{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T06:46:51Z","timestamp":1775630811236,"version":"3.50.1"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T00:00:00Z","timestamp":1764720000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T00:00:00Z","timestamp":1764720000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,3]]},"DOI":"10.1109\/icmla66185.2025.00174","type":"proceedings-article","created":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T19:54:58Z","timestamp":1775591698000},"page":"1131-1136","source":"Crossref","is-referenced-by-count":0,"title":["Analyzing Code Injection Attacks on LLM-based Multi-Agent Systems in Software Development"],"prefix":"10.1109","author":[{"given":"Brian","family":"Bowers","sequence":"first","affiliation":[{"name":"Loyola Marymount University,Department of Computer Science,Los Angeles,USA"}]},{"given":"Smita","family":"Khapre","sequence":"additional","affiliation":[{"name":"University of Colorado Colorado Springs,Department of Computer Science,Colorado Springs,USA"}]},{"given":"Jugal","family":"Kalita","sequence":"additional","affiliation":[{"name":"University of Colorado Colorado Springs,Department of Computer Science,Colorado Springs,USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ieeestd.2008.4475826"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JAC-ECC64419.2024.11061204"},{"key":"ref3","article-title":"Evaluating large language models trained on code","author":"Chen","year":"2021"},{"key":"ref4","volume-title":"Top strategic technology trends for 2025: Agentic AI","author":"Coshow","year":"2024"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3672459"},{"key":"ref6","volume-title":"Python obfuscator","year":"2025"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.349"},{"key":"ref8","article-title":"MetaGPT: Meta programming for a multi-agent collaborative framework","volume-title":"International Conference on Learning Representations, ICLR","author":"Hong"},{"key":"ref9","article-title":"Agentcoder: Multi-agent-based code generation with iterative testing and optimisation","author":"Huang","year":"2023"},{"key":"ref10","article-title":"On the resilience of LLM-based multi-agent collaboration with faulty agents","author":"Huang","year":"2024"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.269"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3747588"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/WCSN.2007.4475760"},{"key":"ref14","volume-title":"Mitre atlas matrix","year":"2025"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2025.3544940"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACAI68217.2025.11406310"},{"key":"ref17","volume-title":"Openai agents SDK","year":"2025"},{"key":"ref18","volume-title":"2025 top 10 risk & mitigations for LLMs and GenAI apps","year":"2025"},{"key":"ref19","article-title":"Code Llama: Open Foundation Models for Code","author":"Roziere","year":"2023"},{"key":"ref20","article-title":"From code to correctness: Closing the last mile of code generation with hierarchical debugging","author":"Shi","year":"2024"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.119"},{"key":"ref22","article-title":"Multi-agent systems execute arbitrary malicious code","author":"Triedman","year":"2025"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/MedAI59581.2023.00044"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-024-40231-1"},{"key":"ref25","article-title":"Autogen: Enabling next-gen LLM applications via multi-agent conversation","author":"Wu","year":"2023"},{"key":"ref26","article-title":"Guardian: Safeguarding LLM multi-agent collaborations with temporal graph modeling","author":"Zhou","year":"2025"}],"event":{"name":"2025 International Conference on Machine Learning and Applications (ICMLA)","location":"Boca Raton, FL, USA","start":{"date-parts":[[2025,12,3]]},"end":{"date-parts":[[2025,12,5]]}},"container-title":["2025 International Conference on Machine Learning and Applications (ICMLA)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11471302\/11471304\/11471391.pdf?arnumber=11471391","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T05:47:38Z","timestamp":1775627258000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11471391\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,3]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/icmla66185.2025.00174","relation":{},"subject":[],"published":{"date-parts":[[2025,12,3]]}}}