{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:3AZG7ROUFXTFZDFEQ3NGFT24ZQ","short_pith_number":"pith:3AZG7ROU","schema_version":"1.0","canonical_sha256":"d8326fc5d42de65c8ca486da62cf5ccc1cbee85a44a032654b02bb82902e298f","source":{"kind":"arxiv","id":"2507.13038","version":1},"attestation_state":"computed","paper":{"title":"MAD-Spear: A Conformity-Driven Prompt Injection Attack on Multi-Agent Debate Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hongyang Du, Yu Cui","submitted_at":"2025-07-17T12:09:39Z","abstract_excerpt":"Multi-agent debate (MAD) systems leverage collaborative interactions among large language models (LLMs) agents to improve reasoning capabilities. While recent studies have focused on increasing the accuracy and scalability of MAD systems, their security vulnerabilities have received limited attention. In this work, we introduce MAD-Spear, a targeted prompt injection attack that compromises a small subset of agents but significantly disrupts the overall MAD process. Manipulated agents produce multiple plausible yet incorrect responses, exploiting LLMs' conformity tendencies to propagate misinfo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.13038","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-07-17T12:09:39Z","cross_cats_sorted":[],"title_canon_sha256":"1f002be0695f0637e390388d24d39fcf177c98ac191fbd5dcfb07de399ad5915","abstract_canon_sha256":"803103367ca2523b986278561cdb3d94e59ea2377b9ccdd1b70b5e1950592fc0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:38:53.560088Z","signature_b64":"KA2LLrgjl073CfQMF839ekI5CuzW/yJr0jxeLZ0th7bxiQhdg9hWMsX9tCpefrFTX54Kuz22BpjqSLD+tcfHBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d8326fc5d42de65c8ca486da62cf5ccc1cbee85a44a032654b02bb82902e298f","last_reissued_at":"2026-07-05T11:38:53.559596Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:38:53.559596Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"MAD-Spear: A Conformity-Driven Prompt Injection Attack on Multi-Agent Debate Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hongyang Du, Yu Cui","submitted_at":"2025-07-17T12:09:39Z","abstract_excerpt":"Multi-agent debate (MAD) systems leverage collaborative interactions among large language models (LLMs) agents to improve reasoning capabilities. While recent studies have focused on increasing the accuracy and scalability of MAD systems, their security vulnerabilities have received limited attention. In this work, we introduce MAD-Spear, a targeted prompt injection attack that compromises a small subset of agents but significantly disrupts the overall MAD process. Manipulated agents produce multiple plausible yet incorrect responses, exploiting LLMs' conformity tendencies to propagate misinfo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.13038","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.13038/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.13038","created_at":"2026-07-05T11:38:53.559648+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.13038v1","created_at":"2026-07-05T11:38:53.559648+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.13038","created_at":"2026-07-05T11:38:53.559648+00:00"},{"alias_kind":"pith_short_12","alias_value":"3AZG7ROUFXTF","created_at":"2026-07-05T11:38:53.559648+00:00"},{"alias_kind":"pith_short_16","alias_value":"3AZG7ROUFXTFZDFE","created_at":"2026-07-05T11:38:53.559648+00:00"},{"alias_kind":"pith_short_8","alias_value":"3AZG7ROU","created_at":"2026-07-05T11:38:53.559648+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.28958","citing_title":"When Latent Agents Lie: KV-Cache Integrity in Multi-Agent LLM Collaboration","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2606.00820","citing_title":"Not All Flips Are Conformity: Decomposing Stance Convergence in Multi-Agent LLM Debate","ref_index":20,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ","json":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ.json","graph_json":"https://pith.science/api/pith-number/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/graph.json","events_json":"https://pith.science/api/pith-number/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/events.json","paper":"https://pith.science/paper/3AZG7ROU"},"agent_actions":{"view_html":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ","download_json":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ.json","view_paper":"https://pith.science/paper/3AZG7ROU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.13038&json=true","fetch_graph":"https://pith.science/api/pith-number/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/graph.json","fetch_events":"https://pith.science/api/pith-number/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/action/storage_attestation","attest_author":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/action/author_attestation","sign_citation":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/action/citation_signature","submit_replication":"https://pith.science/pith/3AZG7ROUFXTFZDFEQ3NGFT24ZQ/action/replication_record"}},"created_at":"2026-07-05T11:38:53.559648+00:00","updated_at":"2026-07-05T11:38:53.559648+00:00"}