{"id":"https://openalex.org/W7133339389","doi":"https://doi.org/10.48550/arxiv.2603.00131","title":"Thought Virus: Viral Misalignment via Subliminal Prompting in Multi-Agent Systems","display_name":"Thought Virus: Viral Misalignment via Subliminal Prompting in Multi-Agent Systems","publication_year":2026,"publication_date":"2026-02-23","ids":{"openalex":"https://openalex.org/W7133339389","doi":"https://doi.org/10.48550/arxiv.2603.00131"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.00131","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.00131","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.00131","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5128033507","display_name":"Moritz Weckbecker","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Weckbecker, Moritz","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5127965167","display_name":"Jonas M\u00fcller","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"M\u00fcller, Jonas","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066409021","display_name":"Ben Hagag","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hagag, Ben","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5127980794","display_name":"Michael Mulet","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mulet, Michael","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.17820000648498535,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.17820000648498535,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12380","display_name":"Authorship Attribution and Profiling","score":0.08839999884366989,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.06909999996423721,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/subliminal-stimuli","display_name":"Subliminal stimuli","score":0.9879000186920166},{"id":"https://openalex.org/keywords/phenomenon","display_name":"Phenomenon","score":0.6995000243186951},{"id":"https://openalex.org/keywords/measure","display_name":"Measure (data warehouse)","score":0.36880001425743103},{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.24250000715255737}],"concepts":[{"id":"https://openalex.org/C151496658","wikidata":"https://www.wikidata.org/wiki/Q310661","display_name":"Subliminal stimuli","level":2,"score":0.9879000186920166},{"id":"https://openalex.org/C50335755","wikidata":"https://www.wikidata.org/wiki/Q483247","display_name":"Phenomenon","level":2,"score":0.6995000243186951},{"id":"https://openalex.org/C180747234","wikidata":"https://www.wikidata.org/wiki/Q23373","display_name":"Cognitive psychology","level":1,"score":0.5212000012397766},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.47269999980926514},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.451200008392334},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.36880001425743103},{"id":"https://openalex.org/C46312422","wikidata":"https://www.wikidata.org/wiki/Q11024","display_name":"Communication","level":1,"score":0.29330000281333923},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.27160000801086426},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.25049999356269836},{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.24250000715255737}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.00131","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.00131","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.00131","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.00131","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.43116098642349243}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Subliminal":[0],"prompting":[1,17,28,106,123],"is":[2,145],"a":[3,51,58,108,125],"phenomenon":[4,70],"in":[5,29,35,129],"which":[6],"language":[7],"models":[8],"are":[9],"biased":[10],"towards":[11],"certain":[12],"concepts":[13],"or":[14],"traits":[15],"through":[16],"with":[18,132],"semantically":[19],"unrelated":[20],"tokens.":[21],"While":[22],"prior":[23],"work":[24],"has":[25],"examined":[26],"subliminal":[27,105,122],"user-LLM":[30],"interactions,":[31],"potential":[32,93],"bias":[33,62],"transfer":[34],"multi-agent":[36,130],"systems":[37],"and":[38],"its":[39,64],"associated":[40],"security":[41],"implications":[42,133],"remain":[43],"unexplored.":[44],"In":[45],"this":[46,69],"work,":[47],"we":[48,96],"show":[49],"that":[50,79,104,121],"single":[52,109],"subliminally":[53],"prompted":[54],"agent":[55,110],"can":[56],"spread":[57],"weakening":[59],"but":[60],"persisting":[61],"throughout":[63,88],"entire":[65],"network.":[66,90],"We":[67],"measure":[68],"across":[71],"6":[72],"agents":[73],"using":[74],"two":[75],"different":[76],"topologies,":[77],"observing":[78],"the":[80,89,113,135],"transferred":[81],"concept":[82],"maintains":[83],"an":[84],"elevated":[85],"response":[86],"rate":[87],"To":[91],"exemplify":[92],"misalignment":[94],"risks,":[95],"assess":[97],"network":[98],"performance":[99],"on":[100],"multiple-choice":[101],"TruthfulQA,":[102],"showing":[103],"of":[107,115,137,142],"may":[111],"degrade":[112],"truthfulness":[114],"other":[116],"agents.":[117],"Our":[118],"findings":[119],"reveal":[120],"introduces":[124],"new":[126],"attack":[127],"vector":[128],"security,":[131],"for":[134],"alignment":[136],"such":[138],"systems.":[139],"The":[140],"implementation":[141],"all":[143],"experiments":[144],"publicly":[146],"available":[147],"at":[148],"https://github.com/Multi-Agent-Security-Initiative/thought_virus":[149],".":[150]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-04T00:00:00"}
