From Monoliths to Swarms: A Study of Attack Surface Evolution in the Transition to Multi-Agent Web Systems
Yashaswi Malla, Sandra Siby
cs.CR
Submitted: 2026-07-31
Code: https://github.com/haven-nyuad/webmas
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- GPT-4V(ision) is a Generalist Web Agent, if Grounded
- Multi-Agent Collaboration: Harnessing the Power of Intelligent LLM Agents
- Magentic-One: A Generalist Multi-Agent System for Solving Complex Tasks
- WorkArena: How Capable Are Web Agents at Solving Common Knowledge Work Tasks?
- SafeArena: Evaluating the Safety of Autonomous Web Agents
- TAMAS: Benchmarking Adversarial Risks in Multi-Agent LLM Systems
- TRiSM for Agentic AI: A Review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems
- Seven Security Challenges in Cross-domain Multi-agent LLM Systems
- Prompt Injection attack against LLM-integrated Applications
- Collaborative Shadows: Distributed Backdoor Attacks in LLM-Based Multi-Agent Systems
- The BrowserGym Ecosystem for Web Agent Research
- ST-WebAgentBench: A Benchmark for Evaluating Safety and Trustworthiness in Web Agents
- AgentWebBench: Benchmarking Multi-Agent Coordination in Agentic Web
- WAInjectBench: Benchmarking Prompt Injection Detections for Web Agents
- Web Fraud Attacks Against LLM-Driven Multi-Agent Systems
- Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks
- WAAA! Web Adversaries Against Agentic Browsers
- MAGPIE: A benchmark for Multi-AGent contextual PrIvacy Evaluation
- Terrarium: Revisiting the Blackboard for Multi-Agent Safety, Privacy, and Security Studies
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs