Fetching the paper…
Reading the bibliography…
Multi-agent systems coordinate LLM-based agents to perform tasks on users' behalf.
The Confused Deputy: (or why capabilities might have been invented)
Norm Hardy · 1988
Earlier work this paper cites.
Ignore Previous Prompt: Attack Techniques For Language Models, November 2022
Fábio Perez and Ian Ribeiro · 2022
Earlier work this paper cites.
Harms from Increasingly Agentic Algorithmic Systems
Alan Chan, Rebecca Salganik, Alva Markelius, Chris Pang, Nitarshan Rajkumar, Dmitrii Krasheninnikov, Lauro Langosco, Zhonghao He, Yawen Duan, Micah Carroll, Michelle Lin, Alex Mayhew, Katherine Collins, Maryam Molamohammadi, John Burden, Wanru Zhao, Shalaleh Rismani, Konstantinos Voudouris, Umang Bhatt, Adrian Weller, David Krueger, and Tegan Maharaj · 2023
Earlier work this paper cites.
crewAIInc/crewAI, February 2025
CrewAI · 2023
Earlier work this paper cites.
Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz · 2023
Earlier work this paper cites.
AgentBench: Evaluating LLMs as Agents, October 2023
Xiao Liu, Hao Yu, Hanchen Zhang, Yifan Xu, Xuanyu Lei, Hanyu Lai, Yu Gu, Hangliang Ding, Kaiwen Men, Kejuan Yang, Shudan Zhang, Xiang Deng, Aohan Zeng, Zhengxiao Du, Chenhui Zhang, Sheng Shen, Tianjun Zhang, Yu Su, Huan Sun, Minlie Huang, Yuxiao Dong, and Jie Tang · 2023
Earlier work this paper cites.
GAIA: a benchmark for General AI Assistants, November 2023
Grégoire Mialon, Clémentine Fourrier, Craig Swift, Thomas Wolf, Yann LeCun, and Thomas Scialom · 2023
Earlier work this paper cites.
Practices for Governing Agentic AI Systems
Yonadav Shavit, Sandhini Agarwal, Miles Brundage, Steven Adler, Cullen O’Keefe, Rosie Campbell, Teddy Lee, Pamela Mishkin, Tyna Eloundou, Alan Hickey, Katarina Slama, Lama Ahmad, Paul McMillan, Alex Beutel, Alexandre Passos, and David G Robinson · 2023
Earlier work this paper cites.
LLM Powered Autonomous Agents, June 2023
Lilian Weng · 2023
Earlier work this paper cites.
AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation, October 2023
Qingyun Wu, Gagan Bansal, Jieyu Zhang, Yiran Wu, Beibin Li, Erkang Zhu, Li Jiang, Xiaoyun Zhang, Shaokun Zhang, Jiale Liu, Ahmed Hassan Awadallah, Ryen W. White, Doug Burger, and Chi Wang · 2023
Earlier work this paper cites.
ReAct: Synergizing Reasoning and Acting in Language Models, March 2023
Shunyu Yao, Jeffrey Zhao, Dian Yu, Nan Du, Izhak Shafran, Karthik Narasimhan, and Yuan Cao · 2023
Earlier work this paper cites.
Universal and Transferable Adversarial Attacks on Aligned Language Models, December 2023
Andy Zou, Zifan Wang, Nicholas Carlini, Milad Nasr, J. Zico Kolter, and Matt Fredrikson · 2023
Earlier work this paper cites.
Introducing computer use, a new Claude 3.5 Sonnet, and Claude 3.5 Haiku, October 2024
Anthropic · 2024
Earlier work this paper cites.
What is an AI agent?, June 2024
Harrison Chase · 2024
Earlier work this paper cites.
Struq: Defending against prompt injection with structured queries
Sizhe Chen, Julien Piet, Chawin Sitawarin, and David Wagner · 2024
Earlier work this paper cites.
Edoardo Debenedetti, Jie Zhang, Mislav Balunović, Luca Beurer-Kellner, Marc Fischer, and Florian Tramèr · 2024
Earlier work this paper cites.
Magentic-One: A Generalist Multi-Agent System for Solving Complex Tasks
Adam Fourney, Gagan Bansal, Hussein Mozannar, Cheng Tan, Eduardo Salinas, Erkang (Eric) Zhu, Friederike Niedtner, Grace Proebsting, Griffin Bassman, Jack Gerrits, Jacob Alber, Peter Chang, Ricky Loynd, Robert West, Victor Dibia, Ahmed Awadallah, Ece Kamar, Rafah Hosn, and Saleema Amershi · 2024
Cited alongside, same era.
Imprompter: Tricking LLM Agents into Improper Tool Use, October 2024
Xiaohan Fu, Shuheng Li, Zihan Wang, Yihao Liu, Rajesh K. Gupta, Taylor Berg-Kirkpatrick, and Earlence Fernandes · 2024
Cited alongside, same era.
The Ethics of Advanced AI Assistants, April 2024
Iason Gabriel, Arianna Manzini, Geoff Keeling, Lisa Anne Hendricks, Verena Rieser, Hasan Iqbal, Nenad Tomašev, Ira Ktena, Zachary Kenton, Mikel Rodriguez, Seliem El-Sayed, Sasha Brown, Canfer Akbulut, Andrew Trask, Edward Hughes, A. Stevie Bergman, Renee Shelby, Nahema Marchal, Conor Griffin, Juan Mateos-Garcia, Laura Weidinger, Winnie Street, Benjamin Lange, Alex Ingerman, Alison Lentz, Reed Enger, Andrew Barakat, Victoria Krakovna, John Oliver Siy, Zeb Kurth-Nelson, Amanda McCroskery, Vijay Bolina, Harry Law, Murray Shanahan, Lize Alberts, Borja Balle, Sarah de Haas, Yetunde Ibitoye, Allan Dafoe, Beth Goldberg, Sébastien Krier, Alexander Reese, Sims Witherspoon, Will Hawkins, Maribeth Rauh, Don Wallace, Matija Franklin, Josh A. Goldstein, Joel Lehman, Michael Klenk, Shannon Vallor, Courtney Biles, Meredith Ringel Morris, Helen King, Blaise Agüera y Arcas, William Isaac, and James Manyika · 2024
Cited alongside, same era.
Beyond RCE: Autonomous Code Execution in Agentic AI, November 2024
Jonathan Walker · 2024
Later among the works it cites.
The instruction hierarchy: Training llms to prioritize privileged instructions
Eric Wallace, Kai Yuanqing Xiao, Reimar Heinrich Leike, Lilian Weng, Johannes Heidecke, and Alex Beutel · 2024
Later among the works it cites.
Fangzhou Wu, Ethan Cecchetti, and Chaowei Xiao · 2024
Later among the works it cites.
τ \tau -bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, June 2024
Shunyu Yao, Noah Shinn, Pedram Razavi, and Karthik Narasimhan · 2024
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Defending Against Indirect Prompt Injection Attacks With Spotlighting, March 2024
Keegan Hines, Gary Lopez, Matthew Hall, Federico Zarfati, Yonatan Zunger, and Emre Kiciman · 2024
Cited alongside, same era.
MetaGPT: Meta programming for a multi-agent collaborative framework
Sirui Hong, Mingchen Zhuge, Jonathan Chen, Xiawu Zheng, Yuheng Cheng, Jinlin Wang, Ceyao Zhang, Zili Wang, Steven Ka Shing Yau, Zijuan Lin, Liyang Zhou, Chenyu Ran, Lingfeng Xiao, Chenglin Wu, and Jürgen Schmidhuber · 2024
Cited alongside, same era.
MLAgentBench: Evaluating Language Agents on Machine Learning Experimentation, April 2024
Qian Huang, Jian Vora, Percy Liang, and Jure Leskovec · 2024
Cited alongside, same era.
Feiran Jia, Tong Wu, Xin Qin, and Anna Squicciarini · 2024
Cited alongside, same era.
Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities, July 2024
Tianjie Ju, Yiting Wang, Xinbei Ma, Pengzhou Cheng, Haodong Zhao, Yulong Wang, Lifeng Liu, Jian Xie, Zhuosheng Zhang, and Gongshen Liu · 2024
Cited alongside, same era.
AI Agents That Matter, July 2024
Sayash Kapoor, Benedikt Stroebl, Zachary S. Siegel, Nitya Nadgir, and Arvind Narayanan · 2024
Cited alongside, same era.
Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems, October 2024
Donghyun Lee and Mo Tiwari · 2024
Cited alongside, same era.
Demystifying RCE Vulnerabilities in LLM-Integrated Apps
Tong Liu, Zizhuang Deng, Guozhu Meng, Yuekang Li, and Kai Chen · 2024
Cited alongside, same era.
Tree of Attacks: Jailbreaking Black-Box LLMs Automatically, October 2024
Anay Mehrotra, Manolis Zampetakis, Paul Kassianik, Blaine Nelson, Hyrum Anderson, Yaron Singer, and Amin Karbasi · 2024
Cited alongside, same era.
Qiusi Zhan, Zhixiang Liang, Zifan Ying, and Daniel Kang · 2024
Later among the works it cites.
WebArena: A Realistic Web Environment for Building Autonomous Agents, April 2024
Shuyan Zhou, Frank F. Xu, Hao Zhu, Xuhui Zhou, Robert Lo, Abishek Sridhar, Xianyi Cheng, Tianyue Ou, Yonatan Bisk, Daniel Fried, Uri Alon, and Graham Neubig · 2024
Later among the works it cites.
Taxonomy of Failure Mode in Agentic AI Systems
Pete Bryan, Giorgio Severi, Joris de Gruyter, Daniel Jones, Blake Bullwinkel, Amanda Minnich, Shiven Chawla, Gary Lopez, Martin Pouliot, Adam Fourney, Whitney Maxwell, Katherine Pratt, Saphir Qi, Nina Chikanov, Roman Lutz, Sekhar Rao Dheekonda, Bolor-Erdene Jagdagdorj, Eugenia Kim, Justin Song, Keegan Hines, Daniel Jones, Richard Lundeen, Sam Vaughan, Victoria Westerhoff, Yonatan Zunger, Chang Kawaguchi, Mark Russinovich, and Ram Shankar Siva Kumar · 2025
Closest in time.
Secalign: Defending against prompt injection with preference optimization, 2025
Sizhe Chen, Arman Zharmagambetov, Saeed Mahloujifar, Kamalika Chaudhuri, David Wagner, and Chuan Guo · 2025
Closest in time.
Stav Cohen, Ron Bitton, and Ben Nassi · 2025
Closest in time.
On the Resilience of LLM-Based Multi-Agent Collaboration with Faulty Agents, January 2025
Jen-tse Huang, Jiaxu Zhou, Tailin Jin, Xuhui Zhou, Zixi Chen, Wenxuan Wang, Youliang Yuan, Michael R. Lyu, and Maarten Sap · 2025
Closest in time.
Same-origin policy - Security on the web | MDN, 2025
Mozilla · 2025
Closest in time.
Introducing Operator, January 2025
OpenAI · 2025
Closest in time.
Multi-Agentic system Threat Modeling Guide v1.0, Apr 2025
OWASP · 2025
Closest in time.
Rerouting LLM Routers, January 2025
Avital Shafran, Roei Schuster, Thomas Ristenpart, and Vitaly Shmatikov · 2025
Closest in time.
Investigating Privacy Bias in Training Data of Language Models, February 2025
Yan Shvartzshnaider and Vasisht Duddu · 2025
Closest in time.
Self-interpreting Adversarial Images, January 2025
Tingwei Zhang, Collin Zhang, John X. Morris, Eugene Bagdasarian, and Vitaly Shmatikov · 2025
Closest in time.