AdvML-Frontiers × CoTMA: From Model Security to Compositional Threats in Multi-Agent AI Systems
Abstract
The AdvML-Frontiers × CoTMA workshop is a cross-community effort that unifies two complementary workshop brands: AdvML-Frontiers and CoTMA (Compositional Threats in Multi-Agent AI Systems). As foundation models evolve from standalone predictors into reusable assets and interconnected multi-agent systems, the adversarial surface of AI has expanded far beyond traditional input-output robustness. Building on the AdvML-Frontiers theme, the workshop focuses on securing frontier models both as valuable assets and as complex systems. This includes emerging security challenges surrounding provenance, watermarking, fingerprinting, unauthorized distillation, supply-chain attacks, model integrity, reasoning-time intervention, and system-level robustness. Complementing this perspective, CoTMA focuses on compositional and interaction-layer threats in multi-agent AI systems, where vulnerabilities emerge through communication, delegation, shared memory, tool use, and coordination among agents. By bridging these two themes, AdvML-Frontiers × CoTMA aims to advance a broader vision of AI security and safety for interconnected, evolving, and deployable AI ecosystems, while fostering collaboration across adversarial ML, foundation models, systems security, and agentic AI communities.