{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T08:17:33Z","timestamp":1783412253005,"version":"3.54.6"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2027,1,1]],"date-time":"2027-01-01T00:00:00Z","timestamp":1798761600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2027,1]]},"DOI":"10.1016\/j.neunet.2026.109280","type":"journal-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T06:51:28Z","timestamp":1782888688000},"page":"109280","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PA","title":["Collaborative-adversarial jailbreaking: A propagation-aware attack framework for multi-agent code generation systems"],"prefix":"10.1016","volume":"205","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6099-7090","authenticated-orcid":false,"given":"Zhaoyang","family":"Qu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7239-1819","authenticated-orcid":false,"given":"Mingyang","family":"Geng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunxin","family":"Mao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shanzhi","family":"Gu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chuanfu","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haotian","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109280_bib0001","unstructured":"Achiam, J., Adler, S., Agarwal, S., Ahmad, L., Akkaya, I., Aleman, F. L., Almeida, D., Altenschmidt, J., Altman, S., Anadkat, S. et al. (2023). GPT-4 technical report. arXiv preprint arXiv: 2303.08774."},{"key":"10.1016\/j.neunet.2026.109280_bib0002","unstructured":"Anthropic (2026). Anthropic API pricing. https:\/\/www.anthropic.com\/pricing. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.126357","article-title":"Collaboration between intelligent agents and large language models: A novel approach for enhancing code generation capability","volume":"269","author":"Bai","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.neunet.2026.109280_bib0004","unstructured":"Bai, Y., Kadavath, S., Kundu, S., Askell, A., Kernion, J., Jones, A., Chen, A., Goldie, A., Mirhoseini, A., McKinnon, C. et al. (2022). Constitutional AI: Harmlessness from AI feedback. arXiv preprint arXiv: 2212.08073."},{"key":"10.1016\/j.neunet.2026.109280_bib0005","series-title":"Proceedings of the 39th IEEE\/ACM International conference on automated software engineering","first-page":"995","article-title":"RMCBench: Benchmarking large language models\u2019 resistance to malicious code","author":"Chen","year":"2024"},{"key":"10.1016\/j.neunet.2026.109280_bib0006","unstructured":"Chen, M., Tworek, J., Jun, H., Yuan, Q., Oliveira, P. H. P. D., Kaplan, J., Edwards, H., Burda, Y., Joseph, N., Brockman, G. et al. (2021). Evaluating large language models trained on code. arXiv preprint arXiv: 2107.03374."},{"key":"10.1016\/j.neunet.2026.109280_bib0007","unstructured":"DeepSeek, A. I. (2025). Deepseek V3\/R1 inference system overview. https:\/\/deepwiki.com\/deepseek-ai\/open-infra-index\/3-deepseek-v3r1-inference-system. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0008","unstructured":"DeepSeek, A. I. (2026). Deepseek API pricing. https:\/\/api-docs.deepseek.com\/. Accessed 2026-06-23."},{"issue":"7","key":"10.1016\/j.neunet.2026.109280_bib0009","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3672459","article-title":"Self-collaboration code generation via chatgpt","volume":"33","author":"Dong","year":"2024","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.neunet.2026.109280_bib0010","doi-asserted-by":"crossref","unstructured":"Duan, Z., & Wang, J. (2024). Exploration of LLM multi-agent application implementation based on LangGraph+ CrewAI. arXiv preprint arXiv: 2411.18241.","DOI":"10.32388\/R27SW4"},{"key":"10.1016\/j.neunet.2026.109280_bib0011","series-title":"Proceedings of the 46th IEEE\/ACM International conference on software engineering","first-page":"1","article-title":"Large language models are few-shot summarizers: Multi-intent comment generation via in-context learning","author":"Geng","year":"2024"},{"key":"10.1016\/j.neunet.2026.109280_bib0012","series-title":"Proceedings of the 31st ACM Joint european software engineering conference and symposium on the foundations of software engineering","first-page":"2201","article-title":"LLM-based code generation method for golang compiler testing","author":"Gu","year":"2023"},{"key":"10.1016\/j.neunet.2026.109280_bib0013","unstructured":"Guo, D., Zhu, Q., Yang, D., Xie, Z., Dong, K., Zhang, W., Chen, G., Bi, X., Wu, Y., Li, Y. K. et al. (2024). Deepseek-coder: When the large language model meets programming\u2013the rise of code intelligence. arXiv preprint arXiv: 2401.14196."},{"key":"10.1016\/j.neunet.2026.109280_bib0014","unstructured":"He, J., Vero, M., Krasnopolska, G., & Vechev, M. (2024). Instruction tuning for secure code generation. arXiv preprint arXiv: 2402.09497."},{"key":"10.1016\/j.neunet.2026.109280_bib0015","unstructured":"Hong, S., Zheng, X., Chen, J., Cheng, Y., Wang, J., Zhang, C., Wang, Z., Yau, S. K. S., Lin, Z., Zhou, L. et al. (2023). MetaGPT: Meta programming for multi-agent collaborative framework. 3 (4), 6, arXiv preprint arXiv: 2308.00352."},{"key":"10.1016\/j.neunet.2026.109280_bib0016","unstructured":"Huang, D., Zhang, J. M., Luck, M., Bu, Q., Qing, Y., & Cui, H. (2023). AgentCoder: Multi-agent code generation with effective testing and self-optimization. arXiv preprint arXiv: 2312.13010."},{"key":"10.1016\/j.neunet.2026.109280_bib0017","series-title":"Milcom 2024-2024 IEEE Military communications conference (milcom)","first-page":"176","article-title":"Hierarchical multi-agent reinforcement learning for autonomous cyber defense in coalition networks","author":"H\u00fcrten","year":"2024"},{"key":"10.1016\/j.neunet.2026.109280_bib0018","unstructured":"Ishibashi, Y., & Nishimura, Y. (2024). Self-organized agents: A LLM multi-agent framework toward ultra large-scale code generation and optimization. arXiv preprint arXiv: 2404.02183."},{"key":"10.1016\/j.neunet.2026.109280_bib0019","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1016\/j.arcontrol.2022.01.004","article-title":"An overview on multi-agent consensus under adversarial attacks","volume":"53","author":"Ishii","year":"2022","journal-title":"Annual Reviews in Control"},{"key":"10.1016\/j.neunet.2026.109280_bib0020","series-title":"Findings of the North American chapter of the association for computational linguistics (NAACL)","article-title":"CODESIM: Multi-agent code generation and problem solving through simulation-driven planning and debugging","author":"Islam","year":"2025"},{"issue":"7","key":"10.1016\/j.neunet.2026.109280_bib0021","first-page":"1","article-title":"Self-planning code generation with large language models","volume":"33","author":"Jiang","year":"2024","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.neunet.2026.109280_bib0022","unstructured":"Kereopa-Yorke, B. (2025). Engineering trust, creating vulnerability: A socio-technical analysis of AI interface design. arXiv preprint arXiv: 2507.02866."},{"issue":"8","key":"10.1016\/j.neunet.2026.109280_bib0023","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3675395","article-title":"AceCoder: An effective prompting technique specialized in code generation","volume":"33","author":"Li","year":"2024","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.neunet.2026.109280_bib0024","unstructured":"Liu, Y., Deng, G., Xu, Z., Li, Y., Zheng, Y., Zhang, Y., Zhao, L., Zhang, T., Wang, K., & Liu, Y. (2023). Jailbreaking chatgpt via prompt engineering: An empirical study. arXiv preprint arXiv: 2305.13860."},{"key":"10.1016\/j.neunet.2026.109280_bib0025","doi-asserted-by":"crossref","first-page":"61065","DOI":"10.52202\/079017-1952","article-title":"Tree of attacks: Jailbreaking black-box LLMs automatically","volume":"37","author":"Mehrotra","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109280_bib0026","unstructured":"Nunez, A., Islam, N. T., Jha, S. K., & Najafirad, P. (2024). Autosafecoder: A multi-agent framework for securing LLM code generation through static analysis and fuzz testing. arXiv preprint arXiv: 2409.10737."},{"key":"10.1016\/j.neunet.2026.109280_bib0027","unstructured":"OpenAI (2023). GPT-4 technical report and model variants documentation. https:\/\/platform.openai.com\/docs\/models\/gpt-4. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0028","unstructured":"OpenAI (2026a). OpenAI API pricing. https:\/\/platform.openai.com\/pricing. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0029","unstructured":"OpenAI (2026b). OpenAI API rate limits documentation. https:\/\/platform.openai.com\/docs\/guides\/rate-limits. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0030","doi-asserted-by":"crossref","first-page":"27730","DOI":"10.52202\/068431-2011","article-title":"Training language models to follow instructions with human feedback","volume":"35","author":"Ouyang","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109280_bib0031","unstructured":"Ouyang, S., Qin, Y., Lin, B., Chen, L., Mao, X., & Wang, S. (2025). Smoke and mirrors: Jailbreaking LLM-based code generation via implicit malicious prompts. arXiv preprint arXiv: 2503.17953."},{"key":"10.1016\/j.neunet.2026.109280_bib0032","series-title":"Proceedings of the 62nd Annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"15174","article-title":"ChatDev: Communicative agents for software development","author":"Qian","year":"2024"},{"issue":"12","key":"10.1016\/j.neunet.2026.109280_bib0033","doi-asserted-by":"crossref","first-page":"324","DOI":"10.1007\/s10462-024-10973-2","article-title":"Digital deception: Generative artificial intelligence in social engineering and phishing","volume":"57","author":"Schmitt","year":"2024","journal-title":"Artificial Intelligence Review"},{"key":"10.1016\/j.neunet.2026.109280_bib0034","unstructured":"Shah, R., Pour, S., Tagade, A., Casper, S., Rando, J. et al. (2023). Scalable and transferable black-box jailbreaks for language models via persona modulation. arXiv preprint arXiv: 2311.03348."},{"key":"10.1016\/j.neunet.2026.109280_bib0035","unstructured":"N. E. Team (2026). Deepseek API pricing and rate limits overview. https:\/\/www.nxcode.io\/resources\/news\/deepseek-api-pricing-complete-guide-2026. Accessed 2026-06-23."},{"key":"10.1016\/j.neunet.2026.109280_bib0036","series-title":"Proceedings of the IEEE\/CVF International conference on computer vision","first-page":"7768","article-title":"Adversarial attacks on multi-agent communication","author":"Tu","year":"2021"},{"key":"10.1016\/j.neunet.2026.109280_bib0037","series-title":"Proceedings of the 31st ACM Joint european software engineering conference and symposium on the foundations of software engineering","first-page":"375","article-title":"Natural language to code: How far are we?","author":"Wang","year":"2023"},{"issue":"4","key":"10.1016\/j.neunet.2026.109280_bib0038","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3764113","article-title":"Unique security and privacy threats of large language models: A comprehensive survey","volume":"58","author":"Wang","year":"2025","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.neunet.2026.109280_bib0039","doi-asserted-by":"crossref","first-page":"80079","DOI":"10.52202\/075280-3508","article-title":"Jailbroken: How does LLM safety training fail?","volume":"36","author":"Wei","year":"2023","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109280_bib0040","doi-asserted-by":"crossref","unstructured":"Wei, Y., Cassano, F., Liu, J., Ding, Y., Jain, N., Mueller, Z., de Vries, H., Von Werra, L., Guha, A., & Zhang, L. (2024). Selfcodealign: Self-alignment for code generation. arXiv preprint arXiv: 2410.24198.","DOI":"10.52202\/079017-2008"},{"key":"10.1016\/j.neunet.2026.109280_bib0041","unstructured":"Wei, Z., Wang, Y., Li, A., Mo, Y., & Wang, Y. (2023b). Jailbreak and guard aligned language models with only few in-context demonstrations. arXiv preprint arXiv: 2310.06387."},{"key":"10.1016\/j.neunet.2026.109280_bib0042","series-title":"First conference on language modeling","article-title":"Autogen: Enabling next-gen LLM applications via multi-agent conversations","author":"Wu","year":"2024"},{"key":"10.1016\/j.neunet.2026.109280_bib0043","unstructured":"Yuan, Y., Jiao, W., Wang, W., Huang, J.-t., He, P., Shi, S., & Tu, Z. (2023). GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher. arXiv preprint arXiv: 2308.06463."},{"key":"10.1016\/j.neunet.2026.109280_bib0044","series-title":"Proceedings of the 2025\u202fCHI Conference on human factors in computing systems","first-page":"1","article-title":"Beyond code generation: LLM-supported exploration of the program design space","author":"Zamfirescu-Pereira","year":"2025"},{"key":"10.1016\/j.neunet.2026.109280_bib0045","series-title":"Proceedings of the 62nd Annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"14322","article-title":"How johnny can persuade LLMs to jailbreak them: Rethinking persuasion to challenge AI safety by humanizing LLMs","author":"Zeng","year":"2024"},{"key":"10.1016\/j.neunet.2026.109280_bib0046","series-title":"Proceedings of the 39th IEEE\/ACM International conference on automated software engineering","first-page":"1319","article-title":"A pair programming framework for code generation via multi-plan exploration and feedback-driven refinement","author":"Zhang","year":"2024"},{"issue":"8","key":"10.1016\/j.neunet.2026.109280_bib0047","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3547330","article-title":"Adversarial attacks and defenses in deep learning: From a perspective of cybersecurity","volume":"55","author":"Zhou","year":"2022","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.neunet.2026.109280_bib0048","doi-asserted-by":"crossref","first-page":"991","DOI":"10.1109\/TIFS.2022.3233190","article-title":"Label-only model inversion attacks: Attack with the least information","volume":"18","author":"Zhu","year":"2022","journal-title":"IEEE Transactions on Information Forensics and Security"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026007409?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026007409?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T07:53:33Z","timestamp":1783410813000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026007409"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2027,1]]},"references-count":48,"alternative-id":["S0893608026007409"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109280","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2027,1]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Collaborative-adversarial jailbreaking: A propagation-aware attack framework for multi-agent code generation systems","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109280","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109280"}}