Trust propagation and structural containment in Multi-agent LLM pipelines
cs.CR, cs.CY
Submitted: 2026-09-15
Updated: 2026-09-15
Comments: Accepted at IEEE Cyber Awareness & Research Symposium (CARS), 2026
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- Ignore Previous Prompt: Attack Techniques For Language Models
- LLM Agents Should Employ Security Principles
- Firewalls to Secure Dynamic LLM Agentic Networks
- Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
- Jatmo: Prompt Injection Defense by Task-Specific Finetuning
- Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
- ASTRIDE: A Security Threat Modeling Platform for Agentic-AI Applications
- Visual Confused Deputy: Exploiting and Defending Perception Failures in Computer-Using Agents
- SoK: The Attack Surface of Agentic AI - Tools and Autonomy
- Are AI-assisted Development Tools Immune to Prompt Injection?
- Dive into Claude Code: The Design Space of Today's and Future AI Agent Systems
- Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs