{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:KEFS7RD7OP4D63DWK2ZER6CVCP","short_pith_number":"pith:KEFS7RD7","schema_version":"1.0","canonical_sha256":"510b2fc47f73f83f6c7656b248f85513c0ccb2c6d247cdb47f7878c24a4db4bf","source":{"kind":"arxiv","id":"2502.19145","version":2},"attestation_state":"computed","paper":{"title":"Multi-Agent Security Tax: Trading Off Security and Collaboration Capabilities in Multi-Agent Systems","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.MA"],"primary_cat":"cs.AI","authors_text":"Christian Schroeder de Witt, Esben Kran, Filip Sondej, Jason Hoelscher-Obermaier, Matthieu David, Mikolaj Kniejski, Pierre Peigne-Lefebvre","submitted_at":"2025-02-26T14:00:35Z","abstract_excerpt":"As AI agents are increasingly adopted to collaborate on complex objectives, ensuring the security of autonomous multi-agent systems becomes crucial. We develop simulations of agents collaborating on shared objectives to study these security risks and security trade-offs. We focus on scenarios where an attacker compromises one agent, using it to steer the entire system toward misaligned outcomes by corrupting other agents. In this context, we observe infectious malicious prompts - the multi-hop spreading of malicious instructions. To mitigate this risk, we evaluated several strategies: two \"vac"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.19145","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.AI","submitted_at":"2025-02-26T14:00:35Z","cross_cats_sorted":["cs.MA"],"title_canon_sha256":"6bf04476bfbde0611707d385bae9d02e37850c1245c03b7c066885ce2d0b7b07","abstract_canon_sha256":"ddfc96390806335b06abef9e7369a883b3daa032148faafc9653ce58ec35025f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:16:06.552953Z","signature_b64":"HyFDDvoQrqHwaYLfaZ0JzVBiZjSj6DId+2xQZHqm7XVFrQmCOVEEv0MeiHK8UgWK6TyIKxdnmiHUt1HRjlynDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"510b2fc47f73f83f6c7656b248f85513c0ccb2c6d247cdb47f7878c24a4db4bf","last_reissued_at":"2026-07-05T11:16:06.552449Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:16:06.552449Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Multi-Agent Security Tax: Trading Off Security and Collaboration Capabilities in Multi-Agent Systems","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.MA"],"primary_cat":"cs.AI","authors_text":"Christian Schroeder de Witt, Esben Kran, Filip Sondej, Jason Hoelscher-Obermaier, Matthieu David, Mikolaj Kniejski, Pierre Peigne-Lefebvre","submitted_at":"2025-02-26T14:00:35Z","abstract_excerpt":"As AI agents are increasingly adopted to collaborate on complex objectives, ensuring the security of autonomous multi-agent systems becomes crucial. We develop simulations of agents collaborating on shared objectives to study these security risks and security trade-offs. We focus on scenarios where an attacker compromises one agent, using it to steer the entire system toward misaligned outcomes by corrupting other agents. In this context, we observe infectious malicious prompts - the multi-hop spreading of malicious instructions. To mitigate this risk, we evaluated several strategies: two \"vac"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.19145","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.19145/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.19145","created_at":"2026-07-05T11:16:06.552511+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.19145v2","created_at":"2026-07-05T11:16:06.552511+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.19145","created_at":"2026-07-05T11:16:06.552511+00:00"},{"alias_kind":"pith_short_12","alias_value":"KEFS7RD7OP4D","created_at":"2026-07-05T11:16:06.552511+00:00"},{"alias_kind":"pith_short_16","alias_value":"KEFS7RD7OP4D63DW","created_at":"2026-07-05T11:16:06.552511+00:00"},{"alias_kind":"pith_short_8","alias_value":"KEFS7RD7","created_at":"2026-07-05T11:16:06.552511+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.23330","citing_title":"Security, Privacy, and Ethical Risks in OpenClaw","ref_index":23,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP","json":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP.json","graph_json":"https://pith.science/api/pith-number/KEFS7RD7OP4D63DWK2ZER6CVCP/graph.json","events_json":"https://pith.science/api/pith-number/KEFS7RD7OP4D63DWK2ZER6CVCP/events.json","paper":"https://pith.science/paper/KEFS7RD7"},"agent_actions":{"view_html":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP","download_json":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP.json","view_paper":"https://pith.science/paper/KEFS7RD7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.19145&json=true","fetch_graph":"https://pith.science/api/pith-number/KEFS7RD7OP4D63DWK2ZER6CVCP/graph.json","fetch_events":"https://pith.science/api/pith-number/KEFS7RD7OP4D63DWK2ZER6CVCP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP/action/storage_attestation","attest_author":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP/action/author_attestation","sign_citation":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP/action/citation_signature","submit_replication":"https://pith.science/pith/KEFS7RD7OP4D63DWK2ZER6CVCP/action/replication_record"}},"created_at":"2026-07-05T11:16:06.552511+00:00","updated_at":"2026-07-05T11:16:06.552511+00:00"}