{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T21:03:54Z","timestamp":1776978234166,"version":"3.51.4"},"reference-count":87,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62322103"],"award-info":[{"award-number":["62322103"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Sci. Eng."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tnse.2026.3680460","type":"journal-article","created":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T19:54:50Z","timestamp":1775246090000},"page":"8481-8498","source":"Crossref","is-referenced-by-count":0,"title":["Topology Linearization for Multi-Agent Systems Security: Mitigating Malicious Propagation via Path Decomposition"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-0162-9168","authenticated-orcid":false,"given":"Yan","family":"Liu","sequence":"first","affiliation":[{"name":"State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3945-0706","authenticated-orcid":false,"given":"Sujie","family":"Shao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2033-8431","authenticated-orcid":false,"given":"Shaoyong","family":"Guo","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6527-2897","authenticated-orcid":false,"given":"Chenyu","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China"}]},{"given":"Chao","family":"Yang","sequence":"additional","affiliation":[{"name":"State Grid Liaoning Electric Power Company, Ltd. Information and Communication Branch, Shenyang, China"}]},{"given":"Zhibin","family":"Zang","sequence":"additional","affiliation":[{"name":"State Grid Information and Telecommunication Industry Group Company Ltd., Beijing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3716628"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3769676"},{"key":"ref3","article-title":"LLM multi-agent systems: Challenges and open problems","author":"Han","year":"2025"},{"key":"ref4","article-title":"A comprehensive survey in LLM(-agent) full stack safety: Data, training and deployment","author":"Wang","year":"2025"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1162\/coli_a_00549"},{"issue":"0501","key":"ref6","article-title":"A review on agent-to-agent protocol: Concept, state-of-the-art, challenges and future directions","volume":"2025","author":"Ray","year":"2025","journal-title":"TechRxiv"},{"key":"ref7","article-title":"A survey of LLM-driven AI agent communication: Protocols, security risks, and defense countermeasures","author":"Kong","year":"2025"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/access.2024.3409051"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3711896.3736561"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3764113"},{"key":"ref11","article-title":"SWE-agent: Agent-computer interfaces enable automated software engineering","author":"Yang","year":"2024"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1220"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3009221"},{"key":"ref14","first-page":"1","article-title":"Improving end-to-end key security in trusted node-based QKD networks with secret sharing","volume-title":"Proc. Opt. Fiber Commun. Conf. Exhib.","author":"Wenning","year":"2025"},{"key":"ref15","article-title":"Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents","author":"Zhang","year":"2024"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3713082.3730378"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i26.34970"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2021.1003820"},{"key":"ref19","article-title":"RedTeamLLM: An agentic AI framework for offensive security","author":"Challita","year":"2025"},{"key":"ref20","article-title":"Hiding in the AI traffic: Abusing MCP for LLM-powered agentic red teaming","author":"Janjusevic","year":"2025"},{"key":"ref21","doi-asserted-by":"crossref","DOI":"10.21203\/rs.3.rs-6372131\/v1","article-title":"Guardians of the agentic system: Preventing many shots jailbreak with agentic system","author":"Barua","year":"2025"},{"key":"ref22","article-title":"A survey on the safety and security threats of computer-using agents: JARVIS or Ultron?","author":"Chen","year":"2025"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.aiopen.2026.02.006"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.icte.2025.12.001"},{"key":"ref25","article-title":"Agentic AI security: Threats, defenses, evaluation, and open challenges","author":"Datta","year":"2025"},{"key":"ref26","article-title":"Open challenges in multi-agent security: Towards secure systems of interacting AI agents","author":"Witt","year":"2025"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.12688\/f1000research.169927.1"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2026.123231"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.3390\/jcp5040095"},{"key":"ref30","article-title":"Improving Google A2A protocol: Protecting sensitive data and mitigating unintended harms in multi-agent systems","author":"Louck","year":"2025"},{"key":"ref31","article-title":"Building a secure agentic AI application leveraging A2A protocol","author":"Habler","year":"2025"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ACAI68217.2025.11406310"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2636"},{"key":"ref34","doi-asserted-by":"crossref","DOI":"10.21203\/rs.3.rs-5292520\/v1","article-title":"Flooding spread of manipulated knowledge in LLM-based multi-agent communities","author":"Ju","year":"2024"},{"key":"ref35","article-title":"Watch out for your agents! Investigating backdoor threats to LLM-based agents","author":"Yang"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.812"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2336"},{"key":"ref38","article-title":"AI agents with formal security guarantees","volume-title":"Proc. Next Gener. AI Saf. Workshop","author":"Balunovi","year":"2024"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30120"},{"key":"ref40","article-title":"LLM agents should employ security principles","author":"Zhang","year":"2025"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.acl-long.359"},{"key":"ref42","article-title":"GuardAgent: Safeguard LLM agents by a guard agent via knowledge-enabled reasoning","author":"Xiang","year":"2025"},{"key":"ref43","article-title":"AutoDefense: Multi-agent LLM defense against jailbreak attacks","author":"Zeng","year":"2024"},{"key":"ref44","article-title":"NetSafe: Exploring the topological safety of multi-agent networks","author":"Yu","year":"2024"},{"key":"ref45","article-title":"A multi-agent LLM defense pipeline against prompt injection attacks","author":"Hossain","year":"2025"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/tccn.2025.3528892"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/lnet.2024.3503292"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/jiot.2024.3366906"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/access.2024.3505298"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2025.3597319"},{"key":"ref51","article-title":"ATAG: AI-agent application threat assessment with attack graphs","author":"Gandhi","year":"2025"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/imcom69009.2026.11360855"},{"key":"ref53","article-title":"Why do multi-agent LLM systems fail?","author":"Cemri","year":"2025"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-demos.44"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3773080"},{"key":"ref56","article-title":"The trust paradox in LLM-based multi-agent systems: When collaboration becomes a security vulnerability","author":"Xu","year":"2025"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.349"},{"key":"ref58","article-title":"Comprehensive vulnerability analysis is necessary for trustworthy LLM-MAS","author":"He","year":"2025"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.20517\/ces.2025.34"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-025-00360-4"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.2985990"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/jiot.2025.3525779"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/tcss.2023.3325263"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/tcss.2019.2912801"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/2716260"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ojcoms.2023.3310528"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.3390\/electronics14183663"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/tsg.2020.2970755"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/icton62926.2024.10647999"},{"key":"ref70","article-title":"Internet of agents: Weaving a web of heterogeneous agents for collaborative intelligence","author":"Chen","year":"2024"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/jsac.2025.3560042"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/tsg.2025.3641983"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2025.3590765"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2026.3658200"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/mnet.2026.3660124"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2026.3672778"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2026.3668346"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/mwc.2025.3615555"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/tccn.2025.3631051"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/mcom.001.2500124"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.624"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-88717-8_18"},{"key":"ref83","article-title":"Measuring massive multitask language understanding","author":"Hendrycks","year":"2021"},{"key":"ref84","article-title":"Training verifiers to solve math word problems","author":"Cobbe","year":"2021"},{"key":"ref85","article-title":"Measuring mathematical problem solving with the MATH dataset","author":"Hendrycks","year":"2021"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/n16-1098"},{"key":"ref87","article-title":"The GPT-WritingPrompts dataset: A comparative analysis of character portrayal in short stories","author":"Huang","year":"2024"}],"container-title":["IEEE Transactions on Network Science and Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6488902\/11264281\/11474672.pdf?arnumber=11474672","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:59:54Z","timestamp":1776974394000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11474672\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":87,"URL":"https:\/\/doi.org\/10.1109\/tnse.2026.3680460","relation":{},"ISSN":["2327-4697","2334-329X"],"issn-type":[{"value":"2327-4697","type":"electronic"},{"value":"2334-329X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}