Pith. sign in

Paper Citation Record · LEDGER

Multi-Agent Systems Execute Arbitrary Malicious Code

As of 14 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 25 inbound Pith citation observations for arXiv:2503.12188.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2503.12188 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 25 of 25 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-10T20:08:02.204824Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation c197dca4-1ded-407b-9300-75cd571f33d5 · inbound

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI cites this paper.

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T14:15:39.937396Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:15:39.937396Z digest=sha256:72a9fdfac0eb9784e953c00f109b7440cd6866b268fcba7dd48bc0ca942f2f5b

Observation 3620ff31-f342-40df-b6a4-aaba67997c8a · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 126

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:45.107075Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:45.107075Z digest=sha256:fd4eb2c3f908af34567623ce7202431a08298996e974447883f04e021252057c

Observation 15eeee1b-2e21-47db-b3d5-28f446e44253 · inbound

Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs cites this paper.

Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T18:37:11.072760Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T18:37:11.072760Z digest=sha256:f4fc2fa49897efea9c9de191aa94d4a2ea3110df75dea66bd0555303059e1db2

Observation 3742b33d-12b7-4195-84da-40221f1006a7 · inbound

AgentMark: Utility-Preserving Behavioral Watermarking for Agents cites this paper.

AgentMark: Utility-Preserving Behavioral Watermarking for Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-16T17:53:11.532827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-16T17:52:49.826217Z digest=sha256:1ae81cf8a9965561bd4466760e8c567dde0560dfb79835b8200081251e93e2df

Observation 5e16f565-d5b9-456b-895a-d2bd684ae017 · inbound

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration cites this paper.

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 43

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T16:40:10.565595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-15T16:36:43.330447Z digest=sha256:27cd5f599ed8e8104761b9367600f7e0221afaa1dae8f527fad5f1b2501aac39

Observation 0d282159-c660-4f7c-ba60-34383c20e469 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 15

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T14:15:54.993562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:d3113faf146f6fb2e94925fa0c97bf1b929b838e22e18ce10727ff6d3ae5f227

Observation 1c562f6c-9c5b-47df-86e4-deec4ffaa155 · inbound

Detailed analysis of possible new-physics effects in the semileptonic decay $B_s \to D_s^{(*)}\tau\bar{\nu}$ cites this paper.

Detailed analysis of possible new-physics effects in the semileptonic decay $B_s \to D_s^{(*)}\tau\bar{\nu}$ Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-15T12:11:00.253650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-15T12:11:00.253650Z digest=sha256:6b84ecfa50c28d06b2b1268a17fc6d7f9aa2113a0b295a92e9aead90d246e8b7

Observation 24514df3-5749-4d33-b456-1943513c1426 · inbound

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines cites this paper.

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 2

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T06:20:58.889968Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-10T17:40:23.128451Z digest=sha256:f54ca2201a754002af26e4a765089ae6ca21d91d832e34250f4ed92e021c35d7

Observation b42ec855-08af-42e0-869a-d5354dc48013 · inbound

Challenges and Future Directions in Agentic Reverse Engineering Systems cites this paper.

Challenges and Future Directions in Agentic Reverse Engineering Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 23

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T12:50:24.701927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-10T12:49:31.238578Z digest=sha256:80d676426f61b0bc1f926158c6d9b8904239114d8b27e0e4244ddb8bc257b7d1

Observation 0fb10241-542c-443f-b80f-116eddf20081 · inbound

Conjunctive Prompt Attacks in Multi-Agent LLM Systems cites this paper.

Conjunctive Prompt Attacks in Multi-Agent LLM Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-05-10T08:17:37.696855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=arxiv_source observed=2026-05-10T08:13:42.401992Z digest=sha256:5c770c3f555611ef37a78e7ae6dc2b8e2a79c9e19f85330fb5e45cd0935ca6ae

Observation db670ae1-ae40-4b94-841e-24d0ca0445f0 · inbound

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection cites this paper.

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 143

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:56:13.834033Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=arxiv_source observed=2026-05-07T15:59:49.513500Z digest=sha256:133513b8af8580cc8014a881181a0fd7fbedc30e1b2c66b30049994f17ff587b

Observation 57b6b7a0-0f37-459a-b02e-371e0f602ca3 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 50

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.144109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:00fdd12c24ab10cb474384a9e9f9e9887f3fa37d6f40c3091c91cee877e0b5e0

Observation acbc91a1-d7bc-4e26-89c6-d5b153928cbb · inbound

Sequential Behavioral Watermarking for LLM Agents cites this paper.

Sequential Behavioral Watermarking for LLM Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 33

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T01:47:04.099933Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-13T01:44:13.564389Z digest=sha256:c8de7c1ce3dedd341a8fb39fd4d26c63dbc0240af7d0cec81877a26cb8c5ee20

Observation 6921c6f5-e747-47fa-8a68-3abb9750f62a · inbound

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents cites this paper.

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 151

Resolution
verified exact
arxiv_id, observed 2026-06-28T19:42:36.133114Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=arxiv_source observed=2026-06-28T18:53:41.420255Z digest=sha256:f09b44e76ccaf4b674376c17d720404e926d661edfa9d0cb7bf6276c6a4dd621

Observation 4c55f5ff-b7b2-49e0-b5ae-bf31ba288518 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 169

Resolution
metadata mismatch
arxiv_id, observed 2026-06-27T13:20:56.861621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:6dab675a1db5e6022b25d35b594bce4a4382980bb0ba84caa39a3c489e61a92e

Observation 01c9d6af-ab45-478f-b192-6a0bd6206d97 · inbound

The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements cites this paper.

The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 46

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T13:58:21.480844Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=arxiv_source observed=2026-06-27T07:25:32.556071Z digest=sha256:97876b7d4f183ae34b9f8cf771b8db278e464d6f16961a521ec4f30d3fbd5d4b

Observation 93786acb-87e0-40fb-b858-9a70b705906b · inbound

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems cites this paper.

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-06-30T16:14:53.967870Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-30T04:48:51.748711Z digest=sha256:52b4c07a725d9277d3df01998febf7b02e8634e2f305090104b5aeaee7d912e2

Observation dedaafb1-0aa6-45b0-97d2-3ca92045901b · inbound

Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety cites this paper.

Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 14

Resolution
verified exact
local_arxiv, observed 2026-07-09T20:16:29.367118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-07-09T20:14:36.433937Z digest=sha256:e6c80a67d46aceb67d054c3fc7624c61cfe8ca7d5f3d288698d5e68363a45c9f

Observation d976e7ac-341b-42cd-8b2c-dcb1a89582dc · inbound

Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across LLM Agents cites this paper.

Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across LLM Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T14:16:00.056317Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T14:16:00.056317Z digest=sha256:10961785444d031596035ed1b6873dfd34ef0a32b35ca27a2396c89e256ffd60

Observation 773b3310-e45e-4e2a-bada-1eed7cd2b555 · inbound

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems cites this paper.

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T00:51:17.583274Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T00:51:17.583274Z digest=sha256:454fd1fcbdd35e00ef3e17d71e7de7a6f9ee4a40e7f470590c012a6457ef58de

Observation 541b6dc2-c999-481c-a71c-6655196b1abf · inbound

From Monoliths to Swarms: A Study of Attack Surface Evolution in the Transition to Multi-Agent Web Systems cites this paper.

From Monoliths to Swarms: A Study of Attack Surface Evolution in the Transition to Multi-Agent Web Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-04T01:03:46.926679Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T01:03:46.926679Z digest=sha256:ef9270275455af12a8d76714911ab0e20e9688f8b5233013a3ee8e91a50586d5

Observation 6ea42930-0465-4304-98ea-353cd51db98b · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T00:25:59.475710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T00:25:59.475710Z digest=sha256:89529ef114e5ecfd673171638d75e6f80470ae7c65f82d0f9b1f17b526224980

Observation df05d453-c18f-46f1-af60-291b8c858210 · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:4a9753faba5427cd8a0ebfe30075d9c2858ee63b919bf37b077a491eade9a2b6

Observation e69bc127-7d6e-4261-86b0-333670b84d27 · inbound

Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity cites this paper.

Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-05T22:07:42.214656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T22:07:42.214656Z digest=sha256:04c3c7e91a8125d34dd78ff022beebb577788973aee69ca05c199ecac9fca56c

Observation 7caad2fa-f1fa-4a87-b239-4323fecc95de · inbound

When Coordination Becomes a Threat: Communication Attacks in LLM-Controlled Multi-Robot Systems cites this paper.

When Coordination Becomes a Threat: Communication Attacks in LLM-Controlled Multi-Robot Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-10T20:08:02.204824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T20:08:02.204824Z digest=sha256:11e38c765c4772f3410043a6d53ba75b1af896a80b6c95fdd1c889164d176863