{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T03:20:18Z","timestamp":1784431218145,"version":"3.55.0"},"reference-count":166,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T00:00:00Z","timestamp":1772150400000},"content-version":"vor","delay-in-days":57,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000199","name":"U.S. Department of Agriculture","doi-asserted-by":"publisher","award":["1031712"],"award-info":[{"award-number":["1031712"]}],"id":[{"id":"10.13039\/100000199","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"Horizon Europe","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007900","name":"University of Central Florida","doi-asserted-by":"publisher","award":["2024-67022-41788"],"award-info":[{"award-number":["2024-67022-41788"]}],"id":[{"id":"10.13039\/100007900","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100005825","name":"National Institute of Food and Agriculture","doi-asserted-by":"publisher","award":["1029004"],"award-info":[{"award-number":["1029004"]}],"id":[{"id":"10.13039\/100005825","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100005825","name":"National Institute of Food and Agriculture","doi-asserted-by":"publisher","award":["AWD003473"],"award-info":[{"award-number":["AWD003473"]}],"id":[{"id":"10.13039\/100005825","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100005825","name":"National Institute of Food and Agriculture","doi-asserted-by":"publisher","award":["AWD004595"],"award-info":[{"award-number":["AWD004595"]}],"id":[{"id":"10.13039\/100005825","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["AI Open"],"published-print":{"date-parts":[[2026]]},"DOI":"10.1016\/j.aiopen.2026.02.006","type":"journal-article","created":{"date-parts":[[2026,3,2]],"date-time":"2026-03-02T20:48:15Z","timestamp":1772484495000},"page":"71-95","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":35,"special_numbering":"C","title":["TRiSM for Agentic AI: A review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems"],"prefix":"10.1016","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1061-5845","authenticated-orcid":false,"given":"Shaina","family":"Raza","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5417-6744","authenticated-orcid":false,"given":"Ranjan","family":"Sapkota","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5337-4848","authenticated-orcid":false,"given":"Manoj","family":"Karkee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4335-6915","authenticated-orcid":false,"given":"Christos","family":"Emmanouilidis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"4","key":"10.1016\/j.aiopen.2026.02.006_b1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3214303","article-title":"A survey on homomorphic encryption schemes: Theory and implementation","volume":"51","author":"Acar","year":"2018","journal-title":"ACM Comput. Surv. (Csur)"},{"key":"10.1016\/j.aiopen.2026.02.006_b2","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3532853","article-title":"Agentic AI: Autonomous intelligence for complex goals\u2013A comprehensive survey","author":"Acharya","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.aiopen.2026.02.006_b3","series-title":"OpenXAI: Towards a transparent evaluation of model explanations","author":"Agarwal","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b4","series-title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","author":"AI","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b5","series-title":"Guardrails AI \u2014 your enterprise AI needs guardrails \u2014 guardrailsai.com","author":"AI","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b6","series-title":"Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems","article-title":"Guidelines for human-AI interaction","author":"Amershi","year":"2019"},{"key":"10.1016\/j.aiopen.2026.02.006_b7","series-title":"Those aren\u2019t your memories, they\u2019re somebody else\u2019s: Seeding misinformation in chat bot memories","author":"Atkins","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b8","series-title":"Agents \u2014 AutoGen AgentChat user guide","author":"AutoGen","year":"2024"},{"issue":"6","key":"10.1016\/j.aiopen.2026.02.006_b9","first-page":"19","article-title":"An overview of penetration testing","volume":"3","author":"Bacudio","year":"2011","journal-title":"Int. J. Netw. Secur. Appl. (IJNSA)"},{"key":"10.1016\/j.aiopen.2026.02.006_b10","doi-asserted-by":"crossref","first-page":"112","DOI":"10.1016\/j.future.2023.10.008","article-title":"A derived information framework for a dynamic knowledge graph and its application to smart cities","volume":"152","author":"Bai","year":"2024","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.aiopen.2026.02.006_b11","series-title":"AI Privacy Risks & Mitigations\u2014Large Language Models (LLMs)","author":"Barber\u00e1","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b12","series-title":"Design patterns for securing llm agents against prompt injections","author":"Beurer-Kellner","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b13","series-title":"Llms for explainable ai: A comprehensive survey","author":"Bilal","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b14","doi-asserted-by":"crossref","DOI":"10.3389\/fhumd.2025.1579166","article-title":"Human-artificial interaction in the age of agentic AI: a system-theoretical approach","volume":"7","author":"Borghoff","year":"2025","journal-title":"Front. Hum. Dyn."},{"key":"10.1016\/j.aiopen.2026.02.006_b15","series-title":"Chemcrow: Augmenting large-language models with chemistry tools","author":"Bran","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b16","series-title":"California consumer privacy act (CCPA)","author":"California Department of Justice, Office of the Attorney General","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b17","series-title":"JailbreakBench: An open robustness benchmark for jailbreaking large language models","author":"Chao","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b18","article-title":"Human-in-the-loop robot learning for smart manufacturing: A human-centric perspective","author":"Chen","year":"2025","journal-title":"IEEE Trans. Autom. Sci. Eng."},{"key":"10.1016\/j.aiopen.2026.02.006_b19","series-title":"A survey on llm-based multi-agent system: Recent advances and new frontiers in application","author":"Chen","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b20","series-title":"Agentverse: Facilitating multi-agent collaboration and exploring emergent behaviors in agents","author":"Chen","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b21","series-title":"Doing a Systematic Review: A Student\u2019s Guide","author":"Cherry","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b22","series-title":"Automating security audit using large language model based agent: An exploration experiment","author":"Chin","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b23","series-title":"LangGraph: Agent orchestration framework for LLMs","author":"Corporation","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b24","series-title":"IACR Cryptology ePrint Archive","first-page":"86","article-title":"Intel SGX explained","volume":"vol. 2016","author":"Costan","year":"2016"},{"key":"10.1016\/j.aiopen.2026.02.006_b25","doi-asserted-by":"crossref","unstructured":"Cranshaw, J., Elwany, E., Newman, T., Kocielnik, R., Yu, B., Soni, S., Teevan, J., Monroy-Hern\u00e1ndez, A., 2017. Calendar. help: Designing a workflow-based scheduling agent with humans in the loop. In: Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems. pp. 2382\u20132393.","DOI":"10.1145\/3025453.3025780"},{"issue":"3","key":"10.1016\/j.aiopen.2026.02.006_b26","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1016\/S0933-3657(96)00376-4","article-title":"CADIAG-2 and MYCIN-like systems","volume":"9","author":"Daniel","year":"1997","journal-title":"Artif. Intell. Med."},{"key":"10.1016\/j.aiopen.2026.02.006_b27","series-title":"Agentic workflows for economic research: Design and implementation","author":"Dawid","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b28","series-title":"Theory of Cryptography Conference","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","author":"Dwork","year":"2006"},{"key":"10.1016\/j.aiopen.2026.02.006_b29","series-title":"Hacking auto-GPT and escaping its docker container","author":"Euler","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b30","series-title":"AI act \u2014 shaping Europe\u2019s digital future","author":"European Commission","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b31","series-title":"AI act","author":"European Commission","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b32","series-title":"General data protection regulation (GDPR) \u2013 article 25: Data protection by design and by default","author":"European Union","year":"2016"},{"issue":"2\u20133","key":"10.1016\/j.aiopen.2026.02.006_b33","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1561\/3300000019","article-title":"A pragmatic introduction to secure multi-party computation","volume":"2","author":"Evans","year":"2018","journal-title":"Found. Trends\u00ae Priv. Secur."},{"key":"10.1016\/j.aiopen.2026.02.006_b34","series-title":"Trustworthy AI on safety, bias, and privacy: A survey","author":"Fang","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b35","article-title":"Evaluating and regulating agentic AI: A study of benchmarks, metrics, and regulation","author":"Farooq","year":"2025","journal-title":"Metrics, Regul."},{"key":"10.1016\/j.aiopen.2026.02.006_b36","series-title":"Multi-agent embodied ai: Advances and future directions","author":"Feng","year":"2025"},{"issue":"11","key":"10.1016\/j.aiopen.2026.02.006_b37","doi-asserted-by":"crossref","first-page":"697","DOI":"10.3390\/info15110697","article-title":"Privacy-preserving techniques in generative AI and large language models: A narrative review","volume":"15","author":"Feretzakis","year":"2024","journal-title":"Information"},{"key":"10.1016\/j.aiopen.2026.02.006_b38","series-title":"Red teaming language models to reduce harms: Methods, scaling behaviors, and lessons learned","author":"Ganguli","year":"2022"},{"key":"10.1016\/j.aiopen.2026.02.006_b39","series-title":"Tackling trust, risk and security in AI models (AI TRiSM)","author":"Gartner","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b40","series-title":"Proceedings of the 41st Annual ACM Symposium on Theory of Computing","first-page":"169","article-title":"Fully homomorphic encryption using ideal lattices","author":"Gentry","year":"2009"},{"key":"10.1016\/j.aiopen.2026.02.006_b41","series-title":"Sciagents: Automating scientific discovery through multi-agent intelligent graph reasoning","author":"Ghafarollahi","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b42","series-title":"What is AI TRiSM?","author":"Gomstyn","year":"2025"},{"issue":"6","key":"10.1016\/j.aiopen.2026.02.006_b43","doi-asserted-by":"crossref","first-page":"908","DOI":"10.1097\/MAO.0b013e3181dd160b","article-title":"Development of a software tool using deterministic logic for the optimization of cochlear implant processor programming","volume":"31","author":"Govaerts","year":"2010","journal-title":"Otol. Neurotol."},{"key":"10.1016\/j.aiopen.2026.02.006_b44","doi-asserted-by":"crossref","DOI":"10.1016\/j.accinf.2024.100698","article-title":"Artificial intelligence co-piloted auditing","volume":"54","author":"Gu","year":"2024","journal-title":"Int. J. Account. Inf. Syst."},{"key":"10.1016\/j.aiopen.2026.02.006_b45","series-title":"Large language model based multi-agents: A survey of progress and challenges","author":"Guo","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b46","article-title":"A survey on semantic communication networks: Architecture, security, and privacy","author":"Guo","year":"2024","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.aiopen.2026.02.006_b47","series-title":"Causal explanations for sequential decision-making in multi-agent systems","author":"Gyevnar","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b48","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122442","article-title":"Artificial intelligence trust, risk and security management (AI trism): Frameworks, applications, challenges and future research directions","volume":"240","author":"Habbal","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.aiopen.2026.02.006_b49","unstructured":"Hannebauer, M., 1999. From formal workflow models to intelligent agents. In: Proceedings of the AAAI-99 Workshop on Agent Based Systems in the Business Context. pp. 19\u201324."},{"key":"10.1016\/j.aiopen.2026.02.006_b50","series-title":"Security of ai agents","author":"He","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b51","series-title":"WebVoyager: Building an end-to-end web agent with large multimodal models","author":"He","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b52","series-title":"Behaviour based AI, Cognitive Processes, and Emergent Behaviors in Autonomous Agents","author":"Hexmoor","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b53","series-title":"The Twelfth International Conference on Learning Representations","article-title":"MetaGPT: Meta programming for a multi-agent collaborative framework","author":"Hong","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b54","article-title":"An overview: Attention mechanisms in multi-agent reinforcement learning","author":"Hu","year":"2024","journal-title":"Neurocomputing"},{"key":"10.1016\/j.aiopen.2026.02.006_b55","series-title":"ISO\/IEC 42001:2023 \u2013 Artificial Intelligence Management System (AI MS) \u2013 Requirements","author":"International Organization for Standardization","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b56","series-title":"Prompt Injection Attacks on Applications That Use LLMs","author":"Invicti Security","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b57","series-title":"ISO\/IEC TR 24029-1:2021 \u2013 Artificial Intelligence (AI) \u2013 Assessment of the Robustness of Neural Networks \u2013 Part 1: Overview","author":"ISO\/IEC","year":"2021"},{"key":"10.1016\/j.aiopen.2026.02.006_b58","series-title":"Information technology \u2013 artificial intelligence (AI) \u2013 AI system impact assessment","author":"ISO\/IEC","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b59","series-title":"MRKL systems: A modular, neuro-symbolic architecture that combines large language models, external knowledge sources and discrete reasoning","author":"Karpas","year":"2022"},{"key":"10.1016\/j.aiopen.2026.02.006_b60","article-title":"Building trust with AI trism: Managing risks in the era of agentic AI","author":"Kaur","year":"2024","journal-title":"Akira AI Blog"},{"key":"10.1016\/j.aiopen.2026.02.006_b61","series-title":"Meta-design matters: A self-design multi-agent system","author":"Ke","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b62","unstructured":"Keele, S., et al., 2007. Guidelines for Performing Systematic Literature Reviews in Software Engineering. Technical Report, Technical report, ver. 2.3 ebse technical report. ebse."},{"key":"10.1016\/j.aiopen.2026.02.006_b63","series-title":"Improving Security, Privacy, and Trust in Cloud Computing","first-page":"113","article-title":"Role-based access control (rbac) and attribute-based access control (abac)","author":"Khan","year":"2024"},{"issue":"2004","key":"10.1016\/j.aiopen.2026.02.006_b64","first-page":"1","article-title":"Procedures for performing systematic reviews","volume":"33","author":"Kitchenham","year":"2004","journal-title":"Keele, UK, Keele Univ."},{"key":"10.1016\/j.aiopen.2026.02.006_b65","series-title":"Seven security challenges that must be solved in cross-domain multi-agent LLM systems","author":"Ko","year":"2025"},{"issue":"1","key":"10.1016\/j.aiopen.2026.02.006_b66","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/0004-3702(87)90050-6","article-title":"Soar: An architecture for general intelligence","volume":"33","author":"Laird","year":"1987","journal-title":"Artificial Intelligence"},{"key":"10.1016\/j.aiopen.2026.02.006_b67","article-title":"LangChain and LangGraph: Comparing function and tool calling capabilities","author":"LangChain Team","year":"2024","journal-title":"LangChain Blog"},{"issue":"1","key":"10.1016\/j.aiopen.2026.02.006_b68","first-page":"1","article-title":"Cognitive architectures: Research issues and challenges","volume":"7","author":"Langley","year":"2006","journal-title":"Cogn. Syst. Res."},{"issue":"23","key":"10.1016\/j.aiopen.2026.02.006_b69","doi-asserted-by":"crossref","first-page":"4744","DOI":"10.3390\/electronics13234744","article-title":"Federated learning: Navigating the landscape of collaborative intelligence","volume":"13","author":"Lazaros","year":"2024","journal-title":"Electronics"},{"issue":"3","key":"10.1016\/j.aiopen.2026.02.006_b70","doi-asserted-by":"crossref","first-page":"402","DOI":"10.1007\/s10669-022-09855-1","article-title":"ModelOps for enhanced decision-making and governance in emergency control rooms","volume":"42","author":"Lefevre","year":"2022","journal-title":"Environ. Syst. Decis."},{"key":"10.1016\/j.aiopen.2026.02.006_b71","unstructured":"Li, G., Hammoud, H.A.A.K., Itani, H., Khizbullin, D., Ghanem, B., 2023. CAMEL: Communicative Agents for \u201cMind\u201d Exploration of Large Language Model Society. In: Thirty-Seventh Conference on Neural Information Processing Systems."},{"key":"10.1016\/j.aiopen.2026.02.006_b72","series-title":"API-bank: A comprehensive benchmark for tool-augmented LLMs","author":"Li","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b73","series-title":"Holistic evaluation of language models","author":"Liang","year":"2022"},{"issue":"1","key":"10.1016\/j.aiopen.2026.02.006_b74","doi-asserted-by":"crossref","first-page":"788","DOI":"10.1038\/s41597-022-01895-1","article-title":"On using simulation to predict the performance of robot swarms","volume":"9","author":"Ligot","year":"2022","journal-title":"Sci. Data"},{"key":"10.1016\/j.aiopen.2026.02.006_b75","series-title":"Human-Computer Interaction: The Agency Perspective","first-page":"241","article-title":"Memory models for intelligent social companions","author":"Lim","year":"2012"},{"key":"10.1016\/j.aiopen.2026.02.006_b76","series-title":"Creativity in LLM-based multi-agent systems: A survey","author":"Lin","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b77","series-title":"Advances in Cryptology\u2014EUROCRYPT 2007","first-page":"329","article-title":"Secure two-party computation via cut-and-choose oblivious transfer","author":"Lindell","year":"2007"},{"key":"10.1016\/j.aiopen.2026.02.006_b78","article-title":"AI trust and AI risk: Tackling trust, risk and security in AI models","author":"Litan","year":"2024","journal-title":"Gartner"},{"key":"10.1016\/j.aiopen.2026.02.006_b79","series-title":"G-eval: NLG evaluation using GPT-4 with better human alignment","author":"Liu","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b80","series-title":"Agent-environment alignment via automated interface generation","author":"Liu","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b81","series-title":"Lost in the middle: How language models use long contexts","author":"Liu","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b82","series-title":"Computer Graphics Forum","article-title":"AVA: Towards autonomous visualization agents through visual perception-driven decision-making","volume":"vol. 43","author":"Liu","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b83","series-title":"AgentBench: Evaluating LLMs as agents","author":"Liu","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b84","series-title":"LlamaIndex agents documentation","author":"LlamaIndex","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b85","doi-asserted-by":"crossref","unstructured":"Lo, F.P.-W., Qiu, J., Wang, Z., Yu, H., Chen, Y., Zhang, G., Lo, B., 2025. AI hiring with llms: A context-aware and explainable multi-agent framework for resume screening. In: Proceedings of the Computer Vision and Pattern Recognition Conference. pp. 4184\u20134193.","DOI":"10.1109\/CVPRW67362.2025.00402"},{"key":"10.1016\/j.aiopen.2026.02.006_b86","series-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","first-page":"4765","article-title":"A unified approach to interpreting model predictions","author":"Lundberg","year":"2017"},{"key":"10.1016\/j.aiopen.2026.02.006_b87","series-title":"Large language model agent: A survey on methodology, applications and challenges","author":"Luo","year":"2025"},{"issue":"4","key":"10.1016\/j.aiopen.2026.02.006_b88","doi-asserted-by":"crossref","first-page":"824","DOI":"10.1109\/JAS.2024.124215","article-title":"A tutorial on federated learning from theory to practice: Foundations, software frameworks, exemplary use cases, and selected trends","volume":"11","author":"Luz\u00f3n","year":"2024","journal-title":"IEEE\/CAA J. Autom. Sin."},{"key":"10.1016\/j.aiopen.2026.02.006_b89","series-title":"HarmBench: A standardized evaluation framework for automated red teaming and robust refusal","author":"Mazeika","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b90","series-title":"GAIA: A benchmark for general AI assistants","author":"Mialon","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b91","doi-asserted-by":"crossref","unstructured":"Miao, H., Ma, F., Quan, R., Zhan, K., Yang, Y., 2025. Autonomous LLM-enhanced adversarial attack for text-to-motion. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol. 39, pp. 6144\u20136152, 6.","DOI":"10.1609\/aaai.v39i6.32657"},{"key":"10.1016\/j.aiopen.2026.02.006_b92","series-title":"Semantic kernel agent framework","author":"Microsoft","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b93","series-title":"MLCommons AI safety benchmark v0.5","author":"MLCommons AI Safety Working Group","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b94","series-title":"CrewAI: Framework for orchestrating role-playing, autonomous AI agents","author":"Moura","year":"2023"},{"issue":"1\u20132","key":"10.1016\/j.aiopen.2026.02.006_b95","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S0004-3702(98)00068-X","article-title":"Remote agent: To boldly go where no AI system has gone before","volume":"103","author":"Muscettola","year":"1998","journal-title":"Artificial Intelligence"},{"key":"10.1016\/j.aiopen.2026.02.006_b96","series-title":"Leveraging large language models for effective and explainable multi-agent credit assignment","author":"Nagpal","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b97","series-title":"BabyAGI (archived version)","author":"Nakajima","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b98","series-title":"OECD.AI catalogue of tools and metrics for trustworthy AI","author":"OECD","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b99","series-title":"OWASP top 10 for large language model applications","author":"Open Worldwide Application Security Project (OWASP)","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b100","series-title":"gpt-engineer: CLI platform to experiment with codegen","author":"Osika","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b101","series-title":"Agentic AI \u2013 Threats and Mitigations","author":"OWASP Agentic Security Initiative","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b102","series-title":"Trustworthy AI psychotherapy: Multi-agent LLM workflow for counseling and explainable mental disorder diagnosis","author":"Ozgun","year":"2025"},{"issue":"3","key":"10.1016\/j.aiopen.2026.02.006_b103","doi-asserted-by":"crossref","first-page":"381","DOI":"10.1177\/0018720810376055","article-title":"Complacency and bias in human use of automation: An attentional integration","volume":"52","author":"Parasuraman","year":"2010","journal-title":"Hum. Factors"},{"key":"10.1016\/j.aiopen.2026.02.006_b104","series-title":"Four principles of explainable artificial intelligence","author":"Phillips","year":"2021"},{"key":"10.1016\/j.aiopen.2026.02.006_b105","series-title":"Strands agents SDK (python)","author":"Project","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b106","series-title":"Communicative agents for software development","author":"Qian","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b107","series-title":"Chatdev: Communicative agents for software development","author":"Qian","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b108","first-page":"114843","article-title":"Agent planning with world knowledge model","volume":"37","author":"Qiao","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.aiopen.2026.02.006_b109","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C., 2016. \u201cWhy should i trust you?\u201d Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. pp. 1135\u20131144.","DOI":"10.1145\/2939672.2939778"},{"key":"10.1016\/j.aiopen.2026.02.006_b110","doi-asserted-by":"crossref","unstructured":"Rodden, K., Hutchinson, H., Fu, X., 2010. Measuring the user experience on a large scale: user-centered metrics for web applications. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. pp. 2395\u20132398.","DOI":"10.1145\/1753326.1753687"},{"key":"10.1016\/j.aiopen.2026.02.006_b111","doi-asserted-by":"crossref","first-page":"673","DOI":"10.1007\/s10458-019-09408-y","article-title":"Explainability in human\u2013agent systems","volume":"33","author":"Rosenfeld","year":"2019","journal-title":"Auton. Agents Multi-Agent Syst."},{"issue":"1\u20132","key":"10.1016\/j.aiopen.2026.02.006_b112","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1016\/S0004-3702(97)00026-X","article-title":"Rationality and intelligence","volume":"94","author":"Russell","year":"1997","journal-title":"Artificial Intelligence"},{"key":"10.1016\/j.aiopen.2026.02.006_b113","series-title":"Breaking the code: Security assessment of ai code agents through systematic jailbreaking attacks","author":"Saha","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b114","series-title":"Layered chain-of-thought prompting for multi-agent llm systems: A comprehensive approach to explainable large language models","author":"Sanwal","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b115","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2025.103599","article-title":"AI agents vs. Agentic AI: A conceptual taxonomy, applications and challenges","volume":"126","author":"Sapkota","year":"2026","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.aiopen.2026.02.006_b116","series-title":"LLM agents","author":"Saravia","year":"2024"},{"issue":"2","key":"10.1016\/j.aiopen.2026.02.006_b117","first-page":"267","article-title":"Privacy by design","volume":"3","author":"Schaar","year":"2010","journal-title":"Identity Inf. Soc."},{"key":"10.1016\/j.aiopen.2026.02.006_b118","series-title":"Toolformer: Language models can teach themselves to use tools","author":"Schick","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b119","article-title":"Wargaming cyber security","author":"Schneider","year":"2020","journal-title":"War the Rocks"},{"key":"10.1016\/j.aiopen.2026.02.006_b120","series-title":"Generative to agentic ai: Survey, conceptualization, and challenges","author":"Schneider","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b121","series-title":"OpenAI agents SDK (python)","author":"SDK","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b122","series-title":"What is AI TRiSM and why it\u2019s essential in the era of GenAI","author":"Securiti","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b123","first-page":"38154","article-title":"Hugginggpt: Solving ai tasks with chatgpt and its friends in hugging face","volume":"36","author":"Shen","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.aiopen.2026.02.006_b124","series-title":"Reflexion: Language agents with verbal reinforcement learning","author":"Shinn","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b125","series-title":"Explainable reinforcement learning agents using world models","author":"Singh","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b126","series-title":"The state of AI: How organizations are rewiring to capture value","author":"Singla","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b127","article-title":"The rise of ModelOps: What comes after MLOps?","author":"Sinha","year":"2025","journal-title":"Brim Labs Blog"},{"issue":"5","key":"10.1016\/j.aiopen.2026.02.006_b128","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3708320","article-title":"Adversarial machine learning attacks and defences in multi-agent reinforcement learning","volume":"57","author":"Standen","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.aiopen.2026.02.006_b129","series-title":"2025 AI index report","author":"Stanford HAI","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b130","unstructured":"Strobel, V., Dorigo, M., Fritz, M., 2024. LLM2Swarm: Robot Swarms that Responsively Reason, Plan, and Collaborate through LLMs. In: NeurIPS 2024 Workshop on Open-World Agents. OWA-2024."},{"key":"10.1016\/j.aiopen.2026.02.006_b131","series-title":"Swarm: Lightweight multi-agent orchestration framework","author":"Swarm","year":"2024"},{"issue":"05","key":"10.1016\/j.aiopen.2026.02.006_b132","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1142\/S0218488502001648","article-title":"k-anonymity: A model for protecting privacy","volume":"10","author":"Sweeney","year":"2002","journal-title":"Internat. J. Uncertain. Fuzziness Knowledge-Based Systems"},{"key":"10.1016\/j.aiopen.2026.02.006_b133","first-page":"29","article-title":"Modeling paradigms in ACT-R","author":"Taatgen","year":"2006","journal-title":"Cogn. Multi-Agent Interact.: From Cogn. Model. Soc. Simul."},{"issue":"58","key":"10.1016\/j.aiopen.2026.02.006_b134","first-page":"59","article-title":"The emerging role of ISO 42001 certification in fostering the deployment of responsible generative AI healthcare solutions","volume":"55","author":"Thiers","year":"2024","journal-title":"Technol. (NIST)"},{"key":"10.1016\/j.aiopen.2026.02.006_b135","series-title":"An outlook on the opportunities and challenges of multi-agent AI systems","author":"Tian","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b136","series-title":"Interpretable to whom? A role-based model for analyzing interpretable machine learning systems","author":"Tomsett","year":"2018"},{"key":"10.1016\/j.aiopen.2026.02.006_b137","series-title":"Multi-agent collaboration mechanisms: A survey of LLMs","author":"Tran","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b138","series-title":"SuperAGI: A dev-first open source autonomous AI agent framework","author":"TransformerOptimus","year":"2023"},{"issue":"5","key":"10.1016\/j.aiopen.2026.02.006_b139","doi-asserted-by":"crossref","first-page":"2392","DOI":"10.3390\/smartcities7050094","article-title":"Towards next-generation urban decision support systems through ai-powered construction of scientific ontology using large language models\u2014A case in optimizing intermodal freight transportation","volume":"7","author":"Tupayachi","year":"2024","journal-title":"Smart Cities"},{"key":"10.1016\/j.aiopen.2026.02.006_b140","series-title":"HIPAA privacy rule \u2013 45 CFR part 164: Security and privacy protections for health information","author":"U.S. Department of Health and Human Services","year":"2003"},{"key":"10.1016\/j.aiopen.2026.02.006_b141","series-title":"Eliza: A web3 friendly ai agent operating system","author":"Walters","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b142","series-title":"Agent AI with LangGraph: A modular framework for enhancing machine translation using large language models","author":"Wang","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b143","series-title":"Internet of agents: Fundamentals, applications, and challenges","author":"Wang","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b144","series-title":"A survey of LLM-based agents in medicine: How far are we from Baymax?","author":"Wang","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b145","doi-asserted-by":"crossref","first-page":"1611","DOI":"10.1109\/OJCS.2025.3589638","article-title":"Security of internet of agents: Attacks and countermeasures","volume":"6","author":"Wang","year":"2025","journal-title":"IEEE Open J. Comput. Soc."},{"key":"10.1016\/j.aiopen.2026.02.006_b146","series-title":"Findings of the Association for Computational Linguistics: ACL 2025","first-page":"4998","article-title":"MegaAgent: A large-scale autonomous LLM-based multi-agent system without predefined SOPs","author":"Wang","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b147","series-title":"Voyager: An open-ended embodied agent with large language models","author":"Wang","year":"2023"},{"issue":"1","key":"10.1016\/j.aiopen.2026.02.006_b148","doi-asserted-by":"crossref","first-page":"93","DOI":"10.3233\/MGS-2009-0121","article-title":"The agent environment in multi-agent systems: A middleware perspective","volume":"5","author":"Weyns","year":"2009","journal-title":"Multiagent Grid Syst."},{"key":"10.1016\/j.aiopen.2026.02.006_b149","series-title":"Open challenges in multi-agent security: Towards secure systems of interacting AI agents","author":"de Witt","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b150","series-title":"Autogen: Enabling next-gen llm applications via multi-agent conversation","author":"Wu","year":"2023"},{"issue":"2","key":"10.1016\/j.aiopen.2026.02.006_b151","doi-asserted-by":"crossref","DOI":"10.1007\/s11432-024-4222-0","article-title":"The rise and potential of large language model based agents: A survey","volume":"68","author":"Xi","year":"2025","journal-title":"Sci. China Inf. Sci."},{"key":"10.1016\/j.aiopen.2026.02.006_b152","doi-asserted-by":"crossref","unstructured":"Xia, F., Zamir, A.R., He, Z., Sax, A., Malik, J., Savarese, S., 2018. Gibson env: Real-world perception for embodied agents. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. pp. 9068\u20139079.","DOI":"10.1109\/CVPR.2018.00945"},{"key":"10.1016\/j.aiopen.2026.02.006_b153","series-title":"OpenAgents: An open platform for language agents in the wild","author":"Xie","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b154","series-title":"On the tool manipulation capability of open-source large language models","author":"Xu","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b155","series-title":"Beyond self-talk: A communication-centric survey of LLM-based multi-agent systems","author":"Yan","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b156","series-title":"Agentic web: Weaving the next web with ai agents","author":"Yang","year":"2025"},{"key":"10.1016\/j.aiopen.2026.02.006_b157","series-title":"Multi-llm-agent systems: Techniques and business perspectives","author":"Yang","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b158","series-title":"Auto-gpt for online decision making: Benchmarks and additional opinions","author":"Yang","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b159","series-title":"ReAct: Synergizing reasoning and acting in language models","author":"Yao","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b160","doi-asserted-by":"crossref","DOI":"10.1016\/j.compstruct.2024.118190","article-title":"Explainable artificial intelligence framework for FRP composites design","volume":"341","author":"Yossef","year":"2024","journal-title":"Compos. Struct."},{"key":"10.1016\/j.aiopen.2026.02.006_b161","doi-asserted-by":"crossref","unstructured":"Yu, M., Meng, F., Zhou, X., Wang, S., Mao, J., Pan, L., Chen, T., Wang, K., Li, X., Zhang, Y., et al., 2025. A survey on trustworthy llm agents: Threats and countermeasures. In: Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2. pp. 6216\u20136226.","DOI":"10.1145\/3711896.3736561"},{"key":"10.1016\/j.aiopen.2026.02.006_b162","series-title":"Breaking agents: Compromising autonomous llm agents through malfunction amplification","author":"Zhang","year":"2024"},{"key":"10.1016\/j.aiopen.2026.02.006_b163","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2025.110524","article-title":"A novel malware detection method based on audit logs and graph neural network","volume":"152","author":"Zhen","year":"2025","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.aiopen.2026.02.006_b164","doi-asserted-by":"crossref","unstructured":"Zhong, B., Cao, H., Zamani, M., Caccamo, M., 2023. Towards safe ai: Sandboxing dnns-based controllers in stochastic games. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol. 37, pp. 15340\u201315349, 12.","DOI":"10.1609\/aaai.v37i12.26789"},{"key":"10.1016\/j.aiopen.2026.02.006_b165","series-title":"WebArena: A realistic web environment for building autonomous agents","author":"Zhou","year":"2023"},{"key":"10.1016\/j.aiopen.2026.02.006_b166","series-title":"LLM-based human-agent collaboration and interaction systems: A survey","author":"Zou","year":"2025"}],"container-title":["AI Open"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2666651026000069?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2666651026000069?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T09:06:18Z","timestamp":1778922378000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2666651026000069"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":166,"alternative-id":["S2666651026000069"],"URL":"https:\/\/doi.org\/10.1016\/j.aiopen.2026.02.006","relation":{},"ISSN":["2666-6510"],"issn-type":[{"value":"2666-6510","type":"print"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"TRiSM for Agentic AI: A review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems","name":"articletitle","label":"Article Title"},{"value":"AI Open","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.aiopen.2026.02.006","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd.","name":"copyright","label":"Copyright"}]}}