{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:GI7PFT63LMQZDATECRWAVYNHY2","short_pith_number":"pith:GI7PFT63","schema_version":"1.0","canonical_sha256":"323ef2cfdb5b21918264146c0ae1a7c69e836bbd0bf927723308e577d349f9d8","source":{"kind":"arxiv","id":"2407.20859","version":1},"attestation_state":"computed","paper":{"title":"Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Ahmed Salem, Boyang Zhang, Michael Backes, Savvas Zannettou, Yang Zhang, Yicong Tan, Yun Shen","submitted_at":"2024-07-30T14:35:31Z","abstract_excerpt":"Recently, autonomous agents built on large language models (LLMs) have experienced significant development and are being deployed in real-world applications. These agents can extend the base LLM's capabilities in multiple ways. For example, a well-built agent using GPT-3.5-Turbo as its core can outperform the more advanced GPT-4 model by leveraging external components. More importantly, the usage of tools enables these systems to perform actions in the real world, moving from merely generating text to actively interacting with their environment. Given the agents' practical applications and the"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.20859","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-07-30T14:35:31Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"ecb7c80a31e73a9d9067d911d90c529d997278d62f71ace8e2c8c791dca06f2b","abstract_canon_sha256":"2411fed42b03fe1539ec821628e2fa4e94019054025501157601ec7cc5817d99"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:50:19.374152Z","signature_b64":"h3XmyqIcNRkyOpwH1pDU6CXxPGwnLd10ZPEUQxv+fZt+tkfEywsV7rc0z7cgBzB8iAWA5lGU6KtEdPi3b6MCBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"323ef2cfdb5b21918264146c0ae1a7c69e836bbd0bf927723308e577d349f9d8","last_reissued_at":"2026-07-05T08:50:19.373691Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:50:19.373691Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Ahmed Salem, Boyang Zhang, Michael Backes, Savvas Zannettou, Yang Zhang, Yicong Tan, Yun Shen","submitted_at":"2024-07-30T14:35:31Z","abstract_excerpt":"Recently, autonomous agents built on large language models (LLMs) have experienced significant development and are being deployed in real-world applications. These agents can extend the base LLM's capabilities in multiple ways. For example, a well-built agent using GPT-3.5-Turbo as its core can outperform the more advanced GPT-4 model by leveraging external components. More importantly, the usage of tools enables these systems to perform actions in the real world, moving from merely generating text to actively interacting with their environment. Given the agents' practical applications and the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.20859","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.20859/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.20859","created_at":"2026-07-05T08:50:19.373746+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.20859v1","created_at":"2026-07-05T08:50:19.373746+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.20859","created_at":"2026-07-05T08:50:19.373746+00:00"},{"alias_kind":"pith_short_12","alias_value":"GI7PFT63LMQZ","created_at":"2026-07-05T08:50:19.373746+00:00"},{"alias_kind":"pith_short_16","alias_value":"GI7PFT63LMQZDATE","created_at":"2026-07-05T08:50:19.373746+00:00"},{"alias_kind":"pith_short_8","alias_value":"GI7PFT63","created_at":"2026-07-05T08:50:19.373746+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":8,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2506.02546","citing_title":"To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":92,"is_internal_anchor":false},{"citing_arxiv_id":"2503.18666","citing_title":"AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents","ref_index":52,"is_internal_anchor":false},{"citing_arxiv_id":"2410.09024","citing_title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03242","citing_title":"Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":112,"is_internal_anchor":false},{"citing_arxiv_id":"2604.20994","citing_title":"Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models","ref_index":27,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2","json":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2.json","graph_json":"https://pith.science/api/pith-number/GI7PFT63LMQZDATECRWAVYNHY2/graph.json","events_json":"https://pith.science/api/pith-number/GI7PFT63LMQZDATECRWAVYNHY2/events.json","paper":"https://pith.science/paper/GI7PFT63"},"agent_actions":{"view_html":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2","download_json":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2.json","view_paper":"https://pith.science/paper/GI7PFT63","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.20859&json=true","fetch_graph":"https://pith.science/api/pith-number/GI7PFT63LMQZDATECRWAVYNHY2/graph.json","fetch_events":"https://pith.science/api/pith-number/GI7PFT63LMQZDATECRWAVYNHY2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2/action/storage_attestation","attest_author":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2/action/author_attestation","sign_citation":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2/action/citation_signature","submit_replication":"https://pith.science/pith/GI7PFT63LMQZDATECRWAVYNHY2/action/replication_record"}},"created_at":"2026-07-05T08:50:19.373746+00:00","updated_at":"2026-07-05T08:50:19.373746+00:00"}