{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:40:16Z","timestamp":1784738416509,"version":"3.55.0"},"reference-count":98,"publisher":"Elsevier BV","issue":"2","license":[{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T00:00:00Z","timestamp":1764633600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006013","name":"United Arab Emirates University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100006013","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["ICT Express"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1016\/j.icte.2025.12.001","type":"journal-article","created":{"date-parts":[[2025,12,13]],"date-time":"2025-12-13T16:19:08Z","timestamp":1765642748000},"page":"353-383","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":30,"title":["From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows"],"prefix":"10.1016","volume":"12","author":[{"given":"Mohamed Amine","family":"Ferrag","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Norbert","family":"Tihanyi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Djallel","family":"Hamouda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Leandros","family":"Maglaras","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abderrahmane","family":"Lakas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Merouane","family":"Debbah","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.icte.2025.12.001_b1","series-title":"Ai agents vs. agentic ai: A conceptual taxonomy, applications and challenge","author":"Sapkota","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b2","series-title":"From llm reasoning to autonomous ai agents: A comprehensive review","author":"Ferrag","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2024.100666","article-title":"Deep study on autonomous learning techniques for complex pattern recognition in interconnected information systems","volume":"54","author":"Amiri","year":"2024","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.icte.2025.12.001_b4","series-title":"Reasoning beyond limits: Advances and open problems for llms","author":"Ferrag","year":"2025"},{"issue":"10","key":"10.1016\/j.icte.2025.12.001_b5","doi-asserted-by":"crossref","first-page":"8445","DOI":"10.1109\/JIOT.2023.3237661","article-title":"A secure intrusion detection platform using blockchain and radial basis function neural networks for internet of drones","volume":"10","author":"Heidari","year":"2023","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.icte.2025.12.001_b6","series-title":"Vibe coding vs. agentic coding: Fundamentals and practical implications of agentic ai","author":"Sapkota","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b7","series-title":"Beyond self-talk: A communication-centric survey of llm-based multi-agent systems","author":"Yan","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b8","series-title":"Survey on evaluation of llm-based agents","author":"Yehudai","year":"2025"},{"issue":"6","key":"10.1016\/j.icte.2025.12.001_b9","doi-asserted-by":"crossref","first-page":"3753","DOI":"10.1007\/s10586-022-03776-z","article-title":"Internet of things intrusion detection systems: a comprehensive review and future directions","volume":"26","author":"Heidari","year":"2023","journal-title":"Clust. Comput."},{"key":"10.1016\/j.icte.2025.12.001_b10","series-title":"From large ai models to agentic ai: A tutorial on future intelligent communications","author":"Jiang","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b11","series-title":"Multi-agent collaboration mechanisms: A survey of LLMs","author":"Tran","year":"2025"},{"issue":"7","key":"10.1016\/j.icte.2025.12.001_b12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3716628","article-title":"Ai agents under threat: A survey of key security challenges and future pathways","volume":"57","author":"Deng","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.icte.2025.12.001_b13","series-title":"Agentic AI for intent-based industrial automation","author":"Romero","year":"2025"},{"issue":"6","key":"10.1016\/j.icte.2025.12.001_b14","doi-asserted-by":"crossref","first-page":"1666","DOI":"10.3390\/s25061666","article-title":"Generative AI and LLMs for critical infrastructure protection: evaluation benchmarks, agentic AI, challenges, and opportunities","volume":"25","author":"Yigit","year":"2025","journal-title":"Sensors"},{"key":"10.1016\/j.icte.2025.12.001_b15","series-title":"Enterprise-grade security for the model context protocol (mcp): Frameworks and mitigation strategies","author":"Narajala","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b16","series-title":"A survey of agent interoperability protocols: Model context protocol (mcp), agent communication protocol (acp), agent-to-agent protocol (a2a), and agent network protocol (anp)","author":"Ehtesham","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b17","series-title":"A survey of AI agent protocols","author":"Yang","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b18","series-title":"From standalone LLMs to integrated intelligence: A survey of compound al systems","author":"Chen","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b19","series-title":"A survey of foundation models for IoT: Taxonomy and criteria-based analysis","author":"Wei","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b20","series-title":"Adaptive attacks break defenses against indirect prompt injection attacks on LLM agents","author":"Zhan","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b21","doi-asserted-by":"crossref","DOI":"10.1145\/3717067","article-title":"Deceiving LLM through compositional instruction with hidden attacks","author":"Jiang","year":"2025","journal-title":"ACM Trans. Auton. Adapt. Syst."},{"key":"10.1016\/j.icte.2025.12.001_b22","series-title":"Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts","author":"Yu","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b23","series-title":"Graph of attacks with pruning: Optimizing stealthy jailbreak prompt generation for enhanced LLM content moderation","author":"Schwartz","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b24","series-title":"Aeia-mn: Evaluating the robustness of multimodal llm-powered mobile agents against active environmental injection attacks","author":"Chen","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b25","series-title":"Composite backdoor attacks against large language models","author":"Huang","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b26","series-title":"Demonagent: Dynamically encrypted multi-backdoor implantation attack on llm-based agent","author":"Zhu","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b27","series-title":"Poisonedrag: Knowledge corruption attacks to retrieval-augmented generation of large language models","author":"Zou","year":"2024"},{"issue":"4","key":"10.1016\/j.icte.2025.12.001_b28","doi-asserted-by":"crossref","first-page":"3255","DOI":"10.1007\/s11276-025-03932-4","article-title":"Securing and optimizing IoT offloading with blockchain and deep reinforcement learning in multi-user environments","volume":"31","author":"Heidari","year":"2025","journal-title":"Wirel. Netw."},{"issue":"6","key":"10.1016\/j.icte.2025.12.001_b29","doi-asserted-by":"crossref","DOI":"10.1002\/itl2.530","article-title":"Everything you wanted to know about ChatGPT: Components, capabilities, applications, and opportunities","volume":"7","author":"Heidari","year":"2024","journal-title":"Internet Technol. Lett."},{"key":"10.1016\/j.icte.2025.12.001_b30","series-title":"100 Days after deepseek-r1: A survey on replication studies and more directions for reasoning language models","author":"Zhang","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b31","series-title":"Model context protocol (mcp): Landscape, security threats, and future research directions","author":"Hou","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b32","doi-asserted-by":"crossref","DOI":"10.1007\/s11432-024-4465-3","article-title":"On privacy, security, and trustworthiness in distributed wireless large AI models","volume":"68","author":"Yang","year":"2025","journal-title":"Sci. China Inf. Sci."},{"issue":"7","key":"10.1016\/j.icte.2025.12.001_b33","doi-asserted-by":"crossref","first-page":"6139","DOI":"10.1007\/s10115-025-02410-9","article-title":"A new flow-based approach for enhancing botnet detection efficiency using convolutional neural networks and long short-term memory","volume":"67","author":"Asadi","year":"2025","journal-title":"Knowl. Inf. Syst."},{"key":"10.1016\/j.icte.2025.12.001_b34","series-title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","author":"Wang","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b35","series-title":"A survey on the safety and security threats of computer-using agents: JARVIS or ultron?","author":"Chen","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b36","doi-asserted-by":"crossref","DOI":"10.1109\/OJCOMS.2024.3456549","article-title":"Llm-based edge intelligence: A comprehensive survey on architectures, applications, security and trustworthiness","author":"Friha","year":"2024","journal-title":"IEEE Open J. Commun. Soc."},{"key":"10.1016\/j.icte.2025.12.001_b37","doi-asserted-by":"crossref","DOI":"10.1016\/j.iotcps.2025.01.001","article-title":"Generative AI in cybersecurity: A comprehensive review of llm applications and vulnerabilities","author":"Ferrag","year":"2025","journal-title":"Internet Things Cyber-Physical Syst."},{"key":"10.1016\/j.icte.2025.12.001_b38","doi-asserted-by":"crossref","unstructured":"Y. Yang, R. Gao, X. Wang, T.-Y. Ho, N. Xu, Q. Xu, Mma-diffusion: Multimodal attack on diffusion models, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 7737\u20137746.","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"10.1016\/j.icte.2025.12.001_b39","series-title":"Seeing is believing: Black-box membership inference attacks against retrieval augmented generation","first-page":"arXiv","author":"Li","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b40","series-title":"Ignore previous prompt: Attack techniques for language models","author":"Perez","year":"2022"},{"key":"10.1016\/j.icte.2025.12.001_b41","series-title":"From prompt injections to sql injection attacks: How protected is your llm-integrated web application?","author":"Pedro","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b42","series-title":"Abusing images and sounds for indirect instruction injection in multi-modal LLMs","author":"Bagdasaryan","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b43","series-title":"Jailbreak and guard aligned language models with only few in-context demonstrations","author":"Wei","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b44","series-title":"Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models","author":"Shayegani","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b45","first-page":"129696","article-title":"Many-shot jailbreaking","volume":"37","author":"Anil","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.icte.2025.12.001_b46","series-title":"Autodan: Generating stealthy jailbreak prompts on aligned large language models","author":"Liu","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b47","series-title":"2025 IEEE Symposium on Security and Privacy","first-page":"336","article-title":"Fuzz-testing meets LLM-based agents: An automated and efficient framework for jailbreaking text-to-image generation models","author":"Dong","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b48","series-title":"Adversarial demonstration attacks on large language models","author":"Wang","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b49","doi-asserted-by":"crossref","unstructured":"H. Zhuang, Y. Zhang, S. Liu, A pilot study of query-free adversarial attack against stable diffusion, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 2385\u20132392.","DOI":"10.1109\/CVPRW59228.2023.00236"},{"key":"10.1016\/j.icte.2025.12.001_b50","series-title":"Real AI agents with fake memories: Fatal context manipulation attacks on Web3 agents","author":"Patlan","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b51","series-title":"GitHub MCP exploited: Accessing private repositories via MCP","author":"Milanta","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b52","first-page":"100938","article-title":"Watch out for your agents! investigating backdoor threats to llm-based agents","volume":"37","author":"Yang","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.icte.2025.12.001_b53","doi-asserted-by":"crossref","first-page":"37068","DOI":"10.52202\/068431-2686","article-title":"Badprompt: Backdoor attacks on continuous prompts","volume":"35","author":"Cai","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.icte.2025.12.001_b54","series-title":"ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing","first-page":"7745","article-title":"Poisonprompt: Backdoor attack on prompt-based large language models","author":"Yao","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b55","series-title":"Badagent: Inserting and activating backdoor attacks in llm agents","author":"Wang","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b56","first-page":"1","article-title":"Medical large language models are vulnerable to data-poisoning attacks","author":"Alber","year":"2025","journal-title":"Nature Med."},{"key":"10.1016\/j.icte.2025.12.001_b57","doi-asserted-by":"crossref","unstructured":"Q. Zhang, B. Zeng, C. Zhou, G. Go, H. Shi, Y. Jiang, Human-imperceptible retrieval poisoning attacks in LLM-powered applications, in: Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering, 2024, pp. 502\u2013506.","DOI":"10.1145\/3663529.3663786"},{"key":"10.1016\/j.icte.2025.12.001_b58","series-title":"Concealed data poisoning attacks on NLP models","author":"Wallace","year":"2020"},{"key":"10.1016\/j.icte.2025.12.001_b59","unstructured":"M. Fang, X. Cao, J. Jia, N. Gong, Local model poisoning attacks to {Byzantine-Robust} federated learning, in: 29th USENIX Security Symposium (USENIX Security 20), 2020, pp. 1605\u20131622."},{"key":"10.1016\/j.icte.2025.12.001_b60","series-title":"A practical memory injection attack against llm agents","author":"Dong","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b61","series-title":"Fedsecurity: Benchmarking attacks and defenses in federated learning and federated llms","author":"Han","year":"2023"},{"key":"10.1016\/j.icte.2025.12.001_b62","series-title":"Follow my instruction and spill the beans: Scalable data extraction from retrieval-augmented generation systems","author":"Qi","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b63","article-title":"Wiretapping LLMs: Network side-channel attacks on interactive llm services","author":"Soleimani","year":"2025","journal-title":"Cryptol. EPrint Arch."},{"key":"10.1016\/j.icte.2025.12.001_b64","series-title":"CORBA: Contagious recursive blocking attacks on multi-agent systems based on large language models","author":"Zhou","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b65","series-title":"Personalized attacks of social engineering in multi-turn conversations\u2013LLM agents for simulation and detection","author":"Kumarage","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b66","series-title":"Introduction to MCP","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b67","series-title":"A2A: A New Era of Agent Interoperability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b68","series-title":"Agent network protocol GitHub repository","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b69","series-title":"Agent communication protocol","year":"2024"},{"key":"10.1016\/j.icte.2025.12.001_b70","series-title":"Building a secure agentic AI application leveraging A2A protocol","author":"Habler","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b71","series-title":"CVE-2025-46059: LangChain \u2013 GmailToolkit (v0.3.51) Indirect Prompt Injection Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b72","series-title":"CWE-94: Improper Control of Generation of Code (\u2019Code Injection\u2019)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b73","series-title":"CVE-2025-2828: LangChain \u2013 RequestsToolkit (OpenAPI Tool) SSRF Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b74","series-title":"CWE-918: Server-Side Request Forgery (SSRF)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b75","series-title":"CVE-2025-6984: LangChain \u2013 EverNoteLoader (v0.3.63) XML External Entity Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b76","series-title":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b77","series-title":"CVE-2025-6985: LangChain \u2013 HTMLSectionSplitter (v0.3.8) XSLT Injection Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b78","series-title":"CWE-611: Improper Restriction of XML External Entity Reference (\u2019XXE\u2019)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b79","series-title":"CVE-2025-6853: LangChain-Chatchat (v0.3.1) Path Traversal in Temporary Uploads","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b80","series-title":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u2019Path Traversal\u2019)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b81","series-title":"CVE-2025-6854: LangChain-Chatchat (v0.3.1) Base64 Path Traversal Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b82","series-title":"CVE-2025-6855: LangChain-Chatchat (v0.3.1) Path Traversal in File Uploads","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b83","series-title":"CVE-2025-11844: Hugging Face \u2013 SmolAgents (v1.20.0) XPath Injection Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b84","series-title":"CWE-643: Improper Neutralization of Data within XPath Expressions (\u2019XPath Injection\u2019)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b85","series-title":"CVE-2025-59532: OpenAI \u2013 Codex CLI (v0.2.0\u20130.38.0) Sandbox Escape Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b86","series-title":"CWE-20: Improper Input Validation","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b87","series-title":"CVE-2025-6514: Anthropic \u2013 MCP-Remote (v0.0.5\u20130.1.15) Command Execution Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b88","series-title":"CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u2019OS Command Injection\u2019)","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b89","series-title":"CVE-2025-49596: Anthropic \u2013 MCP Inspector (v0.14.0) CSRF\/DNS-Rebinding Vulnerability","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b90","series-title":"CWE-306: Missing Authentication for Critical Function","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b91","series-title":"Model context protocol (MCP) at first glance: Studying the security and maintainability of MCP servers","author":"Hasan","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b92","series-title":"MCP bridge: A lightweight, LLM-agnostic restful proxy for model context protocol servers","author":"Ahmadi","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b93","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2023.103809","article-title":"Securing the industrial internet of things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms","volume":"223","author":"Al-Hawawreh","year":"2024","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.icte.2025.12.001_b94","series-title":"Build the web for agents, not agents for the web","author":"L\u00f9","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b95","series-title":"Multi-agent design: Optimizing agents with better prompts and topologies","author":"Zhou","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b96","series-title":"Surfer-h meets Holo1: Cost-efficient web agent powered by open weights","author":"Andreux","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b97","series-title":"Mem0: Building production-ready ai agents with scalable long-term memory","author":"Chhikara","year":"2025"},{"key":"10.1016\/j.icte.2025.12.001_b98","series-title":"AlphaEvolve: A coding agent for scientific and algorithmic discovery","author":"Novikov","year":"2025"}],"container-title":["ICT Express"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2405959525001997?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2405959525001997?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T16:17:22Z","timestamp":1773937042000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2405959525001997"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4]]},"references-count":98,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["S2405959525001997"],"URL":"https:\/\/doi.org\/10.1016\/j.icte.2025.12.001","relation":{},"ISSN":["2405-9595"],"issn-type":[{"value":"2405-9595","type":"print"}],"subject":[],"published":{"date-parts":[[2026,4]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows","name":"articletitle","label":"Article Title"},{"value":"ICT Express","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.icte.2025.12.001","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Authors. Published by Elsevier B.V. on behalf of The Korean Institute of Communications and Information Sciences.","name":"copyright","label":"Copyright"}]}}