Pith. sign in

Paper Citation Record · LEDGER

Multi-Agent Systems Execute Arbitrary Malicious Code

As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 24 inbound Pith citation observations for arXiv:2503.12188.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2503.12188 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 24 of 24 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 24 of 24 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T14:15:39.937396Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation c197dca4-1ded-407b-9300-75cd571f33d5 · inbound

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI cites this paper.

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T14:15:39.937396Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:15:39.937396Z digest=sha256:45f8206f13a673d3609704fc434dc1502fbbf7c2c5347966ba71c1e22f9b72a6

Observation 3620ff31-f342-40df-b6a4-aaba67997c8a · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 126

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:45.107075Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:45.107075Z digest=sha256:cb3df0d5749feadfc08c1205cb4274bf17735a2538d04ccb11253af889daa38d

Observation 15eeee1b-2e21-47db-b3d5-28f446e44253 · inbound

Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs cites this paper.

Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T18:37:11.072760Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T18:37:11.072760Z digest=sha256:25ffa708154b811334a2a56f9094c56fa51a81dc04b40c5497d6eeaf8a6784ae

Observation 3742b33d-12b7-4195-84da-40221f1006a7 · inbound

AgentMark: Utility-Preserving Behavioral Watermarking for Agents cites this paper.

AgentMark: Utility-Preserving Behavioral Watermarking for Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-16T17:53:11.532827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-16T17:52:49.826217Z digest=sha256:a939a9a63ab21cd3adbadfcd748698ec96cc53c623388b3d9c63a62555b36ca0

Observation 5e16f565-d5b9-456b-895a-d2bd684ae017 · inbound

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration cites this paper.

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 43

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T16:40:10.565595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-15T16:36:43.330447Z digest=sha256:dd594f358fa5a1fba181ed422a27d92b00fd068083363cb7e72da4b799c98ae2

Observation 0d282159-c660-4f7c-ba60-34383c20e469 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 15

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T14:15:54.993562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:ff055b1e587df1dedd015890a7b10e7e886420dd798a538aab1af9d7d94f001a

Observation 1c562f6c-9c5b-47df-86e4-deec4ffaa155 · inbound

Detailed analysis of possible new-physics effects in the semileptonic decay $B_s \to D_s^{(*)}\tau\bar{\nu}$ cites this paper.

Detailed analysis of possible new-physics effects in the semileptonic decay $B_s \to D_s^{(*)}\tau\bar{\nu}$ Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-15T12:11:00.253650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-15T12:11:00.253650Z digest=sha256:4e5d8249dfa988bbe47906369c27906e232182aed2da63855a90111f8d05c83e

Observation 24514df3-5749-4d33-b456-1943513c1426 · inbound

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines cites this paper.

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 2

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T06:20:58.889968Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-10T17:40:23.128451Z digest=sha256:a093811e2a7e4fb27d99ee843a9f743ec5f1eaf3e009cad50f5e3b6b0c3174e8

Observation b42ec855-08af-42e0-869a-d5354dc48013 · inbound

Challenges and Future Directions in Agentic Reverse Engineering Systems cites this paper.

Challenges and Future Directions in Agentic Reverse Engineering Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 23

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T12:50:24.701927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-10T12:49:31.238578Z digest=sha256:0faee317160bf0e3d475bff07084b50afc67f0086be4f604f14c2005067fcfaf

Observation 0fb10241-542c-443f-b80f-116eddf20081 · inbound

Conjunctive Prompt Attacks in Multi-Agent LLM Systems cites this paper.

Conjunctive Prompt Attacks in Multi-Agent LLM Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-05-10T08:17:37.696855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-05-10T08:13:42.401992Z digest=sha256:0cb17590cdcda4f189ea5e7fe42b94028a9e4a73d97baa9cef9a58553c8336c9

Observation db670ae1-ae40-4b94-841e-24d0ca0445f0 · inbound

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection cites this paper.

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 143

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:56:13.834033Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-05-07T15:59:49.513500Z digest=sha256:56c17013d7bea1e96c4a4c488759fcbdd28e12fd9c2b6efa2a00a30f21483d9c

Observation 57b6b7a0-0f37-459a-b02e-371e0f602ca3 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 50

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.144109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:01e313896523814367062b02eef90d6ab99f335b264b1663993ac3ef2db6d687

Observation acbc91a1-d7bc-4e26-89c6-d5b153928cbb · inbound

Sequential Behavioral Watermarking for LLM Agents cites this paper.

Sequential Behavioral Watermarking for LLM Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 33

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T01:47:04.099933Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-13T01:44:13.564389Z digest=sha256:a2bae2517b28fb17c9f551b687881090abca2b600dc73fb37ef2dc0012d97cb0

Observation 6921c6f5-e747-47fa-8a68-3abb9750f62a · inbound

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents cites this paper.

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 151

Resolution
verified exact
arxiv_id, observed 2026-06-28T19:42:36.133114Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-06-28T18:53:41.420255Z digest=sha256:86c1c12f6389ccc450a85d82068124f3877535aaf1b523568efa0b2bf129a787

Observation 4c55f5ff-b7b2-49e0-b5ae-bf31ba288518 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 169

Resolution
metadata mismatch
arxiv_id, observed 2026-06-27T13:20:56.861621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:6ae967dbbf0ad2df76d0d92a1e395046a0290144f2b1c93992ccc5d97409b205

Observation 01c9d6af-ab45-478f-b192-6a0bd6206d97 · inbound

The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements cites this paper.

The Containment Gap: How Deployed Agentic AI Frameworks Fail Public-Facing Safety Requirements Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 46

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T13:58:21.480844Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-06-27T07:25:32.556071Z digest=sha256:2d58270fd8691ca0729f6581913a064d336670bfd1a7ed921276cdb051e8f7e0

Observation 93786acb-87e0-40fb-b858-9a70b705906b · inbound

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems cites this paper.

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-06-30T16:14:53.967870Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-30T04:48:51.748711Z digest=sha256:9eebd88879890090053fec1c40e009fef2c47db673531bb6243df225249efdbc

Observation dedaafb1-0aa6-45b0-97d2-3ca92045901b · inbound

Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety cites this paper.

Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 14

Resolution
verified exact
local_arxiv, observed 2026-07-09T20:16:29.367118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-07-09T20:14:36.433937Z digest=sha256:2c2b6324d788068d0eacc42ceccd3f6f235b0a60be72e353367bd0bc4a25d7c0

Observation d976e7ac-341b-42cd-8b2c-dcb1a89582dc · inbound

Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across LLM Agents cites this paper.

Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across LLM Agents Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T14:16:00.056317Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T14:16:00.056317Z digest=sha256:91e8c4b3b7bce80747ff2903e4f0823accf2915c43099738ed33606120ba2197

Observation 773b3310-e45e-4e2a-bada-1eed7cd2b555 · inbound

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems cites this paper.

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T00:51:17.583274Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T00:51:17.583274Z digest=sha256:00689b5b2b6f9e6ff0004441a6fdafce4ffab9bbc1e88c93fa4da2c8faeff844

Observation 541b6dc2-c999-481c-a71c-6655196b1abf · inbound

From Monoliths to Swarms: A Study of Attack Surface Evolution in the Transition to Multi-Agent Web Systems cites this paper.

From Monoliths to Swarms: A Study of Attack Surface Evolution in the Transition to Multi-Agent Web Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-04T01:03:46.926679Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T01:03:46.926679Z digest=sha256:f03adca25cee64479fecc3d78a23928ac30dd8d70f867d8054c4c6f5503560f5

Observation 6ea42930-0465-4304-98ea-353cd51db98b · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T00:25:59.475710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T00:25:59.475710Z digest=sha256:1ac22539376a524cf5fc8aafcb054b4d8bc307f5a3d8c92a5bf7e88dc71ca363

Observation df05d453-c18f-46f1-af60-291b8c858210 · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:76b95d390a08f6783a67403cdc30692f1ca3dcdda3b95e02535bc86e5dd39825

Observation e69bc127-7d6e-4261-86b0-333670b84d27 · inbound

Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity cites this paper.

Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-05T22:07:42.214656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T22:07:42.214656Z digest=sha256:2a6fd43f7fb8c82446f1b0960024eba9483be643a10e65362a8af85fe93fc2d1