{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T20:42:40Z","timestamp":1780778560625,"version":"3.54.1"},"reference-count":59,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T00:00:00Z","timestamp":1770940800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Artif. Intell."],"abstract":"<jats:sec>\n                    <jats:title>Introduction<\/jats:title>\n                    <jats:p>Adversarial robustness in artificial intelligence is commonly defined in terms of input-level perturbations applied to static models. This study reconceptualises adversarial vulnerability for artificial and agentic AI systems by extending the threat model to autonomy, self-governance, and closed-loop decision-making, where behaviour unfolds dynamically through feedback and control.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Methods<\/jats:title>\n                    <jats:p>We develop a system-level analytical framework that formalises adversarial risk across perceptual, cognitive, and executive layers. The analysis is grounded in a PRISMA-compliant systematic literature review, bibliometric mapping, and targeted empirical validation. Established adversarial results from vision benchmarks and recent large-language-model red-teaming studies are synthesised to contextualise the framework, rather than to introduce new benchmark performance claims.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Results<\/jats:title>\n                    <jats:p>The results demonstrate that no single defence mechanism provides robustness across all layers of agentic AI systems. Adversarial vulnerabilities propagate from perception to policy and actuation, with architectural similarity, domain shift, and feedback dynamics critically shaping transferability and failure modes. These effects have direct implications for safety-critical applications, including autonomous mobility, healthcare imaging, and biometric security.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Discussion<\/jats:title>\n                    <jats:p>By framing higher-order agentic adversarial threats as hypothesis-driven, system-level risks, this work shifts adversarial AI security from benchmark-centric evaluation to behavioural integrity and lifecycle resilience. The proposed framework defines a coherent research agenda for agentic AI security that integrates control-theoretic reasoning and governance-aware defence design, addressing limitations of classical adversarial machine-learning theory.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.3389\/frai.2026.1731566","type":"journal-article","created":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T12:29:01Z","timestamp":1770985741000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Threats and vulnerabilities in artificial intelligence and agentic AI models"],"prefix":"10.3389","volume":"9","author":[{"given":"Petar","family":"Radanliev","sequence":"first","affiliation":[{"name":"Department of Computer Sciences, University of Oxford","place":["Oxford, United Kingdom"]},{"name":"The Alan Turing Institute, British Library","place":["London, United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Omar","family":"Santos","sequence":"additional","affiliation":[{"name":"Cisco Systems, RTP","place":["Morrisville, NC, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carsten","family":"Maple","sequence":"additional","affiliation":[{"name":"The Alan Turing Institute, British Library","place":["London, United Kingdom"]},{"name":"University of Warwick \u2013 WMG","place":["Coventry, United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2026,2,13]]},"reference":[{"key":"ref1","doi-asserted-by":"crossref","first-page":"18912","DOI":"10.1109\/ACCESS.2025.3532853","article-title":"Agentic AI: autonomous intelligence for complex goals - a comprehensive survey","volume":"3","author":"Acharya","year":"2025","journal-title":"IEEE Access"},{"key":"ref2","first-page":"1","article-title":"Adversarial attacks on machine learning cybersecurity defences in industrial control systems","volume":"58","author":"Anthi","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref3","doi-asserted-by":"crossref","first-page":"959","DOI":"10.1016\/j.joi.2017.08.007","article-title":"Bibliometrix: an R-tool for comprehensive science mapping analysis","volume":"11","author":"Aria","year":"2017","journal-title":"J. Informet."},{"key":"ref4","doi-asserted-by":"crossref","first-page":"46","DOI":"10.55662\/JST.2023.4502","article-title":"Intrinsically motivated multi-goal reinforcement learning using robotics environment integrated with OpenAI gym","volume":"4","author":"Balasubramanian","year":"2023","journal-title":"Journal of Science &amp; Technology"},{"key":"ref5","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1016\/j.techfore.2017.08.011","article-title":"Technology roadmapping: a methodological proposition to refine Delphi results","volume":"126","author":"Bloem da Silveira Junior","year":"2018","journal-title":"Technological Forecasting and Social Change"},{"key":"ref6","article-title":"Chainlink 2.0: next steps in the evolution of decentralized Oracle networks","author":"Breidenbach","year":"2021"},{"key":"ref7","first-page":"3","article-title":"Adversarial examples are not easily detected: bypassing ten detection methods","volume-title":"AISec 2017 - proceedings of the 10th ACM workshop on artificial intelligence and security, co-located with CCS 2017","author":"Carlini","year":""},{"key":"ref8","article-title":"MagNet and \u2018efficient Defenses against adversarial attacks\u2019 are not robust to adversarial examples","author":"Carlini","year":""},{"key":"ref9","volume-title":"California consumer privacy act (CCPA) | state of California - Department of Justice - Office of the Attorney General","year":"2018"},{"key":"ref10","first-page":"18","article-title":"Vulnerability analysis in attack graphs using conditional probability","volume":"13","author":"Chejara","year":"2013","journal-title":"International Journal of Soft Computing and Engineering (IJSCE)"},{"key":"ref11","volume-title":"TRUST-VLM: Thorough red-teaming for uncovering safety threats in vision-language models","author":"Chen","year":"2025"},{"key":"ref12","volume-title":"Undefined, n.d. Stateful detection of black-box adversarial attacks. dl.acm.org","author":"Chen","year":""},{"key":"ref13","first-page":"30","article-title":"Stateful detection of black-box adversarial attacks","volume-title":"SPAI 2020 - proceedings of the 1st ACM workshop on security and privacy on artificial intelligent, co-located with AsiaCCS 2020","author":"Chen","year":""},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.21314\/JOP.2019.228","volume-title":"An investigation of cyber loss data and its links to operational risk.","author":"Cohen","year":"2019"},{"key":"ref15","first-page":"61113","article-title":"How deep learning sees the world: a survey on adversarial attacks & Defenses","volume":"12","author":"Costa","year":"2023","journal-title":"ARXIV"},{"key":"ref16","doi-asserted-by":"crossref","first-page":"6584","DOI":"10.1109\/TNNLS.2021.3082568","article-title":"Distributional soft actor-critic: off-policy reinforcement learning for addressing value estimation errors","volume":"33","author":"Duan","year":"2022","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"ref17","first-page":"1322","article-title":"Model inversion attacks that exploit confidence information and basic countermeasures","volume-title":"Proceedings of the ACM conference on computer and communications security","author":"Fredrikson","year":"2015"},{"key":"ref18","article-title":"What is GDPR, the EU\u2019S new data protection law? - GDPR.EU","year":"2018"},{"key":"ref19","article-title":"Cleverhans v0.1: an adversarial machine learning library","author":"Goodfellow","year":"2016"},{"key":"ref20","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1145\/3422622","article-title":"Generative adversarial networks","volume":"63","author":"Goodfellow","year":"2014","journal-title":"Communications of the ACM"},{"key":"ref21","doi-asserted-by":"crossref","DOI":"10.1145\/3593042","article-title":"A survey of adversarial Defenses and robustness in NLP","volume":"55","author":"Goyal","year":"2023","journal-title":"ACM Computing Surveys"},{"key":"ref22","article-title":"Meta-reinforcement learning of structured exploration strategies","volume":"31","author":"Gupta","year":"2018","journal-title":"Adv. Neural Inf. Proces. Syst."},{"key":"ref23","article-title":"Soft actor-critic: off-policy maximum entropy deep reinforcement learning with a stochastic actor","author":"Haarnoja","year":"2018"},{"key":"ref24","volume-title":"Information commissioner\u2019s office (ICO): The UK GDPR","year":"2018"},{"key":"ref25","first-page":"28362","article-title":"Parametrized quantum policies for reinforcement learning","volume":"34","author":"Jerbi","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"102266","DOI":"10.1109\/ACCESS.2022.3208131","article-title":"Adversarial deep learning: a survey on adversarial attacks and Defense mechanisms on image classification","volume":"10","author":"Khamaiseh","year":"2022","journal-title":"IEEE Access"},{"key":"ref27","first-page":"2456","article-title":"End-to-end reinforcement learning for autonomous longitudinal control using advantage actor critic with temporal context","volume-title":"2019 IEEE intelligent transportation systems conference, ITSC 2019","author":"Kuutti","year":"2019"},{"key":"ref28","doi-asserted-by":"crossref","first-page":"793","DOI":"10.1016\/j.ifacol.2021.08.093","article-title":"Modeling production scheduling problems as reinforcement learning environments based on discrete-event simulation and OpenAI gym","volume":"54","author":"Lang","year":"2021","journal-title":"IFAC-PapersOnLine"},{"key":"ref29","volume-title":"Deep reinforcement learning hands-on: Apply modern RL methods, with deep Q-networks, value iteration, policy gradients, TRPO, AlphaGo zero and more","author":"Lapan","year":"2018"},{"key":"ref30","first-page":"1283","article-title":"Adversarial attack and Defense: a survey","volume":"11","author":"Liang","year":"2022","journal-title":"Electronics 2022, Vol. 11, Page 1283"},{"key":"ref31","doi-asserted-by":"crossref","first-page":"122223","DOI":"10.1016\/j.eswa.2023.122223","article-title":"Adversarial examples: a survey of attacks and defenses in deep learning-enabled cybersecurity systems","volume":"238","author":"Macas","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref32","doi-asserted-by":"crossref","first-page":"5101","DOI":"10.3390\/app9235101","article-title":"A connected and autonomous vehicle reference architecture for attack surface analysis","volume":"9","author":"Maple","year":"2019","journal-title":"Applied Sciences"},{"key":"ref33","article-title":"Lifelong inverse reinforcement learning","volume":"31","author":"Mendez","year":"2018","journal-title":"Adv. Neural Inf. Proces. Syst."},{"key":"ref34","first-page":"86","article-title":"Universal adversarial perturbations","author":"Moosavi-Dezfooli","year":"","journal-title":"Proceedings - 30th IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017"},{"key":"ref35","first-page":"2574","article-title":"DeepFool: a simple and accurate method to fool deep neural networks","volume-title":"2016 IEEE conference on computer vision and pattern recognition (CVPR)","author":"Moosavi-Dezfooli","year":""},{"key":"ref36","first-page":"2574","article-title":"DeepFool: a simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2015","journal-title":"Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition"},{"key":"ref37","doi-asserted-by":"crossref","DOI":"10.1109\/IBSSC47189.2019.8973068","article-title":"Performance analysis of deep Q networks and advantage actor critic algorithms in designing reinforcement learning-based self-tuning PID controllers","volume-title":"2019 IEEE Bombay section signature conference, IBSSC 2019","author":"Mukhopadhyay","year":"2019"},{"key":"ref38","article-title":"Tight auditing of differentially private machine learning","volume-title":"online","author":"Nasr","year":"2023"},{"key":"ref39","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.procs.2018.10.315","article-title":"Adversarial attacks and Defenses against deep neural networks: a survey","volume":"140","author":"Ozdag","year":"2018","journal-title":"Procedia Computer Science"},{"key":"ref40","article-title":"Technical report on the CleverHans v2.1.0 adversarial examples library","author":"Papernot","year":"2016"},{"key":"ref41","article-title":"Red teaming the mind of the machine: a systematic evaluation of prompt injection and jailbreak vulnerabilities in LLMs","author":"Pathade","year":"2025"},{"key":"ref42","first-page":"697","article-title":"Disruptive and avoidable: GDPR challenges to secondary research uses of data","volume":"28","author":"Peloquin","year":"2020","journal-title":"European Journal of Human Genetics 2020 28:6"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.eng.2019.12.012","article-title":"Adversarial attacks and Defenses in deep learning","volume":"6","author":"Ren","year":"2020","journal-title":"Engineering"},{"key":"ref44","first-page":"102470","article-title":"Attacking the trust machine: developing an information systems research agenda for blockchain cybersecurity","volume":"68","author":"Schlatt","year":"2023","journal-title":"Int. J. Inf. Manag."},{"key":"ref45","article-title":"MAD-MAX: modular and diverse malicious attack MiXtures for automated LLM red teaming","author":"Schoepf","year":"2025"},{"key":"ref46","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1007\/978-981-13-8285-7_11","article-title":"Actor-critic models and the A3C","author":"Sewak","year":"2019","journal-title":"Deep Reinforcement Learning"},{"key":"ref47","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11128-020-02657-x","article-title":"Demonstration of a measurement-based adaptation protocol with quantum reinforcement learning on the IBM Q experience platform","volume":"19","author":"Shenoy","year":"2020","journal-title":"Quantum Information Processing"},{"key":"ref48","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri","year":"2017","journal-title":"Proceedings - IEEE Symposium on Security and Privacy"},{"key":"ref49","first-page":"10","article-title":"Reinforcement learning: an introduction MIT press","volume":"22447","author":"Sutton","year":"1998","journal-title":"Cambridge, MA"},{"key":"ref50","first-page":"1","article-title":"Going deeper with convolutions","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","author":"Szegedy","year":"2015"},{"key":"ref51","article-title":"Intriguing properties of neural networks","volume-title":"2nd international conference on learning representations, ICLR 2014 - conference track proceedings","author":"Szegedy","year":"2013"},{"key":"ref52","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1109\/MCOM.2019.1800971","article-title":"Computation offloading in multi-Access edge computing using a deep sequential model based on reinforcement learning","volume":"57","author":"Wang","year":"2019","journal-title":"IEEE Commun. Mag."},{"key":"ref53","doi-asserted-by":"crossref","first-page":"2766","DOI":"10.1111\/risa.13382","article-title":"Adversarial Risk analysis to allocate optimal Defense resources for protecting cyber\u2013physical systems from cyber attacks","volume":"39","author":"Wang","year":"2019","journal-title":"Risk Analysis"},{"key":"ref54","volume-title":"A methodology for formalizing model-inversion attacks","author":"Wu","year":"2024"},{"key":"ref55","doi-asserted-by":"crossref","first-page":"10639","DOI":"10.1609\/aaai.v35i12.17272","article-title":"WCSAC: worst-case soft actor critic for safety-constrained reinforcement learning","volume":"35","author":"Yang","year":"2021","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"ref56","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1007\/s10796-006-8731-y","article-title":"An attack-norm separation approach for detecting cyber attacks","volume":"8","author":"Ye","year":"2006","journal-title":"Information Systems Frontiers"},{"key":"ref57","article-title":"Meta-world: a benchmark and evaluation for multi-task and Meta reinforcement learning","author":"Yu","year":"2020"},{"key":"ref58","doi-asserted-by":"crossref","first-page":"407","DOI":"10.1016\/j.patcog.2017.07.031","article-title":"Scalable lifelong reinforcement learning","volume":"72","author":"Zhan","year":"2017","journal-title":"Pattern Recogn."},{"key":"ref59","article-title":"MetaCURE: Meta reinforcement learning with empowerment-driven exploration","author":"Zhang","year":"2021"}],"container-title":["Frontiers in Artificial Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/frai.2026.1731566\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T10:30:50Z","timestamp":1771929050000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/frai.2026.1731566\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,13]]},"references-count":59,"alternative-id":["10.3389\/frai.2026.1731566"],"URL":"https:\/\/doi.org\/10.3389\/frai.2026.1731566","relation":{},"ISSN":["2624-8212"],"issn-type":[{"value":"2624-8212","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,13]]},"article-number":"1731566"}}