1 paper
Diego Fernandez Arias, Dev Prashant Mistry, Ren Wang +1
Multi-agent LLM systems can be attacked by a payload that no single agent ever holds in full: a poisoned tool hides encrypted fragments in its observations, spreads them across sev…