

This paper cites Autogen: Enabling next-gen llm applications via multi-agent conversations,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Autogen: Enabling next-gen llm applications via multi-agent conversations,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.055930Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.055930Z digest=sha256:5b2c83042ede7ce7684ecb9dccd02a2ceb8471be2a43ad59225cf90014983c4d

Observation 19b79064-35aa-4ac1-945f-86014d68d124 · outbound

This paper cites Langchain,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Langchain,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.697928Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.061043Z digest=sha256:a9315608bc63023e7912fa885b126e187b21fc33360314b1833ef8cddf02748d

Observation 32c978f4-7a71-4808-a16f-9c8b54dfb8ff · outbound

This paper cites Gaia: a benchmark for general ai assistants,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Gaia: a benchmark for general ai assistants,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.066037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.066037Z digest=sha256:aaf9461c1589f0215b2e35a4d49cfe6724eb4f0e17a97d1bbcc281f7635f6cef

Observation f8057482-a793-4683-b741-75b8155fde69 · outbound

This paper cites SWE-bench: Can Language Models Resolve Real-World GitHub Issues?.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures SWE-bench: Can Language Models Resolve Real-World GitHub Issues?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.071558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.071558Z digest=sha256:5cf3b8b026bfcb0bb05fbdfc99a909236ac54818ce43228afdd04a1cdb2e30f8

Observation 9790e6ee-106e-4444-835c-bdb3eb1b8239 · outbound

This paper cites Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast,

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.667432Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.077284Z digest=sha256:dc99c77f95a356ccd5241bcc70f4005586c6787093b5cda1f43a0da1b97b9433

Observation 032f3d8d-4b5a-4368-a791-26a9cac76b8f · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.082569Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.082569Z digest=sha256:5e466666c80cc3658e7f5155991c003d5b053c9f417023eb6f4e59a695cc2e4d

Observation 433188f8-48e3-4a14-adb7-f254b4811c27 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.649389Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.087640Z digest=sha256:c2ab4f255053e726cc128395c3ec516f527e2f55c3e44f7b0999ee8f1f19d27d

Observation 1d671167-1bc3-4aad-b901-35efc656267a · outbound

This paper cites {PoisonedRAG}: Knowledge corruption attacks to{Retrieval-Augmented}generation of large language models,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures {PoisonedRAG}: Knowledge corruption attacks to{Retrieval-Augmented}generation of large language models,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.632447Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.092972Z digest=sha256:dd3bf7efd57caa86d83cfc5d120d9ab967aa595a60cfcd6a9ed4cc41772f7ddd

Observation c470a0e1-0f96-4143-adff-26ae77737033 · outbound

This paper cites The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.097661Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.097661Z digest=sha256:491a082de99d76868dc1da9a4d2c839b6d95aaa5f857451aa9db9900f93f311f

Observation 5c7f2d26-5329-49f3-be99-5d649822860c · outbound

This paper cites Trism for agentic ai: A review of trust, risk, and security management in llm-based agentic multi-agent systems,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Trism for agentic ai: A review of trust, risk, and security management in llm-based agentic multi-agent systems,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.613142Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.102843Z digest=sha256:a69fd9c9a4ebfd0975e6a68f886abfc481cf55fbfd1528055ba3db5d38465b8d

Observation 16b69702-f144-4a76-9b1f-60b8dd6f9511 · outbound

This paper cites Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.107915Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.107915Z digest=sha256:2dfabb464f3493287859050cc4271e1eab89802f8d95091c129f990ce3e6b11f

Observation 3a7de3e8-c61e-440d-a4d0-7444fa2e6e59 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Ai agents under threat: A survey of key security challenges and future pathways,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.113080Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.113080Z digest=sha256:6eba5d2e85ea3d6317eec0b0694282d44aaad4567a7b1d564112624eb9cd303a

Observation 6e71bfcf-8514-47b0-a6c7-9df787256ac9 · outbound

This paper cites The emerged security and privacy of llm agent: A survey with case studies,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The emerged security and privacy of llm agent: A survey with case studies,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.117767Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.117767Z digest=sha256:4ae69126d352b2b1d0d46c70f5029286441e44e527ad03e2fbe2d3cf694d9c94

Observation 7713eb91-9e44-4cb3-8fae-bbbfeb5cf02b · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Formalizing and benchmarking prompt injection attacks and defenses,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.122785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.122785Z digest=sha256:1515b238924daa50ce3414e2d2741dc0cb4479a3ea7776e52ceed76e5f098ba4

Observation 3f8e5408-860e-4838-8009-ea9b2e915428 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.556685Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.128824Z digest=sha256:b7b04659ba2ffd87aab1f86be4952a673720d14078397f2a30c4b0fd5525c69d

Observation 16e07227-31ea-42d6-ab06-626635e65dcc · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.136135Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.136135Z digest=sha256:9461af172de752048e83e2c3c5eb0c20059790f7857581f42e9c595d021c1723

Observation 36c5ff14-0e72-461d-a2be-a9f61fbdf582 · outbound

This paper cites TRAIL: Trace Reasoning and Agentic Issue Localization.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures TRAIL: Trace Reasoning and Agentic Issue Localization

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.141337Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.141337Z digest=sha256:37fc13e275b5006d451a7a994d45ce67b9978195a2c2c3063ea7cb1b0d780838

Observation 2705ec38-bc05-47ce-b692-4ba22db0802f · outbound

This paper cites Gpt-5 mini,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Gpt-5 mini,

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.539460Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.146788Z digest=sha256:8b6f436038385854b7d1e08058e2ebcef6be9f829d89cdd0b340a541469330bd

Observation 747392b1-ebb6-4342-8549-6fc2c0f8f762 · outbound

This paper cites Claude sonnet 4.5,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Claude sonnet 4.5,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.514039Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.151796Z digest=sha256:d631943aeff88c4f5267502c12c746cd7a9873e1bd8969acdbe351b1bbd1ce47

Observation 119ae632-4252-4263-b37c-d6b2316ba46c · outbound

This paper cites Kimi k2.5,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Kimi k2.5,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.495478Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.156704Z digest=sha256:d65da16e984827ba1da0037c013164a1b411daf9a682621fec9a7756051cacad

Observation 789da312-d8c1-4147-abb6-8a554a5255bd · outbound

This paper cites Practical byzantine fault tolerance,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Practical byzantine fault tolerance,

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.478284Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.161477Z digest=sha256:54ced9c41d40b7f9c1c82eb79b604dba6705500fd7a5c724813ab04866bdbd4d

Observation 44ad6d21-94f7-47b1-b9c7-72acdf0a1d7b · outbound

This paper cites Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.166487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.166487Z digest=sha256:93b7b7a2bc9f0fe017185fe3d24f24d01554ef0b5814573c77e992e6c1d6a184

Observation 94092aae-9710-436a-8486-5647ef7e4673 · outbound

This paper cites Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.172332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.172332Z digest=sha256:6d4e35a8219c676455bc5ae12c24133610c6e8f1a0a89cc62eb9a9d283ec4ea6

Observation 224bc76c-c2a3-4e1c-9444-032c718705c2 · outbound

This paper cites Secret collusion among ai agents: Multi- agent deception via steganography,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Secret collusion among ai agents: Multi- agent deception via steganography,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.462074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.177425Z digest=sha256:5764c61b224e5a918240e1e93493614fdfc22fadcfd83579b0cae17dab106503

Observation 09799ee7-bede-4133-a95f-4a22a85bdebd · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.443889Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.182557Z digest=sha256:4acea66430628cdfee2672ae0e2664907e225c29403a61621c75e23d625695ce

Observation 91332909-a426-4871-a9df-4a28654b5784 · outbound

This paper cites Psysafe: A comprehensive framework for psychological- based attack, defense, and evaluation of multi-agent system safety,.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures Psysafe: A comprehensive framework for psychological- based attack, defense, and evaluation of multi-agent system safety,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T15:21:10.426117Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-15T15:21:10.187512Z digest=sha256:7a9d2a1973f8ccd4dc396d9b5531e364320a1ce56fb3e2fd6a366ddd1c90fb41

Observation 60b68910-3e3b-4683-ad27-bd0fb2648e82 · outbound

This paper cites AutoDefense: Multi-Agent LLM Defense against Jailbreak Attacks.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures AutoDefense: Multi-Agent LLM Defense against Jailbreak Attacks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.192438Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.192438Z digest=sha256:0df5852e4c6562770e46e54e1c2091d762b36c12784e3e1ebe9f54415136145d

Observation f7b82da2-f717-4841-88c5-1a53ad6b72f0 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-15T15:21:10.198301Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T15:21:10.198301Z digest=sha256:b8affe187474ba54357e3363132c69cf8b2d63f64576857fa62726cdd41396b0

Pith citing papers

No inbound Pith citation observations are available.