{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:YYRA2LNNHLKVK447YVMNEELTLF","short_pith_number":"pith:YYRA2LNN","schema_version":"1.0","canonical_sha256":"c6220d2dad3ad555739fc558d21173594586da2a5a1839cdad32529d7d16b7da","source":{"kind":"arxiv","id":"2402.08567","version":2},"attestation_state":"computed","paper":{"title":"Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG","cs.MA"],"primary_cat":"cs.CL","authors_text":"Chao Du, Jing Jiang, Min Lin, Qian Liu, Tianyu Pang, Xiangming Gu, Xiaosen Zheng, Ye Wang","submitted_at":"2024-02-13T16:06:17Z","abstract_excerpt":"A multimodal large language model (MLLM) agent can receive instructions, capture images, retrieve histories from memory, and decide which tools to use. Nonetheless, red-teaming efforts have revealed that adversarial images/prompts can jailbreak an MLLM and cause unaligned behaviors. In this work, we report an even more severe safety issue in multi-agent environments, referred to as infectious jailbreak. It entails the adversary simply jailbreaking a single agent, and without any further intervention from the adversary, (almost) all agents will become infected exponentially fast and exhibit har"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.08567","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2024-02-13T16:06:17Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.MA"],"title_canon_sha256":"0c2d7b0295d704be094620cea183d82a0835743192f7f30632ba4885a967beed","abstract_canon_sha256":"507ee42f0d84165f427fb4c360544f3283216c9b1d5c144abebd92046c435dc3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:26:19.481730Z","signature_b64":"NdIRLGjNwyP4+H23twqwwrRHIay0rnwiIdMisESAsIgzjEJAV/FMGhUnhrvg+hNKxMBC6mHQElkV6Os6e5EMDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c6220d2dad3ad555739fc558d21173594586da2a5a1839cdad32529d7d16b7da","last_reissued_at":"2026-07-05T08:26:19.481247Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:26:19.481247Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG","cs.MA"],"primary_cat":"cs.CL","authors_text":"Chao Du, Jing Jiang, Min Lin, Qian Liu, Tianyu Pang, Xiangming Gu, Xiaosen Zheng, Ye Wang","submitted_at":"2024-02-13T16:06:17Z","abstract_excerpt":"A multimodal large language model (MLLM) agent can receive instructions, capture images, retrieve histories from memory, and decide which tools to use. Nonetheless, red-teaming efforts have revealed that adversarial images/prompts can jailbreak an MLLM and cause unaligned behaviors. In this work, we report an even more severe safety issue in multi-agent environments, referred to as infectious jailbreak. It entails the adversary simply jailbreaking a single agent, and without any further intervention from the adversary, (almost) all agents will become infected exponentially fast and exhibit har"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.08567","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.08567/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.08567","created_at":"2026-07-05T08:26:19.481304+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.08567v2","created_at":"2026-07-05T08:26:19.481304+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.08567","created_at":"2026-07-05T08:26:19.481304+00:00"},{"alias_kind":"pith_short_12","alias_value":"YYRA2LNNHLKV","created_at":"2026-07-05T08:26:19.481304+00:00"},{"alias_kind":"pith_short_16","alias_value":"YYRA2LNNHLKVK447","created_at":"2026-07-05T08:26:19.481304+00:00"},{"alias_kind":"pith_short_8","alias_value":"YYRA2LNN","created_at":"2026-07-05T08:26:19.481304+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":14,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07943","citing_title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","ref_index":46,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30602","citing_title":"MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28104","citing_title":"Defending LLM-based Multi-Agent Systems Against Cooperative Attacks with Sentence-Level Rectification","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2606.00485","citing_title":"Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":220,"is_internal_anchor":false},{"citing_arxiv_id":"2505.10924","citing_title":"A Survey on the Safety and Security Threats of Computer-Using Agents: JARVIS or Ultron?","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2505.16120","citing_title":"LLM-Powered AI Agent Systems and Their Applications in Industry","ref_index":113,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09574","citing_title":"Turing Test on Screen: A Benchmark for Mobile GUI Agent Humanization","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03482","citing_title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12616","citing_title":"Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09056","citing_title":"Conversations Risk Detection LLMs in Financial Agents via Multi-Stage Generative Rollout","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03482","citing_title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","ref_index":7,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF","json":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF.json","graph_json":"https://pith.science/api/pith-number/YYRA2LNNHLKVK447YVMNEELTLF/graph.json","events_json":"https://pith.science/api/pith-number/YYRA2LNNHLKVK447YVMNEELTLF/events.json","paper":"https://pith.science/paper/YYRA2LNN"},"agent_actions":{"view_html":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF","download_json":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF.json","view_paper":"https://pith.science/paper/YYRA2LNN","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.08567&json=true","fetch_graph":"https://pith.science/api/pith-number/YYRA2LNNHLKVK447YVMNEELTLF/graph.json","fetch_events":"https://pith.science/api/pith-number/YYRA2LNNHLKVK447YVMNEELTLF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF/action/storage_attestation","attest_author":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF/action/author_attestation","sign_citation":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF/action/citation_signature","submit_replication":"https://pith.science/pith/YYRA2LNNHLKVK447YVMNEELTLF/action/replication_record"}},"created_at":"2026-07-05T08:26:19.481304+00:00","updated_at":"2026-07-05T08:26:19.481304+00:00"}