{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:KN3STL6EMHU3DSWTAPZPAXGZVQ","short_pith_number":"pith:KN3STL6E","schema_version":"1.0","canonical_sha256":"537729afc461e9b1cad303f2f05cd9ac03946482106cd6205e9e3a37536b6cb8","source":{"kind":"arxiv","id":"2403.02817","version":2},"attestation_state":"computed","paper":{"title":"Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ben Nassi, Ron Bitton, Stav Cohen","submitted_at":"2024-03-05T09:37:13Z","abstract_excerpt":"In this paper, we show that when the communication between GenAI-powered applications relies on RAG-based inference, an attacker can initiate a computer worm-like chain reaction that we call Morris-II. This is done by crafting an adversarial self-replicating prompt that triggers a cascade of indirect prompt injections within the ecosystem and forces each affected application to perform malicious actions and compromise the RAG of additional applications. We evaluate the performance of the worm in creating a chain of confidential user data extraction within a GenAI ecosystem of GenAI-powered ema"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2403.02817","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2024-03-05T09:37:13Z","cross_cats_sorted":[],"title_canon_sha256":"b5685782500a5840cd05769785bfce916bf2c651842aeaf38cbc78bc36c9062c","abstract_canon_sha256":"35d6f7327ba94236c91ce2d9351f9ea50e69e2ca64e4fd24fbd501747f723ea8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:07:24.006701Z","signature_b64":"Mz89DMAIqokuxqNESTnAmmS2bAITBfUKUVIQUFObRcbn7vC6Ei26cpi2WYtgoSEqioJhBEP7VyRpm0mAUDw3Cg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"537729afc461e9b1cad303f2f05cd9ac03946482106cd6205e9e3a37536b6cb8","last_reissued_at":"2026-07-05T10:07:24.006248Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:07:24.006248Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ben Nassi, Ron Bitton, Stav Cohen","submitted_at":"2024-03-05T09:37:13Z","abstract_excerpt":"In this paper, we show that when the communication between GenAI-powered applications relies on RAG-based inference, an attacker can initiate a computer worm-like chain reaction that we call Morris-II. This is done by crafting an adversarial self-replicating prompt that triggers a cascade of indirect prompt injections within the ecosystem and forces each affected application to perform malicious actions and compromise the RAG of additional applications. We evaluate the performance of the worm in creating a chain of confidential user data extraction within a GenAI ecosystem of GenAI-powered ema"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2403.02817","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2403.02817/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2403.02817","created_at":"2026-07-05T10:07:24.006311+00:00"},{"alias_kind":"arxiv_version","alias_value":"2403.02817v2","created_at":"2026-07-05T10:07:24.006311+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2403.02817","created_at":"2026-07-05T10:07:24.006311+00:00"},{"alias_kind":"pith_short_12","alias_value":"KN3STL6EMHU3","created_at":"2026-07-05T10:07:24.006311+00:00"},{"alias_kind":"pith_short_16","alias_value":"KN3STL6EMHU3DSWT","created_at":"2026-07-05T10:07:24.006311+00:00"},{"alias_kind":"pith_short_8","alias_value":"KN3STL6E","created_at":"2026-07-05T10:07:24.006311+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":16,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.23075","citing_title":"Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.22528","citing_title":"Governance Decay: How Context Compaction Silently Erases Safety Constraints in Long-Horizon LLM Agents","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23989","citing_title":"Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security","ref_index":214,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17034","citing_title":"Privacy Policy Enforcement Guardrails for Data-Sensitive Retrieval-Augmented Generation","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2606.22528","citing_title":"Governance Decay: How Context Compaction Silently Erases Safety Constraints in Long-Horizon LLM Agents","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23330","citing_title":"Security, Privacy, and Ethical Risks in OpenClaw","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2412.14855","citing_title":"Position: Mind the Gap-AI Security and the Limits of Current Reporting Standards","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16746","citing_title":"State Contamination in Memory-Augmented LLM Agents","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17034","citing_title":"Privacy Policy Enforcement Guardrails for Data-Sensitive Retrieval-Augmented Generation","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":96,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":55,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2604.21131","citing_title":"Cross-Session Threats in AI Agents: Benchmark, Evaluation, and Algorithms","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01758","citing_title":"Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01758","citing_title":"Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.02812","citing_title":"Autonomous LLM Agent Worms: Cross-Platform Propagation, Automated Discovery and Temporal Re-Entry Defense","ref_index":1,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ","json":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ.json","graph_json":"https://pith.science/api/pith-number/KN3STL6EMHU3DSWTAPZPAXGZVQ/graph.json","events_json":"https://pith.science/api/pith-number/KN3STL6EMHU3DSWTAPZPAXGZVQ/events.json","paper":"https://pith.science/paper/KN3STL6E"},"agent_actions":{"view_html":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ","download_json":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ.json","view_paper":"https://pith.science/paper/KN3STL6E","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2403.02817&json=true","fetch_graph":"https://pith.science/api/pith-number/KN3STL6EMHU3DSWTAPZPAXGZVQ/graph.json","fetch_events":"https://pith.science/api/pith-number/KN3STL6EMHU3DSWTAPZPAXGZVQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ/action/storage_attestation","attest_author":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ/action/author_attestation","sign_citation":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ/action/citation_signature","submit_replication":"https://pith.science/pith/KN3STL6EMHU3DSWTAPZPAXGZVQ/action/replication_record"}},"created_at":"2026-07-05T10:07:24.006311+00:00","updated_at":"2026-07-05T10:07:24.006311+00:00"}