{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:5CGJPQWISKYRM64W5533ZYL2KO","short_pith_number":"pith:5CGJPQWI","schema_version":"1.0","canonical_sha256":"e88c97c2c892b1167b96ef77bce17a53a713b5cca5311ae0b27bbc839c9b17bd","source":{"kind":"arxiv","id":"2505.12442","version":3},"attestation_state":"computed","paper":{"title":"IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Daoyuan Wu, Liwen Wang, Shing-Chi Cheung, Shuai Wang, Wenxuan Wang, Zhenlan Ji, Zongjie Li, Zongyi Lyu","submitted_at":"2025-05-18T14:31:45Z","abstract_excerpt":"The rapid advancement of Large Language Models (LLMs) has led to the emergence of Multi-Agent Systems (MAS) to perform complex tasks through collaboration. However, the intricate nature of MAS, including their architecture and agent interactions, raises significant concerns regarding intellectual property (IP) protection. In this paper, we introduce MASLEAK, a novel attack framework designed to extract sensitive information from MAS applications. MASLEAK targets a practical, black-box setting, where the adversary has no prior knowledge of the MAS architecture or agent configurations. The adver"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.12442","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-05-18T14:31:45Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"398f759b3033a54e171e144e957a928138c054edbbcd9971e6a1a456406b1fd2","abstract_canon_sha256":"78120b64863d7dd21f854c7667aba81cf70b9f9d4ca0a106c75132e05ed8f050"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:22:40.333654Z","signature_b64":"XJSeSQ+pNZSuXUwiWTykOUM9mXoMQQkr7R5BMIry5Qr6LCoWSSPTKzClI6y4uTLG4A99Bec49cVL25oEn5EuBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e88c97c2c892b1167b96ef77bce17a53a713b5cca5311ae0b27bbc839c9b17bd","last_reissued_at":"2026-07-05T11:22:40.333153Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:22:40.333153Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Daoyuan Wu, Liwen Wang, Shing-Chi Cheung, Shuai Wang, Wenxuan Wang, Zhenlan Ji, Zongjie Li, Zongyi Lyu","submitted_at":"2025-05-18T14:31:45Z","abstract_excerpt":"The rapid advancement of Large Language Models (LLMs) has led to the emergence of Multi-Agent Systems (MAS) to perform complex tasks through collaboration. However, the intricate nature of MAS, including their architecture and agent interactions, raises significant concerns regarding intellectual property (IP) protection. In this paper, we introduce MASLEAK, a novel attack framework designed to extract sensitive information from MAS applications. MASLEAK targets a practical, black-box setting, where the adversary has no prior knowledge of the MAS architecture or agent configurations. The adver"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.12442","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.12442/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.12442","created_at":"2026-07-05T11:22:40.333212+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.12442v3","created_at":"2026-07-05T11:22:40.333212+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.12442","created_at":"2026-07-05T11:22:40.333212+00:00"},{"alias_kind":"pith_short_12","alias_value":"5CGJPQWISKYR","created_at":"2026-07-05T11:22:40.333212+00:00"},{"alias_kind":"pith_short_16","alias_value":"5CGJPQWISKYRM64W","created_at":"2026-07-05T11:22:40.333212+00:00"},{"alias_kind":"pith_short_8","alias_value":"5CGJPQWI","created_at":"2026-07-05T11:22:40.333212+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2512.04129","citing_title":"Don't Trust Your Upstream: Exploiting LLM Multi-Agent System via Topology-Guided Adversarial Propagation","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":172,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11514","citing_title":"FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems","ref_index":52,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11036","citing_title":"Sequential Behavioral Watermarking for LLM Agents","ref_index":34,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO","json":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO.json","graph_json":"https://pith.science/api/pith-number/5CGJPQWISKYRM64W5533ZYL2KO/graph.json","events_json":"https://pith.science/api/pith-number/5CGJPQWISKYRM64W5533ZYL2KO/events.json","paper":"https://pith.science/paper/5CGJPQWI"},"agent_actions":{"view_html":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO","download_json":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO.json","view_paper":"https://pith.science/paper/5CGJPQWI","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.12442&json=true","fetch_graph":"https://pith.science/api/pith-number/5CGJPQWISKYRM64W5533ZYL2KO/graph.json","fetch_events":"https://pith.science/api/pith-number/5CGJPQWISKYRM64W5533ZYL2KO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO/action/storage_attestation","attest_author":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO/action/author_attestation","sign_citation":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO/action/citation_signature","submit_replication":"https://pith.science/pith/5CGJPQWISKYRM64W5533ZYL2KO/action/replication_record"}},"created_at":"2026-07-05T11:22:40.333212+00:00","updated_at":"2026-07-05T11:22:40.333212+00:00"}