{
 "as_of": "2026-09-01",
 "caveat": "research telemetry; visibility/structural observation of public data at a snapshot; not validation/supervision/legal-status/prevalence",
 "count": 120,
 "errors": {},
 "fetched_utc": "2026-09-01T04:50:58+00:00",
 "snapshot": {
  "arxiv:2601.00240": {
   "arxiv_id": "2601.00240",
   "authors": [
    "Zongwei Wang",
    "Bincheng Gu",
    "Hongyu Yu",
    "Junliang Yu",
    "Tao He",
    "Jiayin Feng",
    "Chenghua Lin",
    "Min Gao"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-01T07:18:36Z",
   "title": "When Agents See Humans as the Outgroup: Belief-Dependent Bias in LLM-Powered Agents",
   "url": "http://arxiv.org/abs/2601.00240v2",
   "version": "2601.00240v2"
  },
  "arxiv:2601.00360": {
   "arxiv_id": "2601.00360",
   "authors": [
    "Jamiu Idowu",
    "Ahmed Almasoud",
    "Ayman Alfahid"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-01T14:30:37Z",
   "title": "Mapping Human Anti-collusion Mechanisms to Multi-agent AI Systems",
   "url": "http://arxiv.org/abs/2601.00360v3",
   "version": "2601.00360v3"
  },
  "arxiv:2601.02720": {
   "arxiv_id": "2601.02720",
   "authors": [
    "Yuqiao Xu",
    "Mina Namazi",
    "Sahith Reddy Jalapally",
    "Osama Zafar",
    "Youngjin Yoo",
    "Erman Ayday"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-06T05:18:03Z",
   "title": "Privacy-Preserving AI-Enabled Decentralized Learning and Employment Records System",
   "url": "http://arxiv.org/abs/2601.02720v1",
   "version": "2601.02720v1"
  },
  "arxiv:2601.07726": {
   "arxiv_id": "2601.07726",
   "authors": [
    "Xiangyu Liu",
    "Brian Lee",
    "Yuansong Qiao"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-12T16:57:51Z",
   "title": "TeeMAF: A TEE-Based Mutual Attestation Framework for On-Chain and Off-Chain Functions in Blockchain DApps",
   "url": "http://arxiv.org/abs/2601.07726v1",
   "version": "2601.07726v1"
  },
  "arxiv:2601.13903": {
   "arxiv_id": "2601.13903",
   "authors": [
    "Awid Vaziry",
    "Sandro Rodriguez Garzon",
    "Christoph Wronka",
    "Axel Küpper"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-20T12:29:00Z",
   "title": "Know Your Contract: eIDAS-Based Verifiable Legal Identities for Smart Contracts, Enabling Regulatory-Compliant On-Chain Operations",
   "url": "http://arxiv.org/abs/2601.13903v2",
   "version": "2601.13903v2"
  },
  "arxiv:2601.14503": {
   "arxiv_id": "2601.14503",
   "authors": [
    "Wouter Termont",
    "Beatriz Esteves"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-20T21:55:24Z",
   "title": "OpenID for European Digital Identity: An architectural analysis of user-centric identity management",
   "url": "http://arxiv.org/abs/2601.14503v2",
   "version": "2601.14503v2"
  },
  "arxiv:2601.14567": {
   "arxiv_id": "2601.14567",
   "authors": [
    "Roland R. Rodriguez"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-21T01:09:22Z",
   "title": "Agent Identity URI Scheme: Topology-Independent Naming and Capability-Based Discovery for Multi-Agent Systems",
   "url": "http://arxiv.org/abs/2601.14567v2",
   "version": "2601.14567v2"
  },
  "arxiv:2601.16298": {
   "arxiv_id": "2601.16298",
   "authors": [
    "Shaoyu Li",
    "Hexuan Yu",
    "Md Mohaimin Al Barat",
    "Yang Xiao",
    "Y. Thomas Hou",
    "Wenjing Lou"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-22T20:04:00Z",
   "title": "FC-GUARD: Enabling Anonymous yet Compliant Fiat-to-Cryptocurrency Exchanges",
   "url": "http://arxiv.org/abs/2601.16298v1",
   "version": "2601.16298v1"
  },
  "arxiv:2601.19837": {
   "arxiv_id": "2601.19837",
   "authors": [
    "Nacereddine Sitouah",
    "Marco Esposito",
    "Francesco Bruschi"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-01-27T17:43:48Z",
   "title": "Self-Sovereign Identity and eIDAS 2.0: An Analysis of Control, Privacy, and Legal Implications",
   "url": "http://arxiv.org/abs/2601.19837v2",
   "version": "2601.19837v2"
  },
  "arxiv:2602.02629": {
   "arxiv_id": "2602.02629",
   "authors": [
    "Rodrigo Tertulino",
    "Ricardo Almeida",
    "Laercio Alencar"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-02T17:45:58Z",
   "title": "Trustworthy Blockchain-based Federated Learning for Electronic Health Records: Securing Participant Identity with Decentralized Identifiers and Verifiable Credentials",
   "url": "http://arxiv.org/abs/2602.02629v1",
   "version": "2602.02629v1"
  },
  "arxiv:2602.10915": {
   "arxiv_id": "2602.10915",
   "authors": [
    "Zhenhua Zou",
    "Sheng Guo",
    "Qiuyang Zhan",
    "Lepeng Zhao",
    "Shuo Li",
    "Qi Li",
    "Ke Xu",
    "Mingwei Xu",
    "Zhuotao Liu"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-11T14:52:27Z",
   "title": "Blind Gods and Broken Screens: Architecting a Secure, Intent-Centric Mobile Agent Operating System",
   "url": "http://arxiv.org/abs/2602.10915v3",
   "version": "2602.10915v3"
  },
  "arxiv:2602.11023": {
   "arxiv_id": "2602.11023",
   "authors": [
    "Shaoyu Li",
    "Hexuan Yu",
    "Shanghao Shi",
    "Md Mohaimin Al Barat",
    "Yang Xiao",
    "Y. Thomas Hou",
    "Wenjing Lou"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-11T16:49:04Z",
   "title": "IU-GUARD: Privacy-Preserving Spectrum Coordination for Incumbent Users under Dynamic Spectrum Sharing",
   "url": "http://arxiv.org/abs/2602.11023v1",
   "version": "2602.11023v1"
  },
  "arxiv:2602.11376": {
   "arxiv_id": "2602.11376",
   "authors": [
    "Ian Oliver",
    "Pekka Kuure"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-11T21:08:51Z",
   "title": "Modelling Trust and Trusted Systems: A Category Theoretic Approach",
   "url": "http://arxiv.org/abs/2602.11376v1",
   "version": "2602.11376v1"
  },
  "arxiv:2602.12634": {
   "arxiv_id": "2602.12634",
   "authors": [
    "Lingyao Li",
    "Renkai Ma",
    "Chen Chen",
    "Zhicong Lu",
    "Yongfeng Zhang"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-13T05:28:31Z",
   "title": "The Rise of AI Agent Communities: Large-Scale Analysis of Discourse and Interaction on Moltbook",
   "url": "http://arxiv.org/abs/2602.12634v1",
   "version": "2602.12634v1"
  },
  "arxiv:2602.13148": {
   "arxiv_id": "2602.13148",
   "authors": [
    "Parsa Sadri Sinaki",
    "Zainab Ahmad",
    "Wentao Xie",
    "Merlijn Sebrechts",
    "Jimmy Kjällman",
    "Lachlan J. Gunn"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-13T17:56:08Z",
   "title": "TrustMee: Self-Verifying Remote Attestation Evidence",
   "url": "http://arxiv.org/abs/2602.13148v3",
   "version": "2602.13148v3"
  },
  "arxiv:2602.14871": {
   "arxiv_id": "2602.14871",
   "authors": [
    "Hakan Yildiz",
    "Axel Küpper"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-16T16:02:51Z",
   "title": "interID -- An Ecosystem-agnostic Verifier-as-a-Service with OpenID Connect Bridge",
   "url": "http://arxiv.org/abs/2602.14871v1",
   "version": "2602.14871v1"
  },
  "arxiv:2603.05521": {
   "arxiv_id": "2603.05521",
   "authors": [
    "Christoph F. Strnadl"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-02-17T17:40:09Z",
   "title": "Ecosystem Trust Profiles",
   "url": "http://arxiv.org/abs/2603.05521v2",
   "version": "2603.05521v2"
  },
  "arxiv:2603.24172": {
   "arxiv_id": "2603.24172",
   "authors": [
    "Martin Herrmann",
    "Oussama Draissi",
    "Christian Niesler",
    "Ahmad-Reza Sadeghi",
    "Lucas Davi"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-03-25T10:42:08Z",
   "title": "Towards Remote Attestation of Microarchitectural Attacks: The Case of Rowhammer",
   "url": "http://arxiv.org/abs/2603.24172v2",
   "version": "2603.24172v2"
  },
  "arxiv:2603.24775": {
   "arxiv_id": "2603.24775",
   "authors": [
    "Sunil Prakash"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-03-25T19:45:37Z",
   "title": "AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A",
   "url": "http://arxiv.org/abs/2603.24775v1",
   "version": "2603.24775v1"
  },
  "arxiv:2603.28428": {
   "arxiv_id": "2603.28428",
   "authors": [
    "Xiaohang Nie",
    "Zihan Guo",
    "Kezhuo Yang",
    "Zhichong Zheng",
    "Bochen Ge",
    "Shuai Pan",
    "Zeyi Chen",
    "Youling Xiang",
    "Yu Zhang",
    "Weiwen Liu",
    "Yuanjian Zhou",
    "Weinan Zhang"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-03-30T13:35:37Z",
   "title": "Synergy: A Next-Generation General-Purpose Agent for Open Agentic Web",
   "url": "http://arxiv.org/abs/2603.28428v1",
   "version": "2603.28428v1"
  },
  "arxiv:2604.23280": {
   "arxiv_id": "2604.23280",
   "authors": [
    "Takumi Otsuka",
    "Kentaroh Toyoda",
    "Alex Leung"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-04-25T12:51:52Z",
   "title": "AI Identity: Standards, Gaps, and Research Directions for AI Agents",
   "url": "http://arxiv.org/abs/2604.23280v1",
   "version": "2604.23280v1"
  },
  "arxiv:2604.25189": {
   "arxiv_id": "2604.25189",
   "authors": [
    "Minghui Xu",
    "Xiaoyu Liu",
    "Yihao Guo",
    "Chunchi Liu",
    "Yue Zhang",
    "Xiuzhen Cheng"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-04-28T03:50:01Z",
   "title": "AgentDID: Trustless Identity Authentication for AI Agents",
   "url": "http://arxiv.org/abs/2604.25189v1",
   "version": "2604.25189v1"
  },
  "arxiv:2604.25200": {
   "arxiv_id": "2604.25200",
   "authors": [
    "Kemal Bicakci"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-04-28T04:10:04Z",
   "title": "Making AI-Assisted Grant Evaluation Auditable without Exposing the Model",
   "url": "http://arxiv.org/abs/2604.25200v1",
   "version": "2604.25200v1"
  },
  "arxiv:2604.26997": {
   "arxiv_id": "2604.26997",
   "authors": [
    "Akshay Mittal",
    "Elyson De La Cruz"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-04-29T01:24:27Z",
   "title": "Agent Name Service (ANS): A Proof-of-Concept Trust Layer for Secure AI Agent Discovery, Identity, and Governance in Kubernetes",
   "url": "http://arxiv.org/abs/2604.26997v1",
   "version": "2604.26997v1"
  },
  "arxiv:2605.01037": {
   "arxiv_id": "2605.01037",
   "authors": [
    "Alan L. McCann"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-01T19:04:37Z",
   "title": "Certified Purity for Cognitive Workflow Executors: From Static Analysis to Cryptographic Attestation",
   "url": "http://arxiv.org/abs/2605.01037v3",
   "version": "2605.01037v3"
  },
  "arxiv:2605.02824": {
   "arxiv_id": "2605.02824",
   "authors": [
    "João Eduardo Travassos",
    "Miguel Correia"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-04T17:01:16Z",
   "title": "InsureConnect: Blockchain and Digital Identity for the Property Insurance Market",
   "url": "http://arxiv.org/abs/2605.02824v1",
   "version": "2605.02824v1"
  },
  "arxiv:2605.03213": {
   "arxiv_id": "2605.03213",
   "authors": [
    "Javad Forough",
    "Marios Kogias",
    "Hamed Haddadi"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-04T23:09:16Z",
   "title": "When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI",
   "url": "http://arxiv.org/abs/2605.03213v2",
   "version": "2605.03213v2"
  },
  "arxiv:2605.11487": {
   "arxiv_id": "2605.11487",
   "authors": [
    "Partha Madhira"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-12T04:04:34Z",
   "title": "Digital Identity for Agentic Systems: Toward a Portable Authorization Standard for Autonomous Agents",
   "url": "http://arxiv.org/abs/2605.11487v1",
   "version": "2605.11487v1"
  },
  "arxiv:2605.14786": {
   "arxiv_id": "2605.14786",
   "authors": [
    "William Lugoloobi",
    "Samuelle Marro",
    "Jabez Magomere",
    "Joss Wright",
    "Chris Russell"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-14T12:55:19Z",
   "title": "Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces",
   "url": "http://arxiv.org/abs/2605.14786v1",
   "version": "2605.14786v1"
  },
  "arxiv:2605.29868": {
   "arxiv_id": "2605.29868",
   "authors": [
    "Ankit Kanaiyalal Prajapati",
    "Shahzad Memon",
    "Mohammed Mahir Rahman",
    "Ameer Al-Nemrat"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-28T12:52:12Z",
   "title": "Ciphera: A Decentralised Biometric Identity Framework",
   "url": "http://arxiv.org/abs/2605.29868v1",
   "version": "2605.29868v1"
  },
  "arxiv:2606.00962": {
   "arxiv_id": "2606.00962",
   "authors": [
    "Hassan Touheed"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-05-31T02:34:38Z",
   "title": "SS-ZKR: Spatial-Semantic Zero-Knowledge Routing for Privacy-Preserving Multi-Agent Collaboration",
   "url": "http://arxiv.org/abs/2606.00962v1",
   "version": "2606.00962v1"
  },
  "arxiv:2606.03323": {
   "arxiv_id": "2606.03323",
   "authors": [
    "Yang Yang",
    "Kevin Wang",
    "Yuanhai Luo",
    "Hang Yin",
    "Jie Cai",
    "Shunfan Zhou",
    "Wenfeng Wang"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-06-02T08:33:16Z",
   "title": "Implement Kubernetes Pod-Level Remote Attestation for Confidential Workloads on dstack",
   "url": "http://arxiv.org/abs/2606.03323v2",
   "version": "2606.03323v2"
  },
  "arxiv:2606.03771": {
   "arxiv_id": "2606.03771",
   "authors": [
    "Samuel Breckenridge",
    "Dani Vilardell",
    "Derek Leung",
    "Andrés Fábrega",
    "James Austgen",
    "Farinaz Koushanfar",
    "Ari Juels"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-06-02T15:26:35Z",
   "title": "$π$Creds: Privately Inferred Credentials",
   "url": "http://arxiv.org/abs/2606.03771v1",
   "version": "2606.03771v1"
  },
  "arxiv:2606.25876": {
   "arxiv_id": "2606.25876",
   "authors": [
    "Yuhan Jin",
    "Shuohan Wu",
    "Chong Chen",
    "Lingfeng Bao",
    "Xiaohu Yang",
    "Jiachi Chen"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-06-24T14:20:51Z",
   "title": "The Web4 Agent Economy: A Large-Scale Empirical Study of the Landscape, Challenges, and Opportunities",
   "url": "http://arxiv.org/abs/2606.25876v1",
   "version": "2606.25876v1"
  },
  "arxiv:2606.31408": {
   "arxiv_id": "2606.31408",
   "authors": [
    "Robert Schambach",
    "Quoc Do Le",
    "Sergei Arnautov",
    "Christof Fetzer"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-06-30T09:35:28Z",
   "title": "EnclaveX: End-to-End Confidential AI with CPU/GPU TEEs",
   "url": "http://arxiv.org/abs/2606.31408v1",
   "version": "2606.31408v1"
  },
  "arxiv:2607.00695": {
   "arxiv_id": "2607.00695",
   "authors": [
    "Daniel Andrade",
    "João N. Silva",
    "Miguel P. Correia"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-07-01T09:45:14Z",
   "title": "Know Thy Neighbor: Cross-TEE Mutual Attestation",
   "url": "http://arxiv.org/abs/2607.00695v1",
   "version": "2607.00695v1"
  },
  "arxiv:2607.08906": {
   "arxiv_id": "2607.08906",
   "authors": [
    "Nicola Gallo"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-07-09T19:59:29Z",
   "title": "Proof-of-Continuity: A Temporal Model for Authority Propagation in Distributed Systems and AI Agents",
   "url": "http://arxiv.org/abs/2607.08906v1",
   "version": "2607.08906v1"
  },
  "arxiv:2607.17218": {
   "arxiv_id": "2607.17218",
   "authors": [
    "Mohaimin Al Barat",
    "Hexuan Yu",
    "Shaoyu Li",
    "Yang Xiao",
    "Yi Shi",
    "Eric W. Burger",
    "Y. Thomas Hou",
    "Wenjing Lou"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-07-19T12:20:51Z",
   "title": "SpexPay: A Privacy-Preserving Pay-As-You-Go System for Dynamic Spectrum Sharing",
   "url": "http://arxiv.org/abs/2607.17218v1",
   "version": "2607.17218v1"
  },
  "arxiv:2607.23207": {
   "arxiv_id": "2607.23207",
   "authors": [
    "Yifan He",
    "Zhiguang Shan",
    "Le Luo",
    "Wei Wang"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-07-25T13:58:16Z",
   "title": "Accountable yet Anonymous AI Agents - Split-Knowledge Binding in National Agent-Identity Layer in China",
   "url": "http://arxiv.org/abs/2607.23207v1",
   "version": "2607.23207v1"
  },
  "arxiv:2607.23698": {
   "arxiv_id": "2607.23698",
   "authors": [
    "Amarin Laohajirapan",
    "Norrathep Rattanavipanon"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-07-26T14:46:54Z",
   "title": "SMARM+: Analyzing and Enhancing Shuffled Measurements for Remote Attestation in Real-Time IoT Settings",
   "url": "http://arxiv.org/abs/2607.23698v2",
   "version": "2607.23698v2"
  },
  "arxiv:2608.00801": {
   "arxiv_id": "2608.00801",
   "authors": [
    "Anton Sokolov"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-01T18:01:36Z",
   "title": "Hardware-rooted attestation for AI-agent evidence: composing IETF RATS with action evidence packages",
   "url": "http://arxiv.org/abs/2608.00801v1",
   "version": "2608.00801v1"
  },
  "arxiv:2608.01938": {
   "arxiv_id": "2608.01938",
   "authors": [
    "Adam Zahir",
    "Vincent Lefebvre",
    "Mark Angoustures",
    "Milan Groshev",
    "Carlos J. Bernardos"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-03T09:10:31Z",
   "title": "D-MUTRA: DLT-based MUTual Remote Attestation for Multi-Agent Systems",
   "url": "http://arxiv.org/abs/2608.01938v1",
   "version": "2608.01938v1"
  },
  "arxiv:2608.02986": {
   "arxiv_id": "2608.02986",
   "authors": [
    "Keisuke Suzuki"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-04T00:47:13Z",
   "title": "Internalising the Identity Primitive: Cryptographic Individuality for an Autonomous Agent on a Public Blockchain",
   "url": "http://arxiv.org/abs/2608.02986v1",
   "version": "2608.02986v1"
  },
  "arxiv:2608.03534": {
   "arxiv_id": "2608.03534",
   "authors": [
    "Anton Sokolov"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-04T12:14:39Z",
   "title": "A Challenge-Nonce Freshness Gap in Project Veraison's TPM Reference Schemes, Found by Appraising Application-Layer Action Evidence End-to-End",
   "url": "http://arxiv.org/abs/2608.03534v1",
   "version": "2608.03534v1"
  },
  "arxiv:2608.07846": {
   "arxiv_id": "2608.07846",
   "authors": [
    "Yifan He"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-08T01:20:28Z",
   "title": "China RealDID: Verifiable Credentials Anchored in Legal Identity",
   "url": "http://arxiv.org/abs/2608.07846v1",
   "version": "2608.07846v1"
  },
  "arxiv:2608.13030": {
   "arxiv_id": "2608.13030",
   "authors": [
    "Zhenhua Zou",
    "Sheng Guo",
    "Qiuyang Zhan",
    "Lepeng Zhao",
    "Shuo Li",
    "Zhuotao Liu"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-13T10:00:13Z",
   "title": "InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents",
   "url": "http://arxiv.org/abs/2608.13030v2",
   "version": "2608.13030v2"
  },
  "arxiv:2608.19937": {
   "arxiv_id": "2608.19937",
   "authors": [
    "Patrick Herbke",
    "Wolf Rieder",
    "Christian René Sechting",
    "Huaning Yang",
    "Sid Lamichhane",
    "Philip Raschke",
    "Axel Küpper"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-20T11:54:47Z",
   "title": "ShadowPath: Lookup-Private Credential Status Verification over Authenticated State",
   "url": "http://arxiv.org/abs/2608.19937v1",
   "version": "2608.19937v1"
  },
  "arxiv:2608.22525": {
   "arxiv_id": "2608.22525",
   "authors": [
    "Andreea Elena Drăgnoiu",
    "Nicoleta Dumitru",
    "Ruxandra F. Olimid"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-23T17:51:52Z",
   "title": "On SSI-based Private Decentralized Bidding",
   "url": "http://arxiv.org/abs/2608.22525v1",
   "version": "2608.22525v1"
  },
  "arxiv:2608.26367": {
   "arxiv_id": "2608.26367",
   "authors": [
    "Merve Gülmez",
    "Adam Caulfield",
    "Hakan Englund",
    "N. Asokan",
    "Thomas Nyman"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-26T19:51:09Z",
   "title": "PRISM: Lightweight Enclave Isolation with Prismatic Capabilities",
   "url": "http://arxiv.org/abs/2608.26367v1",
   "version": "2608.26367v1"
  },
  "arxiv:2608.30519": {
   "arxiv_id": "2608.30519",
   "authors": [
    "Hui Gong",
    "Michail Samawi",
    "Francesca Medda"
   ],
   "kind": "arxiv_preprint",
   "published": "2026-08-31T09:53:18Z",
   "title": "Authority-Inference Separation in Agentic Finance: First-Line Control, Blockchain Enforcement, and Replayable Assurance",
   "url": "http://arxiv.org/abs/2608.30519v1",
   "version": "2608.30519v1"
  },
  "cite:2501.09674->02489e31aff5ecafbad15efdfa7778b3a310466c": {
   "arxiv": "2512.00742",
   "citer_id": "02489e31aff5ecafbad15efdfa7778b3a310466c",
   "doi": "10.48550/arXiv.2512.00742",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "On the Regulatory Potential of User Interfaces for AI Agent Governance",
   "year": 2025
  },
  "cite:2501.09674->027ed6fb0b40747ed075962bdc53b658ea7f5341": {
   "arxiv": "2607.05463",
   "citer_id": "027ed6fb0b40747ed075962bdc53b658ea7f5341",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Governable Individuals: An Identity Layer for Embodied Agents That Keep Learning",
   "year": 2026
  },
  "cite:2501.09674->06d4f57b387a8a54ba681e5f1ea4be71bcf39bbe": {
   "arxiv": "2604.19211",
   "citer_id": "06d4f57b387a8a54ba681e5f1ea4be71bcf39bbe",
   "doi": "10.48550/arXiv.2604.19211",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "ClawNet: Human-Symbiotic Agent Network for Cross-User Autonomous Cooperation",
   "year": 2026
  },
  "cite:2501.09674->0a0607daf7c1ed403392b656d1e306db3483fb9e": {
   "arxiv": "2604.24920",
   "citer_id": "0a0607daf7c1ed403392b656d1e306db3483fb9e",
   "doi": "10.48550/arXiv.2604.24920",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SUDP: Secret-Use Delegation Protocol for Agentic Systems",
   "year": 2026
  },
  "cite:2501.09674->10bb8c7f1a45af66e3e40bb744eb3d7c22cd6559": {
   "arxiv": "2601.20184",
   "citer_id": "10bb8c7f1a45af66e3e40bb744eb3d7c22cd6559",
   "doi": "10.48550/arXiv.2601.20184",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Securing AI Agents in Cyber-Physical Systems: A Survey of Environmental Interactions, Deepfake Threats, and Defenses",
   "year": 2026
  },
  "cite:2501.09674->1339828ad428805e6483d4dd5972c60c57aba9eb": {
   "arxiv": null,
   "citer_id": "1339828ad428805e6483d4dd5972c60c57aba9eb",
   "doi": "10.1109/REW66121.2025.00053",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Account Abstraction for Enforcing Blockchain-Based AI Agent Non-Functional Requirements",
   "year": 2025
  },
  "cite:2501.09674->19773beab51ff5c61ece81eb0c5759ff1b12ff30": {
   "arxiv": null,
   "citer_id": "19773beab51ff5c61ece81eb0c5759ff1b12ff30",
   "doi": "10.52202/085713-5331",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Emerging Risks from Embodied AI Require Urgent Policy Action",
   "year": 2025
  },
  "cite:2501.09674->1a73f9d70a18f415ac29b6b6a92802b8ac6d50fa": {
   "arxiv": "2506.20702",
   "citer_id": "1a73f9d70a18f415ac29b6b6a92802b8ac6d50fa",
   "doi": "10.48550/arXiv.2506.20702",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "The Singapore Consensus on Global AI Safety Research Priorities",
   "year": 2025
  },
  "cite:2501.09674->1a841ac7ea0a8a016c4c43ebf86b11f48f31332e": {
   "arxiv": "2603.14332",
   "citer_id": "1a841ac7ea0a8a016c4c43ebf86b11f48f31332e",
   "doi": "10.48550/arXiv.2603.14332",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Governing Dynamic Capabilities: Cryptographic Binding and Reproducibility Verification for AI Agent Tool Use",
   "year": 2026
  },
  "cite:2501.09674->1b49e0948c630730d8ab57ac5cec1f970601ce9a": {
   "arxiv": "2509.00117",
   "citer_id": "1b49e0948c630730d8ab57ac5cec1f970601ce9a",
   "doi": "10.48550/arXiv.2509.00117",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Embodied AI: Emerging Risks and Opportunities for Policy Action",
   "year": 2025
  },
  "cite:2501.09674->1c5794bfbb11dbd19b649ee452abcbba68723823": {
   "arxiv": null,
   "citer_id": "1c5794bfbb11dbd19b649ee452abcbba68723823",
   "doi": "10.1109/ICCA66035.2025.11430864",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "A Conceptual Framework for Authentication in Agentic AI Ecosystems: Protocol Analysis and Taxonomy",
   "year": 2025
  },
  "cite:2501.09674->1f5621f256a973872d0eb8d9d2f9418765db4c73": {
   "arxiv": null,
   "citer_id": "1f5621f256a973872d0eb8d9d2f9418765db4c73",
   "doi": "10.1109/ICAISET66439.2026.11541429",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SATHOS: Self-Adaptive Trust-Hierarchical Orchestration for Zero-Trust DevSecOps Pipelines",
   "year": 2026
  },
  "cite:2501.09674->233ec59da6ec77d324b33714687e7892f2b154c0": {
   "arxiv": "2511.15712",
   "citer_id": "233ec59da6ec77d324b33714687e7892f2b154c0",
   "doi": "10.48550/arXiv.2511.15712",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Secure Autonomous Agent Payments: Verifying Authenticity and Intent in a Trustless Environment",
   "year": 2025
  },
  "cite:2501.09674->2a1cd6442ea44b870ee3dbe42668568c1fae6f3d": {
   "arxiv": "2608.02670",
   "citer_id": "2a1cd6442ea44b870ee3dbe42668568c1fae6f3d",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Permission Denied: Policy-Graded Evaluation of Coding Agents in Hardened Environments",
   "year": 2026
  },
  "cite:2501.09674->2b1846ddf3d9a941c9d769ff192ce9cb5f1068de": {
   "arxiv": null,
   "citer_id": "2b1846ddf3d9a941c9d769ff192ce9cb5f1068de",
   "doi": "10.1109/TIFS.2025.3636051",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Benchmarking Selective Disclosure Mechanisms for Verifiable Credentials: A Systematic Comparison for Security and Privacy",
   "year": 2025
  },
  "cite:2501.09674->2caa2524ab54a25cf5d16730d00bf0202fab9d3b": {
   "arxiv": "2605.30169",
   "citer_id": "2caa2524ab54a25cf5d16730d00bf0202fab9d3b",
   "doi": "10.1145/3805689.3806748",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Dissociative Identity: Language Model Agents Lack Grounding for Reputation Mechanisms",
   "year": 2026
  },
  "cite:2501.09674->38b17cf72ba181feaee93a94e090120f9462f643": {
   "arxiv": "2507.03050",
   "citer_id": "38b17cf72ba181feaee93a94e090120f9462f643",
   "doi": "10.48550/arXiv.2507.03050",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "From Turing to Tomorrow: The UK's Approach to AI Regulation",
   "year": 2025
  },
  "cite:2501.09674->3b29cb1aebb232e94c5659ee4894d0289a94d7ae": {
   "arxiv": "2603.02960",
   "citer_id": "3b29cb1aebb232e94c5659ee4894d0289a94d7ae",
   "doi": "10.48550/arXiv.2603.02960",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Architecting Trust in Artificial Epistemic Agents",
   "year": 2026
  },
  "cite:2501.09674->3b778cfbf9d8a3b551922ad29fcf58252c965de0": {
   "arxiv": "2603.09875",
   "citer_id": "3b778cfbf9d8a3b551922ad29fcf58252c965de0",
   "doi": "10.48550/arXiv.2603.09875",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "The Bureaucracy of Speed: Structural Equivalence Between Memory Consistency Models and Multi-Agent Authorization Revocation",
   "year": 2026
  },
  "cite:2501.09674->42f72ac33420e70238cddc2eb3a13d5e3c8ed647": {
   "arxiv": "2607.05743",
   "citer_id": "42f72ac33420e70238cddc2eb3a13d5e3c8ed647",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities",
   "year": 2026
  },
  "cite:2501.09674->45becfd7748559a13de6fce8d4af451c6154d31d": {
   "arxiv": "2509.07131",
   "citer_id": "45becfd7748559a13de6fce8d4af451c6154d31d",
   "doi": "10.1109/BCCA66705.2025.11229689",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SoK: Security and Privacy of AI Agents for Blockchain",
   "year": 2025
  },
  "cite:2501.09674->51e9cee091a345f430d7a6c3a10e210af4f0a182": {
   "arxiv": "2608.13787",
   "citer_id": "51e9cee091a345f430d7a6c3a10e210af4f0a182",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "From Passive Delegates to Strategic Negotiators: Reinforcing Social Reasoning in Small Language Models with SocialRL",
   "year": 2026
  },
  "cite:2501.09674->611967b1b2ddbee4b308451d4ae958f0ac78eb93": {
   "arxiv": "2506.01055",
   "citer_id": "611967b1b2ddbee4b308451d4ae958f0ac78eb93",
   "doi": "10.48550/arXiv.2506.01055",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution",
   "year": 2025
  },
  "cite:2501.09674->61d7b194a134a29264bd86af2d8d18c742b43533": {
   "arxiv": "2506.23978",
   "citer_id": "61d7b194a134a29264bd86af2d8d18c742b43533",
   "doi": "10.48550/arXiv.2506.23978",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "LLM Agents Are the Antidote to Walled Gardens",
   "year": 2025
  },
  "cite:2501.09674->643e64fd77cb9a2b2defd63769af75a92365a6c7": {
   "arxiv": "2504.21034",
   "citer_id": "643e64fd77cb9a2b2defd63769af75a92365a6c7",
   "doi": "10.48550/arXiv.2504.21034",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SAGA: A Security Architecture for Governing AI Agentic Systems",
   "year": 2025
  },
  "cite:2501.09674->6615bc788791948e8b66b54d50499573846b0e78": {
   "arxiv": null,
   "citer_id": "6615bc788791948e8b66b54d50499573846b0e78",
   "doi": "10.1109/ICAISET66439.2026.11541783",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Future-Proofing Identity Security for Agentic AI Systems: Design, Implementation, and Evaluation of an Identity Fabric",
   "year": 2026
  },
  "cite:2501.09674->6d4eb9782c6707c9e66229532f451e5ee0facd7e": {
   "arxiv": "2512.11147",
   "citer_id": "6d4eb9782c6707c9e66229532f451e5ee0facd7e",
   "doi": "10.48550/arXiv.2512.11147",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents",
   "year": 2025
  },
  "cite:2501.09674->6e2208e4502c078c83dbf62a1ae78ed81fd4332c": {
   "arxiv": "2606.19464",
   "citer_id": "6e2208e4502c078c83dbf62a1ae78ed81fd4332c",
   "doi": "10.48550/arXiv.2606.19464",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Deontic Policies for Runtime Governance of Agentic AI Systems",
   "year": 2026
  },
  "cite:2501.09674->72277967da194800869fb20a4b9f73132b9929f8": {
   "arxiv": "2608.10530",
   "citer_id": "72277967da194800869fb20a4b9f73132b9929f8",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models",
   "year": 2026
  },
  "cite:2501.09674->753736d18fa9bf3ed730836b30b89bf5653cd8dd": {
   "arxiv": "2506.04133",
   "citer_id": "753736d18fa9bf3ed730836b30b89bf5653cd8dd",
   "doi": "10.48550/arXiv.2506.04133",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "TRiSM for Agentic AI: A Review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems",
   "year": 2025
  },
  "cite:2501.09674->7888d7a57a8370e3701169737171ccef029ee7dd": {
   "arxiv": "2607.04613",
   "citer_id": "7888d7a57a8370e3701169737171ccef029ee7dd",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Governed Individuation: Cryptographically Decoupling an Agent's Learning from Its Authority",
   "year": 2026
  },
  "cite:2501.09674->7a3c09b2711b035c3e277873f5f5a5a20a4540c9": {
   "arxiv": "2606.10711",
   "citer_id": "7a3c09b2711b035c3e277873f5f5a5a20a4540c9",
   "doi": "10.48550/arXiv.2606.10711",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "The Agentic Web Requires New Normative Infrastructure",
   "year": 2026
  },
  "cite:2501.09674->7b2266e6418b4e797cbb0d8981ff89b2d5d678a2": {
   "arxiv": "2608.05884",
   "citer_id": "7b2266e6418b4e797cbb0d8981ff89b2d5d678a2",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents",
   "year": 2026
  },
  "cite:2501.09674->7dd78ffd9b1729532efc71ab68ff42512b9c0120": {
   "arxiv": "2509.01619",
   "citer_id": "7dd78ffd9b1729532efc71ab68ff42512b9c0120",
   "doi": "10.48550/arXiv.2509.01619",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Throttling Web Agents Using Reasoning Gates",
   "year": 2025
  },
  "cite:2501.09674->7e132acee9903a3e2bd1eeda5a470f3737d05811": {
   "arxiv": "2601.05293",
   "citer_id": "7e132acee9903a3e2bd1eeda5a470f3737d05811",
   "doi": "10.48550/arXiv.2601.05293",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes",
   "year": 2026
  },
  "cite:2501.09674->7ecc29f022a91f4c428f62b47e905dc6452cc1ba": {
   "arxiv": "2512.17538",
   "citer_id": "7ecc29f022a91f4c428f62b47e905dc6452cc1ba",
   "doi": "10.48550/arXiv.2512.17538",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility",
   "year": 2025
  },
  "cite:2501.09674->7f6ef1fffbbde46dbffd032d034301f5a02f3888": {
   "arxiv": "2608.22160",
   "citer_id": "7f6ef1fffbbde46dbffd032d034301f5a02f3888",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "AUDITA: certified auditing and causal attribution of adverse outcomes in autonomous multi-agent systems",
   "year": 2026
  },
  "cite:2501.09674->81fc46b1cbb0ac4d4b3759e1e3f06201bed0efcc": {
   "arxiv": "2604.07695",
   "citer_id": "81fc46b1cbb0ac4d4b3759e1e3f06201bed0efcc",
   "doi": "10.48550/arXiv.2604.07695",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "AITH: A Post-Quantum Continuous Delegation Protocol for Human-AI Trust Establishment",
   "year": 2026
  },
  "cite:2501.09674->82d86909fb32cdab5085eab4c56ae5d267304e5a": {
   "arxiv": "2512.00520",
   "citer_id": "82d86909fb32cdab5085eab4c56ae5d267304e5a",
   "doi": "10.48550/arXiv.2512.00520",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Toward a Safe Internet of Agents",
   "year": 2025
  },
  "cite:2501.09674->863d969b6f3df1d4f298544edc5fe01ab782e17a": {
   "arxiv": "2605.19035",
   "citer_id": "863d969b6f3df1d4f298544edc5fe01ab782e17a",
   "doi": "10.1145/3770855.3818655",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Trustworthy Agent Network: Trust in Agent Networks Must Be Baked In, Not Bolted On",
   "year": 2026
  },
  "cite:2501.09674->8f8a50833248cff72c40a454fe8bf01608ee1498": {
   "arxiv": "2608.13030",
   "citer_id": "8f8a50833248cff72c40a454fe8bf01608ee1498",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents",
   "year": 2026
  },
  "cite:2501.09674->9b68f0d922062d21b68fb1679cf2c6c3a95e5b37": {
   "arxiv": null,
   "citer_id": "9b68f0d922062d21b68fb1679cf2c6c3a95e5b37",
   "doi": "10.3390/fi18080437",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Computational Jurisprudence: Verifiable Law for Machine Societies",
   "year": 2026
  },
  "cite:2501.09674->9d3aa11e8b6f7c4a49c9a11e35425ec38abe2c28": {
   "arxiv": "2601.02371",
   "citer_id": "9d3aa11e8b6f7c4a49c9a11e35425ec38abe2c28",
   "doi": "10.48550/arXiv.2601.02371",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Permission Manifests for Web Agents",
   "year": 2025
  },
  "cite:2501.09674->9e4d6eee1c39b1f4a5caea4d754ecfb34381750f": {
   "arxiv": null,
   "citer_id": "9e4d6eee1c39b1f4a5caea4d754ecfb34381750f",
   "doi": "10.1109/ICAISET66439.2026.11542102",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "AgentQE-Bench: A Reproducible Evaluation Framework for Agentic AI Reliability, Safety, and ROI in CI/CD Pipelines",
   "year": 2026
  },
  "cite:2501.09674->a0188584e1d1ef10f18fa881d8cebd6db6a69d72": {
   "arxiv": "2608.15888",
   "citer_id": "a0188584e1d1ef10f18fa881d8cebd6db6a69d72",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Bounded Agents: Delegation Security for Multi-Agent AI Systems",
   "year": 2026
  },
  "cite:2501.09674->a4fde6109b763df06eeb6c280d38c4d4a53ae004": {
   "arxiv": "2605.14859",
   "citer_id": "a4fde6109b763df06eeb6c280d38c4d4a53ae004",
   "doi": "10.48550/arXiv.2605.14859",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Do Coding Agents Understand Least-Privilege Authorization?",
   "year": 2026
  },
  "cite:2501.09674->a90ce8648a4fa7e6d460085846c1cf36120caabd": {
   "arxiv": "2511.02841",
   "citer_id": "a90ce8648a4fa7e6d460085846c1cf36120caabd",
   "doi": "10.5220/0014234400004052",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "AI Agents with Decentralized Identifiers and Verifiable Credentials",
   "year": 2025
  },
  "cite:2501.09674->b4b23d4feb241798555e2fe7826f737f484213ba": {
   "arxiv": "2506.12469",
   "citer_id": "b4b23d4feb241798555e2fe7826f737f484213ba",
   "doi": "10.48550/arXiv.2506.12469",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Levels of Autonomy for AI Agents",
   "year": 2025
  },
  "cite:2501.09674->b8d1704e8d47a48e6c2319680bc7cd2f00643516": {
   "arxiv": "2605.16300",
   "citer_id": "b8d1704e8d47a48e6c2319680bc7cd2f00643516",
   "doi": "10.48550/arXiv.2605.16300",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Consent Chain Degradation in Embodied Multi-Agent Systems: Bridging the Gap Between AI Agent Governance and Robot Ethics",
   "year": 2026
  },
  "cite:2501.09674->bb3609d213296d9abd95dd718093259be5283234": {
   "arxiv": null,
   "citer_id": "bb3609d213296d9abd95dd718093259be5283234",
   "doi": "10.1109/SoutheastCon63549.2026.11476129",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Risk-Adaptive Authorization for Agentic AI Systems",
   "year": 2026
  },
  "cite:2501.09674->bea9a935b9afd77165a56463d95053bfea430987": {
   "arxiv": null,
   "citer_id": "bea9a935b9afd77165a56463d95053bfea430987",
   "doi": "10.1007/s00146-026-03034-5",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Reinterpreting agency theory in the era of artificial intelligence: conceptualizing delegated agency",
   "year": 2026
  },
  "cite:2501.09674->bfbc4873584f1daec31589d58a53607db6e2e170": {
   "arxiv": "2505.02077",
   "citer_id": "bfbc4873584f1daec31589d58a53607db6e2e170",
   "doi": "10.48550/arXiv.2505.02077",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents",
   "year": 2025
  },
  "cite:2501.09674->c482e9aa341ecd5dbf545aa16df9c6815aa55650": {
   "arxiv": "2510.25819",
   "citer_id": "c482e9aa341ecd5dbf545aa16df9c6815aa55650",
   "doi": "10.48550/arXiv.2510.25819",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Identity Management for Agentic AI: The new frontier of authorization, authentication, and security for an AI agent world",
   "year": 2025
  },
  "cite:2501.09674->cb407f1400394f4a1514749c2c92308726685ae9": {
   "arxiv": "2605.12364",
   "citer_id": "cb407f1400394f4a1514749c2c92308726685ae9",
   "doi": "10.48550/arXiv.2605.12364",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Attacks and Mitigations for Distributed Governance of Agentic AI under Byzantine Adversaries",
   "year": 2026
  },
  "cite:2501.09674->ccb3444b4fa96f96161ca62a28c5f71f234197b6": {
   "arxiv": "2503.15515",
   "citer_id": "ccb3444b4fa96f96161ca62a28c5f71f234197b6",
   "doi": "10.48550/arXiv.2503.15515",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Towards Computer-Using Personal Agents",
   "year": 2025
  },
  "cite:2501.09674->cd83e13fe7afc55b197bd2f4d2d55eb31490cde5": {
   "arxiv": "2604.02767",
   "citer_id": "cd83e13fe7afc55b197bd2f4d2d55eb31490cde5",
   "doi": "10.48550/arXiv.2604.02767",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems",
   "year": 2026
  },
  "cite:2501.09674->d15ccfc4498dbe4810cfe80855ed27a1a4d0c3df": {
   "arxiv": "2603.15799",
   "citer_id": "d15ccfc4498dbe4810cfe80855ed27a1a4d0c3df",
   "doi": "10.48550/arXiv.2603.15799",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Prose2Policy (P2P): A Practical LLM Pipeline for Translating Natural-Language Access Policies into Executable Rego",
   "year": 2026
  },
  "cite:2501.09674->d513cef205d67a4b7c11e45809536969641f0655": {
   "arxiv": null,
   "citer_id": "d513cef205d67a4b7c11e45809536969641f0655",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Robust AI Personalization via The Human Context Protocol",
   "year": null
  },
  "cite:2501.09674->dc02945d8c923d7afb895d26a862e29d94cf04c0": {
   "arxiv": "2605.10481",
   "citer_id": "dc02945d8c923d7afb895d26a862e29d94cf04c0",
   "doi": "10.48550/arXiv.2605.10481",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems",
   "year": 2026
  },
  "cite:2501.09674->ddb80279086bae918b89be825041d878725394f0": {
   "arxiv": "2606.22916",
   "citer_id": "ddb80279086bae918b89be825041d878725394f0",
   "doi": "10.48550/arXiv.2606.22916",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Intent-Governed Tool Authorization for AI Agents",
   "year": 2026
  },
  "cite:2501.09674->e665c4bbc454de8ffcf98bd92f6da212cf3780b1": {
   "arxiv": "2606.30246",
   "citer_id": "e665c4bbc454de8ffcf98bd92f6da212cf3780b1",
   "doi": "10.48550/arXiv.2606.30246",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Clarus: Coordinating Autonomous Research Agents toward Web-Scale Scientific Collaboration",
   "year": 2026
  },
  "cite:2501.09674->e81bb5ae6b1173e48dbab2b7757f9a1a788e7477": {
   "arxiv": "2505.12490",
   "citer_id": "e81bb5ae6b1173e48dbab2b7757f9a1a788e7477",
   "doi": "10.1145/3821216",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Improving Google A2A Protocol: Protecting Sensitive Data and Mitigating Unintended Harms in Multi-Agent Systems",
   "year": 2025
  },
  "cite:2501.09674->ea6cb8ccd76b6d87130cbcfcedb7c2d97a194c99": {
   "arxiv": null,
   "citer_id": "ea6cb8ccd76b6d87130cbcfcedb7c2d97a194c99",
   "doi": "10.2139/ssrn.5403981",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Robust AI Personalization Will Require a Human Context Protocol",
   "year": 2025
  },
  "cite:2501.09674->f4086c8ed9c8ed000ae61eef3866f577f0f713c3": {
   "arxiv": null,
   "citer_id": "f4086c8ed9c8ed000ae61eef3866f577f0f713c3",
   "doi": "10.1109/ICCA66035.2025.11431026",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "SPIFFE-Based Zero-Trust Authentication for AI Agent Ecosystems",
   "year": 2025
  },
  "cite:2501.09674->f552c32a5932fcc156254ae7138aee3db02e1088": {
   "arxiv": "2605.22333",
   "citer_id": "f552c32a5932fcc156254ae7138aee3db02e1088",
   "doi": "10.48550/arXiv.2605.22333",
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "A First Measurement Study on Authentication Security in Real-World Remote MCP Servers",
   "year": 2026
  },
  "cite:2501.09674->f75be6c71ff0afe0758a552a156909d13f736d82": {
   "arxiv": "2607.10712",
   "citer_id": "f75be6c71ff0afe0758a552a156909d13f736d82",
   "doi": null,
   "hub": "2501.09674",
   "kind": "forward_citation",
   "title": "Distributed Denial of Science: How Indirect Data Poisoning of AI Systems Can Industrialize Scientific Fraud",
   "year": 2026
  },
  "cite:2604.23280->306be845bca3d17ed41b6d6e3ed85c298d4b974f": {
   "arxiv": "2608.26696",
   "citer_id": "306be845bca3d17ed41b6d6e3ed85c298d4b974f",
   "doi": null,
   "hub": "2604.23280",
   "kind": "forward_citation",
   "title": "Five Primitives for Governing Autonomous AI Agents at Runtime",
   "year": 2026
  },
  "cite:2604.23280->7e3f035505fe7034cfed6bec3f633e705faaaee8": {
   "arxiv": "2608.25474",
   "citer_id": "7e3f035505fe7034cfed6bec3f633e705faaaee8",
   "doi": null,
   "hub": "2604.23280",
   "kind": "forward_citation",
   "title": "Separating Disclosure from Authorization: Field-Tier Minimization for Agent Action Mediation",
   "year": 2026
  },
  "cite:2604.23280->c7a29e07095c9e336b2a5b22ef9200d1da0aa014": {
   "arxiv": "2607.20729",
   "citer_id": "c7a29e07095c9e336b2a5b22ef9200d1da0aa014",
   "doi": null,
   "hub": "2604.23280",
   "kind": "forward_citation",
   "title": "Operational Identity: A Finite Audit of Declared and Implemented Rules of Sameness",
   "year": 2026
  },
  "cite:2604.23280->d01f73ee8c7ef4328f47dd219013f9be420b128c": {
   "arxiv": "2608.22512",
   "citer_id": "d01f73ee8c7ef4328f47dd219013f9be420b128c",
   "doi": null,
   "hub": "2604.23280",
   "kind": "forward_citation",
   "title": "HANSARD: A Reference Architecture for Forensic Readiness, Runtime Witnessing, and Graded Attribution in Autonomous Multi-Agent AI Systems",
   "year": 2026
  }
 },
 "surface": "papers"
}
