diff --git a/artifact/README.md b/artifact/README.md new file mode 100644 index 0000000..89da13f --- /dev/null +++ b/artifact/README.md @@ -0,0 +1,202 @@ +# Source Links for the 189-Work MAS-Security Corpus + +This directory is the source-access layer for the USENIX artifact. It lists every active corpus work with at least one stable, clickable locator. Third-party PDFs are not redistributed here; the links point to DOI, arXiv, or the recorded primary source. + +Active corpus: **92 Set 1 + 97 Set 2 = 189 works**. + +Source-link priority is **DOI → arXiv → recorded primary URL** so that durable scholarly identifiers are preferred over aggregator pages. Corpus membership and taxonomy remain authoritative in `../corpus/set1_core.csv` and `../corpus/set2_emerging.csv`. + +## Set 1: mature MAS-security works (92) + +1. [Cooperation, Competition, and Maliciousness: LLM-Stakeholders Interactive Negotiation](https://doi.org/10.52202/079017-2658) — **evaluation** · NeurIPS 2024 · 2023 · DOI · `supp_cooperation_competition_and_maliciousness_llm_stakeholders_interactive_negotiati` +2. [A Troublemaker with Contagious Jailbreak Makes Chaos in Honest Towns](https://doi.org/10.18653/v1/2025.acl-long.859) — **attack** · ACL · 2024 · DOI · `men2025troublemaker` +3. [Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast](https://arxiv.org/abs/2402.08567) — **attack** · ICML · 2024 · arXiv · `gu2024agent_smith` +4. [BlockAgents: Towards Byzantine-Robust LLM-Based Multi-Agent Coordination via Blockchain](https://doi.org/10.1145/3674399.3674445) — **defense** · ACM Turing Celebration Conference · 2024 · DOI · `doi:10.1145/3674399.3674445` +5. [CRDA: Content Risk Drift Assessment of Large Language Models through Adversarial Multi-Agent Interaction](https://doi.org/10.1109/ijcnn60899.2024.10650172) — **evaluation** · IEEE International Joint Conference on Neural Network · 2024 · DOI · `doi:10.1109/ijcnn60899.2024.10650172` +6. [Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems](https://arxiv.org/abs/2410.02506) — **general** · International Conference on Learning Representations · 2024 · arXiv · `arxiv:2410.02506` +7. [Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities](https://doi.org/10.1007/s11432-024-4663-2) — **attack** · Science China Information Sciences · 2024 · DOI · `ju2026flooding` +8. [G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks](https://arxiv.org/abs/2410.11782) — **general** · International Conference on Machine Learning · 2024 · arXiv · `arxiv:2410.11782` +9. [NetSafe: Exploring the Topological Safety of Multi-agent System](https://doi.org/10.18653/v1/2025.findings-acl.150) — **evaluation** · Findings of ACL · 2024 · DOI · `yu2025netsafe` +10. [Prompt Infection: LLM-to-LLM Prompt Injection within Multi-agent Systems](https://doi.org/10.1007/978-3-032-16092-8_28) — **attack** · ESORICS 2025 International Workshops · 2024 · DOI · `lee2026prompt_infection` +11. [Secret Collusion among AI Agents: Multi-Agent Deception via Steganography](https://doi.org/10.52202/079017-2336) — **attack** · NeurIPS · 2024 · DOI · `motwani2024secret_collusion` +12. [The Wolf Within: Covert Injection of Malice into MLLM Societies via an MLLM Operative](https://arxiv.org/abs/2402.14859) — **attack** · arXiv · 2024 · arXiv · `tan2024wolf_within` +13. [Agents Under Siege: Breaking Pragmatic Multi-Agent LLM Systems with Optimized Prompt Attacks](https://doi.org/10.18653/v1/2025.acl-long.476) — **attack** · ACL · 2025 · DOI · `khan2025agents_under_siege` +14. [AI Agents with Decentralized Identifiers and Verifiable Credentials](https://doi.org/10.5220/0014234400004052) — **defense** · ICAART 2026 · 2025 · DOI · `supp_ai_agents_with_decentralized_identifiers_and_verifiable_credentials` +15. [ATAG: AI-Agent Application Threat Assessment with Attack Graphs](https://doi.org/10.1145/3779208.3785380) — **evaluation** · ACM AsiaCCS 2026 · 2025 · DOI · `supp_atag_ai_agent_application_threat_assessment_with_attack_graphs` +16. [Attack the Messages, Not the Agents: A Multi-round Adaptive Stealthy Tampering Framework for LLM-MAS](https://doi.org/10.1609/aaai.v40i35.40224) — **attack** · AAAI · 2025 · DOI · `yan2026mast` +17. [Benchmarking the Robustness of Agentic Systems to Adversarially-Induced Harmful Behaviors](https://arxiv.org/abs/2508.16481) — **evaluation** · COLM · 2025 · arXiv · `nother2026badacts` +18. [BlindGuard: Safeguarding LLM-based Multi-Agent Systems under Unknown Attacks](https://doi.org/10.18653/v1/2026.acl-long.1819) — **defense** · ACL · 2025 · DOI · `miao2026blindguard` +19. [BlockA2A: Towards Secure and Verifiable Agent-to-Agent Interoperability](https://arxiv.org/abs/2508.01332) — **defense** · arXiv · 2025 · arXiv · `zou2025blocka2a` +20. [Breaking and Fixing Defenses Against Control-Flow Hijacking in Multi-Agent Systems](https://arxiv.org/abs/2510.17276) — **defense** · ICLR · 2025 · arXiv · `jha2026control_flow_hijacking` +21. [Can an Individual Manipulate the Collective Decisions of Multi-Agents?](https://doi.org/10.18653/v1/2025.emnlp-main.611) — **attack** · EMNLP · 2025 · DOI · `liu2025collective_manipulation` +22. [CoMet: Metaphor-Driven Covert Communication for Multi-Agent Language Games](https://doi.org/10.18653/v1/2025.acl-long.389) — **attack** · ACL 2025 · 2025 · DOI · `supp_comet_metaphor_driven_covert_communication_for_multi_agent_language_games` +23. [CORBA: Contagious Recursive Blocking Attacks on Multi-Agent Systems Based on Large Language Models](https://doi.org/10.18653/v1/2026.findings-acl.342) — **attack** · Findings of ACL · 2025 · DOI · `zhou2026corba` +24. [Cross-Agent Multimodal Provenance-Aware Framework for Robust Prompt Injection Defense in Large Language and Vision-Language Models](https://doi.org/10.1109/icca66035.2025.11430791) — **defense** · International Conferences on Computing Advancements · 2025 · DOI · `doi:10.1109/icca66035.2025.11430791` +25. [Decentralized Multi-Agent System with Trust-Aware Communication](https://doi.org/10.1109/ispa67752.2025.00198) — **defense** · IEEE ISPA 2025 · 2025 · DOI · `supp_decentralized_multi_agent_system_with_trust_aware_communication` +26. [Enhancing Robustness of LLM-Driven Multi-Agent Systems through Randomized Smoothing](https://doi.org/10.1016/j.cja.2025.103779) — **defense** · Chinese Journal of Aeronautics · 2025 · DOI · `supp_enhancing_robustness_of_llm_driven_multi_agent_systems_through_randomized_smooth` +27. [Explainable and Fine-Grained Safeguarding of LLM Multi-Agent Systems via Bi-Level Graph Anomaly Detection](https://doi.org/10.18653/v1/2026.acl-long.1407) — **defense** · ACL · 2025 · DOI · `pan2026xgguard` +28. [Free-MAD: Consensus-Free Multi-Agent Debate](https://doi.org/10.18653/v1/2026.findings-acl.1600) — **general** · FINDINGS ACL · 2025 · DOI · `arxiv:2509.11035` +29. [G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems](https://doi.org/10.18653/v1/2025.acl-long.359) — **defense** · ACL · 2025 · DOI · `wang2025gsafeguard` +30. [GUARDIAN: Safeguarding LLM Multi-Agent Collaborations with Temporal Graph Modeling](https://arxiv.org/abs/2505.19234) — **defense** · NeurIPS · 2025 · arXiv · `zhou2025guardian` +31. [Hidden in Plain Text: Emergence and Mitigation of Steganographic Collusion in LLMs](https://doi.org/10.18653/v1/2025.ijcnlp-long.34) — **evaluation** · IJCNLP-AACL · 2025 · DOI · `mathew2025hidden` +32. [MAGPIE: A Benchmark for Multi-Agent Contextual Privacy Evaluation](https://arxiv.org/abs/2506.20737) — **evaluation** · NeurIPS Responsible Foundation Models Workshop · 2025 · arXiv · `juneja2025magpie` +33. [Multi-Agent Systems Execute Arbitrary Malicious Code](https://arxiv.org/abs/2503.12188) — **attack** · COLM · 2025 · arXiv · `triedman2025malicious_code` +34. [PEAR: Planner-Executor Agent Robustness Benchmark](https://doi.org/10.18653/v1/2026.findings-eacl.237) — **evaluation** · Findings of EACL · 2025 · DOI · `dong2026pear` +35. [PeerGuard: Defending Multi-Agent Systems Against Backdoor Attacks Through Mutual Reasoning](https://doi.org/10.1109/iri66576.2025.00051) — **defense** · IEEE IRI 2025 · 2025 · DOI · `supp_peerguard_defending_multi_agent_systems_against_backdoor_attacks_through_mutual_` +36. [Quantifying Privacy Leakage in Multi-Agent LLMs: A Unified Theoretical and Empirical Analysis](https://doi.org/10.1109/bigdata66926.2025.11401523) — **evaluation** · BigData Congress [Services Society] · 2025 · DOI · `doi:10.1109/bigdata66926.2025.11401523` +37. [Red-Teaming LLM Multi-Agent Systems via Communication Attacks](https://doi.org/10.18653/v1/2025.findings-acl.349) — **attack** · Findings of ACL · 2025 · DOI · `he2025communication_attacks` +38. [Rethinking the Reliability of Multi-agent System: A Perspective from Byzantine Fault Tolerance](https://doi.org/10.1609/aaai.v40i41.40806) — **defense** · AAAI · 2025 · DOI · `zheng2026byzantine_reliability` +39. [SAFEFLOW: A Principled Protocol for Trustworthy and Transactional Autonomous Agent Systems](https://arxiv.org/abs/2506.07564) — **defense** · arXiv · 2025 · arXiv · `arxiv_2506_07564` +40. [SafeSieve: From Heuristics to Experience in Progressive Pruning for LLM-based Multi-Agent Communication](https://doi.org/10.1609/aaai.v40i35.40236) — **defense** · AAAI 2026 · 2025 · DOI · `supp_safesieve_from_heuristics_to_experience_in_progressive_pruning_for_llm_based_mul` +41. [SecureGov-Agent: A Governance-Centric Multi-Agent Framework for Privacy-Preserving and Attack-Resilient LLM Agents](https://doi.org/10.1145/3795154.3795296) — **defense** · Proceedings of the 2025 6th International Conference on Computer Science and Management Technology · 2025 · DOI · `arxiv:5154.37952` +42. [Security and Privacy in Multi-Agent LLM Networks](https://doi.org/10.4018/979-8-3373-1419-8.ch009) — **defense** · Advances in computational intelligence and robotics book series · 2025 · DOI · `doi:10.4018/979-8-3373-1419-8.ch009` +43. [Security of LLM Agents: A Case Study Approach](https://doi.org/10.1109/trustcom66490.2025.00226) — **evaluation** · International Conference on Trust, Security and Privacy in Computing and Communications · 2025 · DOI · `doi:10.1109/trustcom66490.2025.00226` +44. [Sentinel Agents for Secure and Trustworthy Agentic AI in Multi-Agent Systems](https://arxiv.org/abs/2509.14956) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2509.14956` +45. [SentinelAgent: Graph-based Anomaly Detection in Multi-Agent Systems](https://arxiv.org/abs/2505.24201) — **defense** · arXiv · 2025 · arXiv · `arxiv_2505_24201` +46. [Seven Security Challenges in Cross-Domain Multi-Agent LLM Systems](https://doi.org/10.1038/s44387-026-00128-9) — **survey** · npj Artificial Intelligence · 2025 · DOI · `ko2026sevenchallenges` +47. [Shadows in the Code: Exploring the Risks and Defenses of LLM-based Multi-Agent Software Development Systems](https://doi.org/10.1609/aaai.v40i44.41134) — **attack** · AAAI · 2025 · DOI · `wang2026shadows_code` +48. [SPIFFE-Based Zero-Trust Authentication for AI Agent Ecosystems](https://doi.org/10.1109/icca66035.2025.11431026) — **defense** · International Conferences on Computing Advancements · 2025 · DOI · `doi:10.1109/icca66035.2025.11431026` +49. [TAMAS: Benchmarking Adversarial Risks in Multi-Agent LLM Systems](https://doi.org/10.18653/v1/2026.acl-long.1442) — **evaluation** · ACL · 2025 · DOI · `kavathekar2026tamas` +50. [The Subtle Art of Defection: Understanding Uncooperative Behaviors in LLM based Multi-Agent Systems](https://doi.org/10.18653/v1/2026.eacl-industry.44) — **evaluation** · EACL 2026 Industry Track · 2025 · DOI · `supp_the_subtle_art_of_defection_understanding_uncooperative_behaviors_in_llm_based_m` +51. [The Sum Leaks More Than Its Parts: Compositional Privacy Risks and Mitigations in Multi-Agent Collaboration](https://arxiv.org/abs/2509.14284) — **attack** · arXiv · 2025 · arXiv · `arxiv_2509_14284` +52. [Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs](https://doi.org/10.18653/v1/2026.findings-acl.1980) — **evaluation** · Findings of ACL · 2025 · DOI · `liu2026topology_memory` +53. [TRiSM for Agentic AI: A Review of Trust Risk and Security Management in LLM-based Agentic Multi-Agent Systems](https://doi.org/10.1016/j.aiopen.2026.02.006) — **survey** · AI Open · 2025 · DOI · `raza2026trism` +54. [Who's the Mole? Modeling and Detecting Intention-Hiding Malicious Agents in LLM-Based Multi-Agent Systems](https://arxiv.org/abs/2507.04724) — **evaluation** · arXiv · 2025 · arXiv · `xie2025_whos_the_mole` +55. [WOLF: Werewolf-based Observations for LLM Deception and Falsehoods](https://arxiv.org/abs/2512.09187) — **evaluation** · arXiv · 2025 · arXiv · `arxiv_2512_09187` +56. [A Literature Survey on Privacy-Preserving Multi-Agent RAG Systems with an Intelligent Tag-Inference Routing System](https://doi.org/10.56726/irjmets98584) — **survey** · International Research Journal of Modernization in Engineering Technology and Science · 2026 · DOI · `doi:10.56726/irjmets98584` +57. [A2ASecBench: A Protocol-Aware Security Benchmark for Agent-to-Agent Multi-Agent Systems](https://iclr.cc/virtual/2026/poster/10010017) — **evaluation** · ICLR · 2026 · Primary source · `li2026a2asecbench` +58. [ACIARena: Toward Unified Evaluation for Agent Cascading Injection](https://doi.org/10.18653/v1/2026.acl-long.457) — **evaluation** · ACL · 2026 · DOI · `an2026aciarena` +59. [AgentChain: Blockchain-Empowered Multi-Agent Coordination for Trustworthy LLM Question-Answering Systems](https://doi.org/10.1109/tdsc.2026.3685256) — **defense** · IEEE Transactions on Dependable and Secure Computing · 2026 · DOI · `doi:10.1109/tdsc.2026.3685256` +60. [AgentLeak: A Benchmark for Internal-Channel Privacy Leakage in Multi-Agent LLM Systems](https://doi.org/10.1109/access.2026.3704541) — **evaluation** · IEEE Access · 2026 · DOI · `elyagoubi2026agentleak` +61. [Among Us: Measuring and Mitigating Malicious Contributions in Model Collaboration Systems](https://doi.org/10.18653/v1/2026.acl-long.725) — **attack** · ACL · 2026 · DOI · `yang2026among_us` +62. [Architectural Resilience in AI-Driven Decision Systems under Adversarial Conditions](https://doi.org/10.1109/icaic67076.2026.11395749) — **defense** · International Conference on Applied Informatics and Communication · 2026 · DOI · `doi:10.1109/icaic67076.2026.11395749` +63. [CAPRI-DP: A Differentially Private Extension to Context-Aware Multi-Agent Privacy Frameworks](https://doi.org/10.1109/iccces62661.2026.11437027) — **defense** · 2026 5th International Conference on Communication, Computing and Electronics Systems (ICCCES) · 2026 · DOI · `doi:10.1109/iccces62661.2026.11437027` +64. [Cascading Instruction Influence Indirect Prompt Injection in Hierarchical Multi-Agent Systems](https://doi.org/10.19139/soic-2310-5070-3574) — **attack** · Statistics, Optimization & Information Computing · 2026 · DOI · `doi:10.19139/soic-2310-5070-3574` +65. [CIA: Inferring the Communication Topology from LLM-based Multi-Agent Systems](https://doi.org/10.18653/v1/2026.acl-long.815) — **attack** · ACL · 2026 · DOI · `wu2026cia` +66. [Collaborative-adversarial jailbreaking: A propagation-aware attack framework for multi-agent code generation systems.](https://doi.org/10.1016/j.neunet.2026.109280) — **evaluation** · Neural Networks · 2026 · DOI · `doi:10.1016/j.neunet.2026.109280` +67. [Conjunctive Prompt Attacks in Multi-Agent LLM Systems](https://doi.org/10.18653/v1/2026.acl-long.1577) — **attack** · ACL · 2026 · DOI · `arif2026conjunctive` +68. [Consensus-Driven Metacognition in Multi-Agent Systems: A Logic-Based Byzantine Fault-Tolerant Protocol](https://doi.org/10.63412/8vgf0b98) — **defense** · International Journal of Global Innovations and Solutions · 2026 · DOI · `doi:10.63412/8vgf0b98` +69. [ConvPayMAS: Conversational Payment Multi-Agent System with Agent-to-Agent Protocol and Three-Mandate Verification](https://doi.org/10.65109/ydmy4904) — **defense** · Proceedings of the 25th International Conference on Autonomous Agents and Multiagent Systems · 2026 · DOI · `doi:10.65109/ydmy4904` +70. [Deception and Communication in Autonomous Multi-Agent Systems: An Experimental Study with Among Us](https://doi.org/10.65109/frxl8789) — **evaluation** · AAMAS · 2026 · DOI · `milkowski2026amongus` +71. [Ethical Coordination of LLM Multi-Agent Systems](https://doi.org/10.3390/electronics15112278) — **defense** · Electronics · 2026 · DOI · `doi:10.3390/electronics15112278` +72. [LieCraft: A Multi-Agent Framework for Evaluating Deceptive Capabilities in Language Models](https://doi.org/10.1609/aaai.v40i44.41116) — **evaluation** · AAAI · 2026 · DOI · `olson2026liecraft` +73. [Lying with Truths: Open-Channel Multi-Agent Collusion for Belief Manipulation via Generative Montage](https://doi.org/10.18653/v1/2026.acl-long.270) — **attack** · ACL · 2026 · DOI · `hu2026lying_truths` +74. [MASLeak: Investigating and Exposing Intellectual Property Leakage Vulnerabilities in Multi-Agent Systems](https://arxiv.org/abs/2505.12442) — **attack** · USENIX Security 2026 · 2026 · arXiv · `wang2026masleak` +75. [MIN-Trust: A Minimum Necessary Information Trust Orchestration Framework for Multi-Agent Collaboration](https://doi.org/10.1145/3813808.3813811) — **defense** · GAIE 2026 · 2026 · DOI · `supp_min_trust_a_minimum_necessary_information_trust_orchestration_framework_for_mult` +76. [MPAS: Breaking Sequential Constraints of Multi-Agent Communication Topologies via Individual-Epistemic Message Propagation](https://doi.org/10.1609/aaai.v40i35.40231) — **general** · Open MIND · 2026 · DOI · `doi:10.1609/aaai.v40i35.40231` +77. [Orchestration and Verification of Agentic AI Systems: A Survey of Multi-Agent Collaboration and Safety](https://doi.org/10.59324/ejaset.2026.4(2).16) — **survey** · European Journal of Applied Science, Engineering and Technology · 2026 · DOI · `doi:10.59324/ejaset.2026.4(2).16` +78. [Privacy-Preserving LLM Infrastructure With Multi-Agent Orchestration And RAG-Driven Retrieval](https://doi.org/10.63278/jicrcr.vi.3596) — **defense** · Journal of International Crisis and Risk Communication Research · 2026 · DOI · `doi:10.63278/jicrcr.vi.3596` +79. [RAG-Induced Failures in Multi-Agent Large Language Model Debate](https://doi.org/10.1109/icetes68504.2026.11518808) — **attack** · 2026 1st International Conference on Emerging Technologies and Engineering Systems (ICETES) · 2026 · DOI · `doi:10.1109/icetes68504.2026.11518808` +80. [ResMAS: Resilience Optimization in LLM-based Multi-agent Systems](https://doi.org/10.1609/aaai.v40i41.40824) — **defense** · AAAI · 2026 · DOI · `zhou2026resmas` +81. [RiskLab: A Controlled Toolkit for Probing Emergent Risks in LLM-Based Multi-Agent Systems](https://doi.org/10.18653/v1/2026.acl-demo.17) — **evaluation** · ACL System Demonstrations · 2026 · DOI · `jiang2026risklab` +82. [Robust LLM-based Multi-Agent System with Action Negotiation and Sharing Redundancy Enhancement](https://doi.org/10.1145/3770854.3780202) — **defense** · Knowledge Discovery and Data Mining · 2026 · DOI · `doi:10.1145/3770854.3780202` +83. [RoMa: A Credibility-Aware Fault-Tolerance Framework for LLM Multi-Agent Systems](https://doi.org/10.1109/cscwd68734.2026.11582680) — **defense** · International Conference on Computer Supported Cooperative Work in Design · 2026 · DOI · `doi:10.1109/cscwd68734.2026.11582680` +84. [Self-Healing Memory Architectures for Large Language Model-Based Multi-Agent Collaboration](https://doi.org/10.71465/ajainn3659) — **defense** · American journal of artificial intelligence and neural networks · 2026 · DOI · `doi:10.71465/ajainn3659` +85. [Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines](https://doi.org/10.1609/aaaiss.v9i1.42936) — **attack** · AAAI Symposium Series · 2026 · DOI · `ahad2026sif` +86. [SentinelNet: Safeguarding Multi-Agent Collaboration Through Credit-Based Dynamic Threat Detection](https://doi.org/10.1145/3774904.3792462) — **defense** · The Web Conference · 2026 · DOI · `feng2026sentinelnet` +87. [The Trust Paradox in LLM-Based Multi-Agent Systems: When Collaboration Becomes a Security Vulnerability](https://doi.org/10.1109/tcss.2026.3695070) — **evaluation** · IEEE Transactions on Computational Social Systems · 2026 · DOI · `xu2026trust_paradox` +88. [Topology Linearization for Multi-Agent Systems Security: Mitigating Malicious Propagation via Path Decomposition](https://doi.org/10.1109/tnse.2026.3680460) — **defense** · IEEE Transactions on Network Science and Engineering · 2026 · DOI · `doi:10.1109/tnse.2026.3680460` +89. [Trustworthy Agentic AI: A Survey and Taxonomy of Secure Coordination and Hallucination Mitigation in Multi-Agent Large Language Model Systems](https://doi.org/10.38124/ijisrt/26feb1090) — **survey** · International Journal of Innovative Science and Research Technology · 2026 · DOI · `doi:10.38124/ijisrt/26feb1090` +90. [When collaboration fails: persuasion driven adversarial influence in multi agent large language model debate](https://doi.org/10.1038/s41598-026-42705-7) — **attack** · Scientific Reports · 2026 · DOI · `kraidia2026collaboration_fails` +91. [When Embedding-Based Defenses Fail: Rethinking Safety in LLM-Based Multi-Agent Systems](https://arxiv.org/abs/2605.01133) — **attack** · ICML · 2026 · arXiv · `zhang2026embedding_defenses` +92. [Whispering Agents: A Event-Driven Covert Communication Protocol for the Internet of Agents](https://doi.org/10.1609/aaai.v40i37.40380) — **attack** · AAAI · 2026 · DOI · `doi:10.1609/aaai.v40i37.40380` + +## Set 2: emerging MAS-security works (97) + +93. [AgentMonitor: A Plug-and-Play Framework for Predictive and Secure Multi-Agent Systems](https://arxiv.org/abs/2408.14972) — **defense** · arXiv.org · 2024 · arXiv · `arxiv:2408.14972` +94. [IBGP: Imperfect Byzantine Generals Problem for Zero-Shot Robustness in Communicative Multi-Agent Systems](https://arxiv.org/abs/2410.16237) — **defense** · AAMAS · 2024 · arXiv · `mao2025ibgp` +95. [1-2-3 Check: Enhancing Contextual Privacy in LLM via Multi-Agent Reasoning](https://arxiv.org/abs/2508.07667) — **defense** · LLMSEC 2025 Workshop · 2025 · arXiv · `arxiv_2508_07667` +96. [Achilles Heel of Distributed Multi-Agent Systems](https://arxiv.org/abs/2504.07461) — **evaluation** · arXiv.org · 2025 · arXiv · `arxiv:2504.07461` +97. [AdvEvo-MARL: Shaping Internalized Safety through Adversarial Co-Evolution in Multi-Agent Reinforcement Learning](https://arxiv.org/abs/2510.01586) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2510.01586` +98. [Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents](https://arxiv.org/abs/2509.13597) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2509.13597` +99. [AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management](https://arxiv.org/abs/2503.04392) — **defense** · arXiv · 2025 · arXiv · `mao2025agentsafe` +100. [AgentShield: Make MAS more secure and efficient](https://arxiv.org/abs/2511.22924) — **defense** · arXiv · 2025 · arXiv · `supp_agentshield_2025` +101. [Amplified Vulnerabilities: Structured Jailbreak Attacks on LLM-based Multi-Agent Debate](https://arxiv.org/abs/2504.16489) — **attack** · arXiv.org · 2025 · arXiv · `arxiv:2504.16489` +102. [Byzantine Fault-Tolerant Multi-Agent System for Healthcare: A Gossip Protocol Approach to Secure Medical Message Propagation](https://arxiv.org/abs/2512.17913) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2512.17913` +103. [Byzantine-Robust Decentralized Coordination of LLM Agents](https://arxiv.org/abs/2507.14928) — **defense** · arXiv · 2025 · arXiv · `jo2025byzantinerobust` +104. [Collaborative Shadows: Distributed Backdoor Attacks in LLM-Based Multi-Agent Systems](https://arxiv.org/abs/2510.11246) — **attack** · arXiv · 2025 · arXiv · `zhu2025_collaborative_shadows` +105. [Convergence dynamics of Agent-to-Agent Interactions with Misaligned objectives](https://arxiv.org/abs/2511.08710) — **general** · arXiv.org · 2025 · arXiv · `arxiv:2511.08710` +106. [DAO-Agent: Zero Knowledge-Verified Incentives for Decentralized Multi-Agent Coordination](https://arxiv.org/abs/2512.20973) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2512.20973` +107. [Demonstrations of Integrity Attacks in Multi-Agent Systems](https://arxiv.org/abs/2506.04572) — **attack** · arXiv · 2025 · arXiv · `zheng2025integrity_attacks` +108. [Don't Trust Your Upstream: Exploiting LLM Multi-Agent System via Topology-Guided Adversarial Propagation](https://arxiv.org/abs/2512.04129) — **attack** · arXiv · 2025 · arXiv · `liang2025_dont_trust_upstream` +109. [Ev-Trust: An Evolutionarily Stable Trust Mechanism for Decentralized LLM-Based Multi-Agent Service Economies](https://arxiv.org/abs/2512.16167) — **defense** · venue not recorded · 2025 · arXiv · `arxiv:2512.16167` +110. [Exposing Weak Links in Multi-Agent Systems under Adversarial Prompting](https://arxiv.org/abs/2511.10949) — **evaluation** · AAMAS Strategic Engineering Workshop · 2025 · arXiv · `arora2026safeagents` +111. [Formalizing the Safety Security and Functional Properties of Agentic AI Systems](https://arxiv.org/abs/2510.14133) — **general** · arXiv · 2025 · arXiv · `allegrini2025formalizing` +112. [Goal-Aware Identification and Rectification of Misinformation in Multi-Agent Systems](https://arxiv.org/abs/2506.00509) — **defense** · arXiv · 2025 · arXiv · `li2025argus` +113. [LLM Hijacking: When Models Manipulate Their Routers](https://doi.org/10.5281/zenodo.17812179) — **attack** · Zenodo (CERN European Organization for Nuclear Research) · 2025 · DOI · `doi:10.5281/zenodo.17812179` +114. [MAD-Spear: A Conformity-Driven Prompt Injection Attack on Multi-Agent Debate Systems](https://arxiv.org/abs/2507.13038) — **attack** · arXiv.org · 2025 · arXiv · `arxiv:2507.13038` +115. [Many-to-One Adversarial Consensus: Exposing Multi-Agent Collusion Risks in AI-Based Healthcare](https://arxiv.org/abs/2512.03097) — **attack** · arXiv.org · 2025 · arXiv · `arxiv:2512.03097` +116. [Maris: A Formally Verifiable Privacy Policy Enforcement Paradigm for Multi-Agent Collaboration Systems](https://arxiv.org/abs/2505.04799) — **defense** · arXiv · 2025 · arXiv · `cui2025maris` +117. [MedSentry: Understanding and Mitigating Safety Risks in Medical LLM Multi-Agent Systems](https://arxiv.org/abs/2505.20824) — **evaluation** · arXiv · 2025 · arXiv · `chen2025medsentry` +118. [QuadSentinel: Sequent Safety for Machine-Checkable Control in Multi-agent Systems](https://arxiv.org/abs/2512.16279) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2512.16279` +119. [Securing Multi-Agent Systems Against Corruptions via Node Contribution Backpropagation](https://arxiv.org/abs/2510.19420) — **defense** · venue not recorded · 2025 · arXiv · `arxiv:2510.19420` +120. [Terrarium: Revisiting the Blackboard for Multi-Agent Safety, Privacy, and Security Studies](https://arxiv.org/abs/2510.14312) — **evaluation** · arXiv.org · 2025 · arXiv · `arxiv:2510.14312` +121. [The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise](https://arxiv.org/abs/2507.06850) — **attack** · arXiv · 2025 · arXiv · `lupinacci2025darkside` +122. [To Trust or Not to Trust: Attention-based Trust Management for LLM Multi-Agent Systems](https://arxiv.org/abs/2506.02546) — **defense** · arXiv · 2025 · arXiv · `he2025atrust` +123. [Toward Trustworthy Agentic AI: A Multimodal Framework for Preventing Prompt Injection Attacks](https://arxiv.org/abs/2512.23557) — **defense** · arXiv.org · 2025 · arXiv · `arxiv:2512.23557` +124. [When Persuasion Overrides Truth in Multi-Agent LLM Debates: Introducing a Confidence-Weighted Persuasion Override Rate (CW-POR)](https://arxiv.org/abs/2504.00374) — **attack** · arXiv · 2025 · arXiv · `arxiv_2504_00374` +125. [AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems](https://arxiv.org/abs/2603.15727) — **attack** · venue not recorded · 2026 · arXiv · `arxiv:2603.15727` +126. [Algorithmic Cowardice: Cognitive Dissonance and Moral Conformity in Multi-Agent LLM Interactions](https://doi.org/10.5281/zenodo.18902320) — **evaluation** · Zenodo · 2026 · DOI · `doi:10.5281/zenodo.18902320` +127. [Architecture Matters: Comparing RAG Systems under Knowledge Base Poisoning](https://arxiv.org/abs/2605.05632) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2605.05632` +128. [Auditing Agent Harness Safety](https://arxiv.org/abs/2605.14271) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2605.14271` +129. [Autonomous LLM Agent Worms: Cross-Platform Propagation, Automated Discovery and Temporal Re-Entry Defense](https://arxiv.org/abs/2605.02812) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2605.02812` +130. [Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems](https://arxiv.org/abs/2606.07805) — **evaluation** · arXiv · 2026 · arXiv · `zhao2026macbench` +131. [Beyond Input Guardrails: Reconstructing Cross-Agent Semantic Flows for Execution-Aware Attack Detection](https://arxiv.org/abs/2603.04469) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2603.04469` +132. [Beyond Single-Agent Alignment: Preventing Context-Fragmented Violations in Multi-Agent Systems](https://arxiv.org/abs/2604.22879) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2604.22879` +133. [Blind Spots in the Guard: How Domain-Camouflaged Injection Attacks Evade Detection in Multi-Agent LLM Systems](https://arxiv.org/abs/2605.22001) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2605.22001` +134. [Byzantine Cheap Talk: Adversarial Resilience and Topology Effects in LLM Coordination Games](https://arxiv.org/abs/2606.07790) — **attack** · arXiv (Cornell University) · 2026 · arXiv · `arxiv:2606.07790` +135. [CalBench: Evaluating Coordination-Privacy Trade-offs in Multi-Agent LLMs](https://arxiv.org/abs/2605.09823) — **evaluation** · arXiv · 2026 · arXiv · `zou2026calbench` +136. [CASPIAN: Online Detection and Attribution of Cascade Attacks in LLM Multi-Agent Systems via Cross-Channel Causal Monitoring](https://arxiv.org/abs/2605.19240) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2605.19240` +137. [Collective Hallucination in Multi-Agent LLMs:Modeling and Defense](https://arxiv.org/abs/2606.07941) — **defense** · venue not recorded · 2026 · arXiv · `arxiv:2606.07941` +138. [Colosseum: Auditing Collusion in Cooperative Multi-Agent Systems](https://arxiv.org/abs/2602.15198) — **evaluation** · arXiv · 2026 · arXiv · `nakamura2026colosseum` +139. [Defending LLM-based Multi-Agent Systems Against Cooperative Attacks with Sentence-Level Rectification](https://arxiv.org/abs/2605.28104) — **defense** · arXiv · 2026 · arXiv · `supp_star_cooperative_attacks_2026` +140. [Detecting Multi-Agent Collusion Through Multi-Agent Interpretability](https://arxiv.org/abs/2604.01151) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2604.01151` +141. [Distributed General-Purpose Agent Networks: Architecture, Key Mechanisms, and Prototypes](https://arxiv.org/abs/2606.17368) — **general** · venue not recorded · 2026 · arXiv · `arxiv:2606.17368` +142. [Don't Trust Stubborn Neighbors: A Security Framework for Agentic Networks](https://arxiv.org/abs/2603.15809) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2603.15809` +143. [Dynamic Attentional Context Scoping: Agent-Triggered Focus Sessions for Isolated Per-Agent Steering in Multi-Agent LLM Orchestration](https://arxiv.org/abs/2604.07911) — **general** · arXiv.org · 2026 · arXiv · `arxiv:2604.07911` +144. [DynaTrust: Defending Multi-Agent Systems Against Sleeper Agents via Dynamic Trust Graphs](https://arxiv.org/abs/2603.15661) — **defense** · arXiv · 2026 · arXiv · `supp_dynatrust_2026` +145. [EquiMem: Calibrating Shared Memory in Multi-Agent Debate via Game-Theoretic Equilibrium](https://arxiv.org/abs/2605.09278) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2605.09278` +146. [FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems](https://arxiv.org/abs/2605.11514) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2605.11514` +147. [From Debate to Decision: Conformal Social Choice for Safe Multi-Agent Deliberation](https://arxiv.org/abs/2604.07667) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2604.07667` +148. [From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration](https://arxiv.org/abs/2603.04474) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2603.04474` +149. [GAMBIT: A Three-Mode Benchmark for Adversarial Robustness in Multi-Agent LLM Collectives](https://arxiv.org/abs/2605.09027) — **evaluation** · arXiv · 2026 · arXiv · `lemercier2026gambit` +150. [Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs](https://arxiv.org/abs/2606.10322) — **defense** · venue not recorded · 2026 · arXiv · `arxiv:2606.10322` +151. [GAMMAF: A Common Framework for Graph-Based Anomaly Monitoring Benchmarking in LLM Multi-Agent Systems](https://arxiv.org/abs/2604.24477) — **evaluation** · arXiv · 2026 · arXiv · `mateotorrejon2026gammaf` +152. [Governed Shared Memory for Multi-Agent LLM Systems](https://arxiv.org/abs/2606.24535) — **defense** · venue not recorded · 2026 · arXiv · `arxiv:2606.24535` +153. [HARP: Measuring Harm Amplification in Multi-Agent LLM Systems](https://arxiv.org/abs/2605.27489) — **evaluation** · arXiv · 2026 · arXiv · `rahman2026harp` +154. [INFA-Guard: Mitigating Malicious Propagation via Infection-Aware Safeguarding in LLM-Based Multi-Agent Systems](https://arxiv.org/abs/2601.14667) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2601.14667` +155. [Insider Attacks in Multi-Agent LLM Consensus Systems](https://arxiv.org/abs/2605.08268) — **attack** · arXiv · 2026 · arXiv · `sun2026insider` +156. [Institutional AI: Governing LLM Collusion in Multi-Agent Cournot Markets via Public Governance Graphs](https://arxiv.org/abs/2601.11369) — **defense** · arXiv · 2026 · arXiv · `arxiv_2601_11369` +157. [Kill-Chain Canaries: Stage-Level Tracking of Prompt Injection Across Attack Surfaces and Model Safety Tiers](https://arxiv.org/abs/2603.28013) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2603.28013` +158. [LCGuard: Latent Communication Guard for Safe KV Sharing in Multi-Agent Systems](https://arxiv.org/abs/2605.22786) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2605.22786` +159. [LDP: An Identity-Aware Protocol for Multi-Agent LLM Systems](https://doi.org/10.21203/rs.3.rs-9121599/v1) — **defense** · arXiv.org · 2026 · DOI · `arxiv:2603.08852` +160. [Linguistic Firewall: Geometry as Defense in Multi-Agent Systems Routing](https://arxiv.org/abs/2606.30555) — **defense** · arXiv (Cornell University) · 2026 · arXiv · `arxiv:2606.30555` +161. [LLM Drift Experiment: A Framework for Quantifying Behavioral Decay in Adversarial Multi-Agent Simulations](https://doi.org/10.5281/zenodo.20032071) — **evaluation** · Zenodo (CERN European Organization for Nuclear Research) · 2026 · DOI · `doi:10.5281/zenodo.20032071` +162. [Memetic Cascade Detection and Symbolic Immunity in Multi-Agent LLM Systems](https://doi.org/10.5281/zenodo.19244877) — **defense** · Zenodo (CERN European Organization for Nuclear Research) · 2026 · DOI · `doi:10.5281/zenodo.19244877` +163. [MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems](https://arxiv.org/abs/2606.30602) — **evaluation** · venue not recorded · 2026 · arXiv · `arxiv:2606.30602` +164. [Multi-Agent Orchestration: Coordination, Trust, and Cascading Failures](https://doi.org/10.2139/ssrn.6734798) — **survey** · SSRN Electronic Journal · 2026 · DOI · `doi:10.2139/ssrn.6734798` +165. [Nexus Protocol: A Cryptographically Secure, Zero-Latency Semantic Routing Engine for Multi-Agent Systems](https://doi.org/10.2139/ssrn.7127218) — **defense** · SSRN Electronic Journal · 2026 · DOI · `doi:10.2139/ssrn.7127218` +166. [No Action Without a NOD: A Heterogeneous Multi-Agent Architecture for Reliable Service Agents](https://arxiv.org/abs/2605.12240) — **general** · arXiv.org · 2026 · arXiv · `arxiv:2605.12240` +167. [OMNI-LEAK: Orchestrator Multi-Agent Network Induced Data Leakage](https://arxiv.org/abs/2602.13477) — **survey** · arXiv · 2026 · arXiv · `naik2026omni_leak` +168. [Pratyahara: A Neural Tissue Defense Model for Detecting Compromised Agents in Multi-Agent Networks](https://doi.org/10.5281/zenodo.19628588) — **defense** · Zenodo (CERN European Organization for Nuclear Research) · 2026 · DOI · `doi:10.5281/zenodo.19628588` +169. [PRISM: Generation-Time Detection and Mitigation of Secret Leakage in Multi-Agent LLM Pipelines](https://arxiv.org/abs/2605.10614) — **defense** · arXiv · 2026 · arXiv · `tapwal2026prism` +170. [Prompt Injection Mitigation with Agentic AI, Nested Learning, and AI Sustainability via Semantic Caching](https://arxiv.org/abs/2601.13186) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2601.13186` +171. [Prompt Optimization Enables Stable Algorithmic Collusion in LLM Agents](https://arxiv.org/abs/2604.17774) — **general** · arXiv.org · 2026 · arXiv · `arxiv:2604.17774` +172. [PropGuard: Safeguarding LLM-MAS via Propagation-Aware Exploration and Remediation](https://arxiv.org/abs/2605.16346) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2605.16346` +173. [Robust Multi-Agent LLMs under Byzantine Faults](https://arxiv.org/abs/2605.09076) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2605.09076` +174. [SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems](https://arxiv.org/abs/2606.12474) — **defense** · arXiv · 2026 · arXiv · `shi2026saiguard` +175. [Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations](https://arxiv.org/abs/2606.15008) — **evaluation** · venue not recorded · 2026 · arXiv · `arxiv:2606.15008` +176. [Semantic Taint Propagation: Embedding-Based Semantic Flow Monitoring for Multi-Agent Large Language Model Systems](https://doi.org/10.5281/zenodo.20834834) — **defense** · Zenodo (CERN European Organization for Nuclear Research) · 2026 · DOI · `doi:10.5281/zenodo.20834834` +177. [SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems](https://arxiv.org/abs/2604.02767) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2604.02767` +178. [SGTO-MAS: Secure Gorilla Troops Optimization for Multi-Agent LLM Systems](https://arxiv.org/abs/2606.07940) — **defense** · venue not recorded · 2026 · arXiv · `arxiv:2606.07940` +179. [Smarter Saboteurs, Better Fixers: Scaling&Security in Linear Multi-Agent Workflows](https://arxiv.org/abs/2606.12709) — **general** · venue not recorded · 2026 · arXiv · `arxiv:2606.12709` +180. [SNEAK: Evaluating Strategic Communication and Information Leakage in Large Language Models](https://arxiv.org/abs/2603.29846) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2603.29846` +181. [The Capability Paradox: How Smarter Auditors Make Multi-Agent Systems Less Secure](https://arxiv.org/abs/2605.17480) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2605.17480` +182. [The Consensus Trap: Rescuing Multi-Agent LLMs from Adversarial Majorities via Token-Level Collaboration](https://arxiv.org/abs/2604.17139) — **defense** · arXiv.org · 2026 · arXiv · `arxiv:2604.17139` +183. [Towards Security-Auditable LLM Agents: A Unified Graph Representation](https://arxiv.org/abs/2605.06812) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2605.06812` +184. [TrinityGuard: A Unified Framework for Safeguarding Multi-Agent Systems](https://arxiv.org/abs/2603.15408) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2603.15408` +185. [TRUST: A Framework for Decentralized AI Service v.0.1](https://arxiv.org/abs/2604.27132) — **general** · arXiv.org · 2026 · arXiv · `arxiv:2604.27132` +186. [WebWeaver: Breaking Topology Confidentiality in LLM Multi-Agent Systems with Stealthy Context-Based Inference](https://arxiv.org/abs/2603.11132) — **attack** · arXiv.org · 2026 · arXiv · `arxiv:2603.11132` +187. [When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks](https://arxiv.org/abs/2605.08460) — **evaluation** · arXiv.org · 2026 · arXiv · `arxiv:2605.08460` +188. [When Latent Agents Lie: KV-Cache Integrity in Multi-Agent LLM Collaboration](https://arxiv.org/abs/2606.28958) — **attack** · venue not recorded · 2026 · arXiv · `arxiv:2606.28958` +189. [Tool Use Enables Undetectable Steganography in Multi-Agent LLM Systems](https://doi.org/10.48550/arXiv.2606.28425) — **attack** · arXiv · 2026 · DOI · `arxiv:2606.28425` diff --git a/scripts/build_artifact_source_links.py b/scripts/build_artifact_source_links.py new file mode 100644 index 0000000..fce3dbe --- /dev/null +++ b/scripts/build_artifact_source_links.py @@ -0,0 +1,93 @@ +#!/usr/bin/env python3 +from __future__ import annotations + +import csv +from pathlib import Path + +ROOT = Path(__file__).resolve().parents[1] +CORPUS = ROOT / "corpus" +OUT = ROOT / "artifact" / "README.md" + +EXPECTED = {"set1_core": 92, "set2_emerging": 97} + + +def read_rows(name: str) -> list[dict[str, str]]: + path = CORPUS / f"{name}.csv" + with path.open(encoding="utf-8-sig", newline="") as handle: + rows = list(csv.DictReader(handle)) + if len(rows) != EXPECTED[name]: + raise SystemExit(f"{name}: expected {EXPECTED[name]} rows, found {len(rows)}") + return rows + + +def source_url(row: dict[str, str]) -> tuple[str, str]: + doi = (row.get("doi") or "").strip() + arxiv = (row.get("arxiv_id") or "").strip() + primary = (row.get("primary_url") or "").strip() + + # Prefer durable scholarly identifiers over aggregator URLs. + if doi and doi.upper() != "N/A": + return f"https://doi.org/{doi}", "DOI" + if arxiv and arxiv.upper() != "N/A": + return f"https://arxiv.org/abs/{arxiv}", "arXiv" + if primary and primary.upper() != "N/A": + return primary, "Primary source" + raise SystemExit(f"No stable source locator for {row.get('work_key')}: {row.get('title')}") + + +def esc(text: str) -> str: + return text.replace("[", "\\[").replace("]", "\\]") + + +def render_section(label: str, rows: list[dict[str, str]], start: int) -> tuple[list[str], int]: + lines = [f"## {label} ({len(rows)})", ""] + n = start + for row in rows: + url, kind = source_url(row) + title = esc((row.get("title") or "").strip()) + venue = (row.get("venue") or "").strip() or "venue not recorded" + year = (row.get("year") or "").strip() or (row.get("publication_date") or "")[:4] + contribution = (row.get("dominant_contribution") or "").strip() or "unspecified" + work_key = (row.get("work_key") or "").strip() + lines.append( + f"{n}. [{title}]({url}) — **{contribution}** · {venue} · {year} · {kind} · `{work_key}`" + ) + n += 1 + lines.append("") + return lines, n + + +def main() -> None: + set1 = read_rows("set1_core") + set2 = read_rows("set2_emerging") + all_rows = set1 + set2 + if len(all_rows) != 189: + raise SystemExit(f"expected 189 active works, found {len(all_rows)}") + keys = [r.get("work_key", "") for r in all_rows] + if len(keys) != len(set(keys)): + raise SystemExit("duplicate work_key in active corpus") + + lines = [ + "# Source Links for the 189-Work MAS-Security Corpus", + "", + "This directory is the source-access layer for the USENIX artifact. It lists every active corpus work with at least one stable, clickable locator. Third-party PDFs are not redistributed here; the links point to DOI, arXiv, or the recorded primary source.", + "", + "Active corpus: **92 Set 1 + 97 Set 2 = 189 works**.", + "", + "Source-link priority is **DOI → arXiv → recorded primary URL** so that durable scholarly identifiers are preferred over aggregator pages. Corpus membership and taxonomy remain authoritative in `../corpus/set1_core.csv` and `../corpus/set2_emerging.csv`.", + "", + ] + section, next_n = render_section("Set 1: mature MAS-security works", set1, 1) + lines.extend(section) + section, next_n = render_section("Set 2: emerging MAS-security works", set2, next_n) + lines.extend(section) + if next_n != 190: + raise SystemExit(f"numbering error: next index is {next_n}") + + OUT.parent.mkdir(parents=True, exist_ok=True) + OUT.write_text("\n".join(lines).rstrip() + "\n", encoding="utf-8") + print(f"Wrote {OUT.relative_to(ROOT)} with {len(all_rows)} linked works") + + +if __name__ == "__main__": + main()