{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:TZ5HAE6GIHVONP7KDCAAXYD3NK","short_pith_number":"pith:TZ5HAE6G","canonical_record":{"source":{"id":"2605.13170","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-13T08:32:30Z","cross_cats_sorted":["cs.MA"],"title_canon_sha256":"b0b5e0dee3ab9c6ecfb4fe894446fbdfa51fb021d51c9b47ff28006a1e332b93","abstract_canon_sha256":"ffb9ad8cbdb7f4c87f5fede5bf89636ffe422f36a7f20e9e5738f696b6656ff8"},"schema_version":"1.0"},"canonical_sha256":"9e7a7013c641eae6bfea18800be07b6a811a08f8e2d23cff9ad4e2c321cfa23d","source":{"kind":"arxiv","id":"2605.13170","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13170","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13170v1","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13170","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"pith_short_12","alias_value":"TZ5HAE6GIHVO","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"TZ5HAE6GIHVONP7K","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"TZ5HAE6G","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:TZ5HAE6GIHVONP7KDCAAXYD3NK","target":"record","payload":{"canonical_record":{"source":{"id":"2605.13170","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-13T08:32:30Z","cross_cats_sorted":["cs.MA"],"title_canon_sha256":"b0b5e0dee3ab9c6ecfb4fe894446fbdfa51fb021d51c9b47ff28006a1e332b93","abstract_canon_sha256":"ffb9ad8cbdb7f4c87f5fede5bf89636ffe422f36a7f20e9e5738f696b6656ff8"},"schema_version":"1.0"},"canonical_sha256":"9e7a7013c641eae6bfea18800be07b6a811a08f8e2d23cff9ad4e2c321cfa23d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T03:08:56.586836Z","signature_b64":"a+9iAP90Q9Zk5t/t2jvLd6tDLoNByAfPP2t+Bxq8czEVUQM1j89DUFRn4v6cszbv0eFPBVhSBrY8CWnsOeZ7Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9e7a7013c641eae6bfea18800be07b6a811a08f8e2d23cff9ad4e2c321cfa23d","last_reissued_at":"2026-05-18T03:08:56.586105Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T03:08:56.586105Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.13170","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:08:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7LEOfJiKVqmOh3y2v5xPZiMGWpe/FPMzNgvwCkwGCHYX5s++2dWrETB1bl7Pul8tN5CdKIK+1Q/hw2zAvGRhBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T10:00:26.228006Z"},"content_sha256":"554688453dd65216b1dc90fa151a10a71248c6aa4f003bc48caa3396ae1c0a31","schema_version":"1.0","event_id":"sha256:554688453dd65216b1dc90fa151a10a71248c6aa4f003bc48caa3396ae1c0a31"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:TZ5HAE6GIHVONP7KDCAAXYD3NK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Finding the Weakest Link: Adversarial Attack against Multi-Agent Communications","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases.","cross_cats":["cs.MA"],"primary_cat":"cs.LG","authors_text":"Claudia Szabo, Junae Kim, Maxwell Standen","submitted_at":"2026-05-13T08:32:30Z","abstract_excerpt":"Multi-agent systems rely on communication for information sharing and action coordination, which exposes a vulnerability to attacks. We investigate single-victim communication perturbation attacks against Multi-Agent Reinforcement Learning-trained systems and propose methods that use gradient information from the Jacobian to identify which messages, agent, and timesteps are most susceptible to attack and have the greatest impact on the system. We enhance these methods with two proposed adversarial loss functions that trade-off attack success for attack impact which also create more effective p"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Our novel message selection method achieves a similar or greater impact than random message selection across almost all tested scenarios. Our victim selection, message selection, tempo, and loss functions improve attack effectiveness in half of the thirty scenarios we tested.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The attacker has white-box access to compute Jacobians and gradients from the victim model, which may not hold for black-box deployed systems.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Jacobian-based selection of messages, agents, and timesteps combined with two new adversarial loss functions disrupts multi-agent RL communication more effectively than random perturbations in navigation, PredatorPrey, and TrafficJunction environments.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"ed3a3a76d3c59664fa62165df33c8d03a7ff5985804c2cbecc9b7d61790d081e"},"source":{"id":"2605.13170","kind":"arxiv","version":1},"verdict":{"id":"dc0d8d56-94af-448d-9683-c11d1b6ba784","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-14T19:17:22.075416Z","strongest_claim":"Our novel message selection method achieves a similar or greater impact than random message selection across almost all tested scenarios. Our victim selection, message selection, tempo, and loss functions improve attack effectiveness in half of the thirty scenarios we tested.","one_line_summary":"Jacobian-based selection of messages, agents, and timesteps combined with two new adversarial loss functions disrupts multi-agent RL communication more effectively than random perturbations in navigation, PredatorPrey, and TrafficJunction environments.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The attacker has white-box access to compute Jacobians and gradients from the victim model, which may not hold for black-box deployed systems.","pith_extraction_headline":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases."},"references":{"count":36,"sample":[{"doi":"","year":2024,"title":"Multi-Agent Deep Reinforcement Learning Applications in Cybersecurity: Challenges and Perspectives,","work_id":"34cd33e4-863b-4fe6-8577-a97fbd39476a","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2024,"title":"Multi-agent reinforcement learning for cybersecurity: Approaches and challenges,","work_id":"bec57a1b-6487-4849-925d-d9f9363e1ee6","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2016,"title":"F. A. Oliehoek and C. Amato,A Concise Introduction to Decentralized POMDPs. Springer International Publishing, 2016","work_id":"9020e3f4-a5a7-44e0-9919-6a1ec837dd44","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2016,"title":"Learning to Communi- cate with Deep Multi-Agent Reinforcement Learning,","work_id":"6ef5ffd0-9d84-44d7-a470-fbd21e295615","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2020,"title":"Succinct and robust multi-agent communication with temporal message control,","work_id":"e5e501f2-acb9-4349-9fd6-abab8a36aabb","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":36,"snapshot_sha256":"75bbe556b229c42b7b71d46c60996548b93ef151eb5ec443e652b3b6b75c4f70","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"dc0d8d56-94af-448d-9683-c11d1b6ba784"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:08:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mTRVDuJMRmhvm9OeKBykG2vEOk3N4/y+okchb4dNHGUmkI7+HoltYR8FcTBw3Dzvo0v4yuD8he2xDvnHCzJuAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T10:00:26.229010Z"},"content_sha256":"c447a8ab14317b8d27d5b0050b61b5bbbc75116878603bf71c9593bfd7571d53","schema_version":"1.0","event_id":"sha256:c447a8ab14317b8d27d5b0050b61b5bbbc75116878603bf71c9593bfd7571d53"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/bundle.json","state_url":"https://pith.science/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T10:00:26Z","links":{"resolver":"https://pith.science/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK","bundle":"https://pith.science/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/bundle.json","state":"https://pith.science/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TZ5HAE6GIHVONP7KDCAAXYD3NK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:TZ5HAE6GIHVONP7KDCAAXYD3NK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ffb9ad8cbdb7f4c87f5fede5bf89636ffe422f36a7f20e9e5738f696b6656ff8","cross_cats_sorted":["cs.MA"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-13T08:32:30Z","title_canon_sha256":"b0b5e0dee3ab9c6ecfb4fe894446fbdfa51fb021d51c9b47ff28006a1e332b93"},"schema_version":"1.0","source":{"id":"2605.13170","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13170","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13170v1","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13170","created_at":"2026-05-18T03:08:56Z"},{"alias_kind":"pith_short_12","alias_value":"TZ5HAE6GIHVO","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"TZ5HAE6GIHVONP7K","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"TZ5HAE6G","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:c447a8ab14317b8d27d5b0050b61b5bbbc75116878603bf71c9593bfd7571d53","target":"graph","created_at":"2026-05-18T03:08:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Our novel message selection method achieves a similar or greater impact than random message selection across almost all tested scenarios. Our victim selection, message selection, tempo, and loss functions improve attack effectiveness in half of the thirty scenarios we tested."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The attacker has white-box access to compute Jacobians and gradients from the victim model, which may not hold for black-box deployed systems."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Jacobian-based selection of messages, agents, and timesteps combined with two new adversarial loss functions disrupts multi-agent RL communication more effectively than random perturbations in navigation, PredatorPrey, and TrafficJunction environments."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases."}],"snapshot_sha256":"ed3a3a76d3c59664fa62165df33c8d03a7ff5985804c2cbecc9b7d61790d081e"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Multi-agent systems rely on communication for information sharing and action coordination, which exposes a vulnerability to attacks. We investigate single-victim communication perturbation attacks against Multi-Agent Reinforcement Learning-trained systems and propose methods that use gradient information from the Jacobian to identify which messages, agent, and timesteps are most susceptible to attack and have the greatest impact on the system. We enhance these methods with two proposed adversarial loss functions that trade-off attack success for attack impact which also create more effective p","authors_text":"Claudia Szabo, Junae Kim, Maxwell Standen","cross_cats":["cs.MA"],"headline":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-13T08:32:30Z","title":"Finding the Weakest Link: Adversarial Attack against Multi-Agent Communications"},"references":{"count":36,"internal_anchors":0,"resolved_work":36,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Multi-Agent Deep Reinforcement Learning Applications in Cybersecurity: Challenges and Perspectives,","work_id":"34cd33e4-863b-4fe6-8577-a97fbd39476a","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Multi-agent reinforcement learning for cybersecurity: Approaches and challenges,","work_id":"bec57a1b-6487-4849-925d-d9f9363e1ee6","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"F. A. Oliehoek and C. Amato,A Concise Introduction to Decentralized POMDPs. Springer International Publishing, 2016","work_id":"9020e3f4-a5a7-44e0-9919-6a1ec837dd44","year":2016},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Learning to Communi- cate with Deep Multi-Agent Reinforcement Learning,","work_id":"6ef5ffd0-9d84-44d7-a470-fbd21e295615","year":2016},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Succinct and robust multi-agent communication with temporal message control,","work_id":"e5e501f2-acb9-4349-9fd6-abab8a36aabb","year":2020}],"snapshot_sha256":"75bbe556b229c42b7b71d46c60996548b93ef151eb5ec443e652b3b6b75c4f70"},"source":{"id":"2605.13170","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T19:17:22.075416Z","id":"dc0d8d56-94af-448d-9683-c11d1b6ba784","model_set":{"reader":"grok-4.3"},"one_line_summary":"Jacobian-based selection of messages, agents, and timesteps combined with two new adversarial loss functions disrupts multi-agent RL communication more effectively than random perturbations in navigation, PredatorPrey, and TrafficJunction environments.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Gradient-based selection of vulnerable messages and agents disrupts multi-agent reinforcement learning communications as effectively as random attacks in most cases.","strongest_claim":"Our novel message selection method achieves a similar or greater impact than random message selection across almost all tested scenarios. Our victim selection, message selection, tempo, and loss functions improve attack effectiveness in half of the thirty scenarios we tested.","weakest_assumption":"The attacker has white-box access to compute Jacobians and gradients from the victim model, which may not hold for black-box deployed systems."}},"verdict_id":"dc0d8d56-94af-448d-9683-c11d1b6ba784"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:554688453dd65216b1dc90fa151a10a71248c6aa4f003bc48caa3396ae1c0a31","target":"record","created_at":"2026-05-18T03:08:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ffb9ad8cbdb7f4c87f5fede5bf89636ffe422f36a7f20e9e5738f696b6656ff8","cross_cats_sorted":["cs.MA"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-13T08:32:30Z","title_canon_sha256":"b0b5e0dee3ab9c6ecfb4fe894446fbdfa51fb021d51c9b47ff28006a1e332b93"},"schema_version":"1.0","source":{"id":"2605.13170","kind":"arxiv","version":1}},"canonical_sha256":"9e7a7013c641eae6bfea18800be07b6a811a08f8e2d23cff9ad4e2c321cfa23d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9e7a7013c641eae6bfea18800be07b6a811a08f8e2d23cff9ad4e2c321cfa23d","first_computed_at":"2026-05-18T03:08:56.586105Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T03:08:56.586105Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"a+9iAP90Q9Zk5t/t2jvLd6tDLoNByAfPP2t+Bxq8czEVUQM1j89DUFRn4v6cszbv0eFPBVhSBrY8CWnsOeZ7Dg==","signature_status":"signed_v1","signed_at":"2026-05-18T03:08:56.586836Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.13170","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:554688453dd65216b1dc90fa151a10a71248c6aa4f003bc48caa3396ae1c0a31","sha256:c447a8ab14317b8d27d5b0050b61b5bbbc75116878603bf71c9593bfd7571d53"],"state_sha256":"d00d927a961e2a9e2cb0feb58d8ff7e23a67c85e6023ed5662fdbe133057693a"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5MdBa6M+scfQQrlW0P5eEr0UbxQ5Aeskivc+Thyt/SnNr8GdZoRiicpKwuctcJV7T7oB28MB7V0CnRzrmrQKDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T10:00:26.233523Z","bundle_sha256":"ab909dfa9b43ccda693e5479244e80907d7ec9260334c2263795027837929f7b"}}