{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:KERLQ7N567SIFJUDF47QZVQTK2","short_pith_number":"pith:KERLQ7N5","schema_version":"1.0","canonical_sha256":"5122b87dbdf7e482a6832f3f0cd61356a372cc11892c9539c58acd504978c2bd","source":{"kind":"arxiv","id":"2311.11855","version":2},"attestation_state":"computed","paper":{"title":"Evil Geniuses: Delving into the Safety of LLM-based Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Hang Su, Jingyuan Zhang, Xiao Yang, Yinpeng Dong, Yu Tian","submitted_at":"2023-11-20T15:50:09Z","abstract_excerpt":"Rapid advancements in large language models (LLMs) have revitalized in LLM-based agents, exhibiting impressive human-like behaviors and cooperative capabilities in various scenarios. However, these agents also bring some exclusive risks, stemming from the complexity of interaction environments and the usability of tools. This paper delves into the safety of LLM-based agents from three perspectives: agent quantity, role definition, and attack level. Specifically, we initially propose to employ a template-based attack strategy on LLM-based agents to find the influence of agent quantity. In addit"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2311.11855","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2023-11-20T15:50:09Z","cross_cats_sorted":[],"title_canon_sha256":"40579894e09c693762d7ab98a1124012e562ea304a05d759e763dcd17c94feec","abstract_canon_sha256":"80c7178f0325d0b87af406f85fbe227892655d91e8ee7d2c9d0dd6a79804aeb2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:40:25.272234Z","signature_b64":"381+7T0/H9GI3WGlX+g4o+7NzPWaf7pXPb/NO7of9WCtOvwD0AGyRlgd0PN8s3jLbRfaErU+/wCLfyrORhrrAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5122b87dbdf7e482a6832f3f0cd61356a372cc11892c9539c58acd504978c2bd","last_reissued_at":"2026-07-05T07:40:25.271761Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:40:25.271761Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Evil Geniuses: Delving into the Safety of LLM-based Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Hang Su, Jingyuan Zhang, Xiao Yang, Yinpeng Dong, Yu Tian","submitted_at":"2023-11-20T15:50:09Z","abstract_excerpt":"Rapid advancements in large language models (LLMs) have revitalized in LLM-based agents, exhibiting impressive human-like behaviors and cooperative capabilities in various scenarios. However, these agents also bring some exclusive risks, stemming from the complexity of interaction environments and the usability of tools. This paper delves into the safety of LLM-based agents from three perspectives: agent quantity, role definition, and attack level. Specifically, we initially propose to employ a template-based attack strategy on LLM-based agents to find the influence of agent quantity. In addit"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2311.11855","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2311.11855/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2311.11855","created_at":"2026-07-05T07:40:25.271813+00:00"},{"alias_kind":"arxiv_version","alias_value":"2311.11855v2","created_at":"2026-07-05T07:40:25.271813+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2311.11855","created_at":"2026-07-05T07:40:25.271813+00:00"},{"alias_kind":"pith_short_12","alias_value":"KERLQ7N567SI","created_at":"2026-07-05T07:40:25.271813+00:00"},{"alias_kind":"pith_short_16","alias_value":"KERLQ7N567SIFJUD","created_at":"2026-07-05T07:40:25.271813+00:00"},{"alias_kind":"pith_short_8","alias_value":"KERLQ7N5","created_at":"2026-07-05T07:40:25.271813+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":14,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.06807","citing_title":"When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems","ref_index":56,"is_internal_anchor":true},{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":210,"is_internal_anchor":false},{"citing_arxiv_id":"2504.15801","citing_title":"A closer look at how large language models trust humans: patterns and biases","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2510.14133","citing_title":"Formalizing the Safety, Security, and Functional Properties of Agentic AI Systems","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2402.03578","citing_title":"LLM Multi-Agent Systems: Challenges and Open Problems","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2404.11584","citing_title":"The Landscape of Emerging AI Agent Architectures for Reasoning, Planning, and Tool Calling: A Survey","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2604.03242","citing_title":"DRAFT: Task Decoupled Latent Reasoning for Agent Safety","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":85,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":91,"is_internal_anchor":false},{"citing_arxiv_id":"2410.09024","citing_title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08460","citing_title":"When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":113,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06161","citing_title":"Beyond Accuracy: Policy Invariance as a Reliability Test for LLM Safety Judges","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07110","citing_title":"Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability","ref_index":155,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2","json":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2.json","graph_json":"https://pith.science/api/pith-number/KERLQ7N567SIFJUDF47QZVQTK2/graph.json","events_json":"https://pith.science/api/pith-number/KERLQ7N567SIFJUDF47QZVQTK2/events.json","paper":"https://pith.science/paper/KERLQ7N5"},"agent_actions":{"view_html":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2","download_json":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2.json","view_paper":"https://pith.science/paper/KERLQ7N5","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2311.11855&json=true","fetch_graph":"https://pith.science/api/pith-number/KERLQ7N567SIFJUDF47QZVQTK2/graph.json","fetch_events":"https://pith.science/api/pith-number/KERLQ7N567SIFJUDF47QZVQTK2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2/action/storage_attestation","attest_author":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2/action/author_attestation","sign_citation":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2/action/citation_signature","submit_replication":"https://pith.science/pith/KERLQ7N567SIFJUDF47QZVQTK2/action/replication_record"}},"created_at":"2026-07-05T07:40:25.271813+00:00","updated_at":"2026-07-05T07:40:25.271813+00:00"}