Research · curated 17 Sep 2026

SoK: When Safe Agents Fail Together: The Security of Multi Agent LLM Systems

Coverage timeline

17 Sep 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Multi-agent LLM systems move state and authority across principal boundaries, creating emergent failure modes that local checks miss, so defenders need this interaction-aware taxonomy to trace attacks end to end and test whether defenses actually close those paths.

The SoK paper "When Safe Agents Fail Together" systematizes the security of multi-agent LLM systems (MAS) through an execution-centered analysis of 197 works, covering six interaction interfaces, four adversary positions, seven system-level risks, and eight recurring attack paths. It introduces an A-I-R framework organizing attacks by adversary position, interaction interface, and resulting risk, and a five-part defense contract, while auditing 44 evaluation and benchmark works.