04:00
2026-07-21
arxiv.org
ai-safety
PlanFlip: Attacking Multi-Agent LLM Systems via Planning-Phase Prompt Injection
A new study from arXiv reveals that multi-agent LLM systems are vulnerable to planning-phase prompt injection attacks, with GPT-5 achieving the highest attack success rate (ASR = 0.68) across 3,479 epโฆ