{"work":{"id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","openalex_id":"https://openalex.org/W4411337880","doi":"10.1109/sp61157.2025.00250","arxiv_id":"2302.12173","raw_key":null,"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","authors":null,"authors_text":"Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Mario Fritz","year":2023,"venue":"cs.CR","abstract":"Large Language Models (LLMs) are increasingly being integrated into various applications. The functionalities of recent LLMs can be flexibly modulated via natural language prompts. This renders them susceptible to targeted adversarial prompting, e.g., Prompt Injection (PI) attacks enable attackers to override original instructions and employed controls. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We argue that LLM-Integrated Applications blur the line between data and instructions. We reveal new attack vectors, using Indirect Prompt Injection, that enable adversaries to remotely (without a direct interface) exploit LLM-integrated applications by strategically injecting prompts into data likely to be retrieved. We derive a comprehensive taxonomy from a computer security perspective to systematically investigate impacts and vulnerabilities, including data theft, worming, information ecosystem contamination, and other novel security risks. We demonstrate our attacks' practical viability against both real-world systems, such as Bing's GPT-4 powered Chat and code-completion engines, and synthetic applications built on GPT-4. We show how processing retrieved prompts can act as arbitrary code execution, manipulate the application's functionality, and control how and if other APIs are called. Despite the increasing integration and reliance on LLMs, effective mitigations of these emerging threats are currently lacking. By raising awareness of these vulnerabilities and providing key insights into their implications, we aim to promote the safe and responsible deployment of these powerful models and the development of robust defenses that protect users and systems from potential attacks.","external_url":"https://arxiv.org/abs/2302.12173","cited_by_count":7,"metadata_source":"pith","metadata_fetched_at":"2026-08-05T02:28:24.338817+00:00","pith_arxiv_id":"2302.12173","created_at":"2026-05-09T06:55:44.492516+00:00","updated_at":"2026-08-05T02:28:24.338817+00:00","title_quality_ok":true,"display_title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","render_title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection"},"hub":{"state":{"work_id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","tier":"super_hub","tier_reason":"100+ Pith inbound or 10,000+ external citations","pith_inbound_count":110,"external_cited_by_count":7,"distinct_field_count":11,"first_pith_cited_at":"2023-07-05T17:58:10+00:00","last_pith_cited_at":"2026-07-09T12:18:40+00:00","author_build_status":"needed","summary_status":"needed","contexts_status":"needed","graph_status":"needed","ask_index_status":"needed","reader_status":"not_needed","recognition_status":"not_needed","updated_at":"2026-08-23T00:59:26.933793+00:00","tier_text":"super_hub"},"tier":"super_hub","role_counts":[{"context_role":"background","n":15},{"context_role":"baseline","n":2}],"polarity_counts":[{"context_polarity":"background","n":14},{"context_polarity":"baseline","n":2},{"context_polarity":"support","n":1}],"runs":{"ask_index":{"job_type":"ask_index","status":"succeeded","result":{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","claims":[{"claim_text":"Large Language Models (LLMs) are increasingly being integrated into various applications. The functionalities of recent LLMs can be flexibly modulated via natural language prompts. This renders them susceptible to targeted adversarial prompting, e.g., Prompt Injection (PI) attacks enable attackers to override original instructions and employed controls. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We argue that LLM-Integrated Applications blur the line between data and instructions. We reveal new attack vectors, using Indirect P","claim_type":"abstract","evidence_strength":"source_metadata"},{"claim_text":"RAGLog [123] Semi-Sup No BGL, Thunderbird No F1 RAG Model XRAGLog [201] Semi-Sup No HDFS, BGL, ThunderbirdYes F1 GPT-3.5 Hybrid & Collaborative (Small Model + Large Model) LLMeLog [47] Supervised Yes HDFS, BGL, ThunderbirdYes F1 ChatGPT + BERT LogFormer [43] Supervised Yes HDFS, BGL, TB, GAIA No F1 S-BERT + ChatGPT CLogLLM [139] Unsup Yes HDFS, BGL, ThunderbirdNo F1 Qwen + GPT-3.5 LogLLM [41] Supervised Yes HDFS, BGL, TB, Liberty No F1 BERT + LLaMA-3 AdaptiveLog [104] Supervised Yes BGL, Thunder","claim_type":"baseline","confidence":0.95,"evidence_strength":"citation_context"},{"claim_text":"Both admit content from group channels, email gateways, fetched URLs, shared documents, and imported memory into the same memory and skill stores their paired- DM sessions consult, and expose filesystem and shell capa- bilities under the owner's identity. Existing prompt-injection literature treats these capabilities one at a time: indirect injec- tion in a single turn [3], single-session web-tool agents [4], memory-only persistence in one runtime [5], training-time backdoors [6]. None treats th","claim_type":"background","confidence":0.95,"evidence_strength":"citation_context"},{"claim_text":"At the per-stream level, for each individual stream, we verify that: (1) the stream is free of malformed tokens, garbled characters, or unexpected special symbols introduced during tokenization and de-tokenization; (2) the text is linguistically fluent and coherent without abrupt breaks; (3) the stream does not contain redundant or repetitive content; and (4) for the assistant stream specifically, the concatenated response adequately addresses the user's question without omission or hallucinatio","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"International Conference on Learning Representations, 2025. doi: 10.48550/arXiv.2410.09024. URLhttps://arxiv.org/abs/2410.09024. Anthropic. Introducing Claude Sonnet 4.5, 2025. URL https://www.anthropic.com/news/ claude-sonnet-4-5. Official product announcement. Tim Berners-Lee, James Hendler, and Ora Lassila. The semantic web.Scientific American, 284(5): 34-43, 2001. URLhttps://www.scientificamerican.com/article/the-semantic-web/. Edoardo Debenedetti, Jie Zhang, Mislav Balunovi'c, Luca Beurer-K","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"beyond the \"on-the-fly\" paradigm to navigate effectively. 1 Introduction AI agents today can exhibit striking failures, e.g., deleting an entire inbox when asked to remove a confidential message [19]; erasing a codebase to \"fix\" an authorization issue [43]; and compromising developers' machines because of a single GitHub title containing a prompt injection [23]. This recalls the web and software landscape of two decades ago, when frequent crashes and SQL injection attacks made reliability and se","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"RAGLog [123] Semi-Sup No BGL, Thunderbird No F1 RAG Model XRAGLog [201] Semi-Sup No HDFS, BGL, ThunderbirdYes F1 GPT-3.5 Hybrid & Collaborative (Small Model + Large Model) LLMeLog [47] Supervised Yes HDFS, BGL, ThunderbirdYes F1 ChatGPT + BERT LogFormer [43] Supervised Yes HDFS, BGL, TB, GAIA No F1 S-BERT + ChatGPT CLogLLM [139] Unsup Yes HDFS, BGL, ThunderbirdNo F1 Qwen + GPT-3.5 LogLLM [41] Supervised Yes HDFS, BGL, TB, Liberty No F1 BERT + LLaMA-3 AdaptiveLog [104] Supervised Yes BGL, Thunder","claim_type":"baseline","confidence":0.85,"evidence_strength":"citation_context"}],"why_cited":"Pith tracks Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection because it crossed a citation-hub threshold. Current citing contexts most often use it as background evidence (15 contexts).","role_counts":[{"n":15,"context_role":"background"},{"n":2,"context_role":"baseline"}]},"error":null,"updated_at":"2026-07-04T00:56:14.936290+00:00"},"author_expand":{"job_type":"author_expand","status":"succeeded","result":{"authors_linked":[{"id":"dc5d5343-95a0-47bc-b7ad-bd51c93091e7","orcid":null,"display_name":"Kai Greshake"},{"id":"5c61e930-789f-4841-abe0-867e9c2ec954","orcid":null,"display_name":"Sahar Abdelnabi"},{"id":"2a50b49b-83e1-4965-ae1f-a87e698bde0c","orcid":null,"display_name":"Shailesh Mishra"},{"id":"a64014f8-d5d9-46fc-a8b0-881fae679f49","orcid":null,"display_name":"Christoph Endres"},{"id":"94182073-eecb-4406-9a46-b266f0086c40","orcid":null,"display_name":"Thorsten Holz"},{"id":"deba94d7-8c2f-4bd0-9c94-0061188322a1","orcid":null,"display_name":"Mario Fritz"}]},"error":null,"updated_at":"2026-07-04T00:56:15.967199+00:00"},"context_extract":{"job_type":"context_extract","status":"succeeded","result":{"enqueued_papers":25},"error":null,"updated_at":"2026-05-14T18:10:21.144945+00:00"},"graph_features":{"job_type":"graph_features","status":"succeeded","result":{"co_cited":[{"title":"Ignore Previous Prompt: Attack Techniques For Language Models","work_id":"a7c5b6ec-3407-4330-96c8-3fc58e7d410b","shared_citers":11},{"title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","work_id":"93844332-869b-448c-a1be-35466150b1b2","shared_citers":7},{"title":"Prompt Injection attack against LLM-integrated Applications","work_id":"977b4683-bba6-49d6-8f3d-496c41cb7fac","shared_citers":7},{"title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","shared_citers":7},{"title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","work_id":"5cbfcda4-ec26-44e4-be60-e1525956d71d","shared_citers":6},{"title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","work_id":"7b1b672f-e6b4-4df9-aa8b-3396a2eb8b16","shared_citers":5},{"title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","shared_citers":5},{"title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","shared_citers":5},{"title":"Constitutional AI: Harmlessness from AI Feedback","work_id":"faaaa4e0-2676-4fac-a0b4-99aef10d2095","shared_citers":5},{"title":"Defeating Prompt Injections by Design","work_id":"86405b86-1c51-4042-9b04-aff0b6541411","shared_citers":5},{"title":"ReAct: Synergizing Reasoning and Acting in Language Models","work_id":"407a2351-25f1-497d-b611-f77d0292a8e6","shared_citers":5},{"title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","work_id":"3322fa86-1768-4677-8425-dd326b45e078","shared_citers":5},{"title":"Agentspec: Customizable runtime enforcement for safe and reliable llm agents","work_id":"2d265b31-7dcb-4ab3-8c83-e13bd5598435","shared_citers":4},{"title":"Defending against indirect prompt injection attacks with spotlighting","work_id":"c18cd975-e731-4e0f-a99f-a37d846cdd31","shared_citers":4},{"title":"The Rise and Potential of Large Language Model Based Agents: A Survey","work_id":"985ca219-7e34-4c4f-bdc5-ccd39763ad61","shared_citers":4},{"title":"Toolformer: Language Models Can Teach Themselves to Use Tools","work_id":"9bce40c8-cfd7-4983-80e0-c3bd4402322a","shared_citers":4},{"title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","shared_citers":3},{"title":"AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation","work_id":"92b7eb9c-c3d8-4518-a376-06fa15dd895b","shared_citers":3},{"title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","work_id":"db5870ca-177b-4d1d-a08d-ee5ceab17fe3","shared_citers":3},{"title":"Detecting language model attacks with perplexity","work_id":"8fac4469-dd8b-4784-9ff6-13d2e74e57fb","shared_citers":3},{"title":"Formal Policy Enforcement for Real-World Agentic Systems","work_id":"dc0c6fb4-ef13-485c-8109-a5a138684d7e","shared_citers":3},{"title":"Gorilla: Large Language Model Connected with Massive APIs","work_id":"126a464a-4a73-495f-b669-de1e44aa8f09","shared_citers":3},{"title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","work_id":"3d4c3b66-d749-4939-b1bc-62b10b2ebbb6","shared_citers":3},{"title":"MemGPT: Towards LLMs as Operating Systems","work_id":"2698f5ad-c84c-40ca-b839-0912dae10ba2","shared_citers":3}],"time_series":[{"n":1,"year":2023},{"n":33,"year":2026}],"dependency_candidates":[]},"error":null,"updated_at":"2026-05-14T18:09:51.217487+00:00"},"identity_refresh":{"job_type":"identity_refresh","status":"succeeded","result":{"items":[{"title":"Qwen3 Technical Report","outcome":"unchanged","work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e","resolver":"local_arxiv","confidence":0.98,"old_work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e"}],"counts":{"fixed":0,"merged":0,"unchanged":1,"quarantined":0,"needs_external_resolution":0},"errors":[],"attempted":1},"error":null,"updated_at":"2026-05-14T18:10:04.681988+00:00"},"role_polarity":{"job_type":"role_polarity","status":"succeeded","result":{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","claims":[{"claim_text":"Large Language Models (LLMs) are increasingly being integrated into various applications. The functionalities of recent LLMs can be flexibly modulated via natural language prompts. This renders them susceptible to targeted adversarial prompting, e.g., Prompt Injection (PI) attacks enable attackers to override original instructions and employed controls. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We argue that LLM-Integrated Applications blur the line between data and instructions. We reveal new attack vectors, using Indirect P","claim_type":"abstract","evidence_strength":"source_metadata"},{"claim_text":"RAGLog [123] Semi-Sup No BGL, Thunderbird No F1 RAG Model XRAGLog [201] Semi-Sup No HDFS, BGL, ThunderbirdYes F1 GPT-3.5 Hybrid & Collaborative (Small Model + Large Model) LLMeLog [47] Supervised Yes HDFS, BGL, ThunderbirdYes F1 ChatGPT + BERT LogFormer [43] Supervised Yes HDFS, BGL, TB, GAIA No F1 S-BERT + ChatGPT CLogLLM [139] Unsup Yes HDFS, BGL, ThunderbirdNo F1 Qwen + GPT-3.5 LogLLM [41] Supervised Yes HDFS, BGL, TB, Liberty No F1 BERT + LLaMA-3 AdaptiveLog [104] Supervised Yes BGL, Thunder","claim_type":"baseline","confidence":0.95,"evidence_strength":"citation_context"},{"claim_text":"Both admit content from group channels, email gateways, fetched URLs, shared documents, and imported memory into the same memory and skill stores their paired- DM sessions consult, and expose filesystem and shell capa- bilities under the owner's identity. Existing prompt-injection literature treats these capabilities one at a time: indirect injec- tion in a single turn [3], single-session web-tool agents [4], memory-only persistence in one runtime [5], training-time backdoors [6]. None treats th","claim_type":"background","confidence":0.95,"evidence_strength":"citation_context"},{"claim_text":"At the per-stream level, for each individual stream, we verify that: (1) the stream is free of malformed tokens, garbled characters, or unexpected special symbols introduced during tokenization and de-tokenization; (2) the text is linguistically fluent and coherent without abrupt breaks; (3) the stream does not contain redundant or repetitive content; and (4) for the assistant stream specifically, the concatenated response adequately addresses the user's question without omission or hallucinatio","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"International Conference on Learning Representations, 2025. doi: 10.48550/arXiv.2410.09024. URLhttps://arxiv.org/abs/2410.09024. Anthropic. Introducing Claude Sonnet 4.5, 2025. URL https://www.anthropic.com/news/ claude-sonnet-4-5. Official product announcement. Tim Berners-Lee, James Hendler, and Ora Lassila. The semantic web.Scientific American, 284(5): 34-43, 2001. URLhttps://www.scientificamerican.com/article/the-semantic-web/. Edoardo Debenedetti, Jie Zhang, Mislav Balunovi'c, Luca Beurer-K","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"beyond the \"on-the-fly\" paradigm to navigate effectively. 1 Introduction AI agents today can exhibit striking failures, e.g., deleting an entire inbox when asked to remove a confidential message [19]; erasing a codebase to \"fix\" an authorization issue [43]; and compromising developers' machines because of a single GitHub title containing a prompt injection [23]. This recalls the web and software landscape of two decades ago, when frequent crashes and SQL injection attacks made reliability and se","claim_type":"background","confidence":0.9,"evidence_strength":"citation_context"},{"claim_text":"RAGLog [123] Semi-Sup No BGL, Thunderbird No F1 RAG Model XRAGLog [201] Semi-Sup No HDFS, BGL, ThunderbirdYes F1 GPT-3.5 Hybrid & Collaborative (Small Model + Large Model) LLMeLog [47] Supervised Yes HDFS, BGL, ThunderbirdYes F1 ChatGPT + BERT LogFormer [43] Supervised Yes HDFS, BGL, TB, GAIA No F1 S-BERT + ChatGPT CLogLLM [139] Unsup Yes HDFS, BGL, ThunderbirdNo F1 Qwen + GPT-3.5 LogLLM [41] Supervised Yes HDFS, BGL, TB, Liberty No F1 BERT + LLaMA-3 AdaptiveLog [104] Supervised Yes BGL, Thunder","claim_type":"baseline","confidence":0.85,"evidence_strength":"citation_context"}],"why_cited":"Pith tracks Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection because it crossed a citation-hub threshold. Current citing contexts most often use it as background evidence (15 contexts).","role_counts":[{"n":15,"context_role":"background"},{"n":2,"context_role":"baseline"}]},"error":null,"updated_at":"2026-07-04T00:56:14.774412+00:00"},"summary_claims":{"job_type":"summary_claims","status":"succeeded","result":{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","claims":[{"claim_text":"Large Language Models (LLMs) are increasingly being integrated into various applications. The functionalities of recent LLMs can be flexibly modulated via natural language prompts. This renders them susceptible to targeted adversarial prompting, e.g., Prompt Injection (PI) attacks enable attackers to override original instructions and employed controls. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We argue that LLM-Integrated Applications blur the line between data and instructions. We reveal new attack vectors, using Indirect P","claim_type":"abstract","evidence_strength":"source_metadata"}],"why_cited":"Pith tracks Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection because it crossed a citation-hub threshold.","role_counts":[]},"error":null,"updated_at":"2026-05-14T18:10:09.142611+00:00"}},"summary":{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","claims":[{"claim_text":"Large Language Models (LLMs) are increasingly being integrated into various applications. The functionalities of recent LLMs can be flexibly modulated via natural language prompts. This renders them susceptible to targeted adversarial prompting, e.g., Prompt Injection (PI) attacks enable attackers to override original instructions and employed controls. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We argue that LLM-Integrated Applications blur the line between data and instructions. We reveal new attack vectors, using Indirect P","claim_type":"abstract","evidence_strength":"source_metadata"}],"why_cited":"Pith tracks Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection because it crossed a citation-hub threshold.","role_counts":[]},"graph":{"co_cited":[{"title":"Ignore Previous Prompt: Attack Techniques For Language Models","work_id":"a7c5b6ec-3407-4330-96c8-3fc58e7d410b","shared_citers":11},{"title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","work_id":"93844332-869b-448c-a1be-35466150b1b2","shared_citers":7},{"title":"Prompt Injection attack against LLM-integrated Applications","work_id":"977b4683-bba6-49d6-8f3d-496c41cb7fac","shared_citers":7},{"title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","shared_citers":7},{"title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","work_id":"5cbfcda4-ec26-44e4-be60-e1525956d71d","shared_citers":6},{"title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","work_id":"7b1b672f-e6b4-4df9-aa8b-3396a2eb8b16","shared_citers":5},{"title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","shared_citers":5},{"title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","shared_citers":5},{"title":"Constitutional AI: Harmlessness from AI Feedback","work_id":"faaaa4e0-2676-4fac-a0b4-99aef10d2095","shared_citers":5},{"title":"Defeating Prompt Injections by Design","work_id":"86405b86-1c51-4042-9b04-aff0b6541411","shared_citers":5},{"title":"ReAct: Synergizing Reasoning and Acting in Language Models","work_id":"407a2351-25f1-497d-b611-f77d0292a8e6","shared_citers":5},{"title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","work_id":"3322fa86-1768-4677-8425-dd326b45e078","shared_citers":5},{"title":"Agentspec: Customizable runtime enforcement for safe and reliable llm agents","work_id":"2d265b31-7dcb-4ab3-8c83-e13bd5598435","shared_citers":4},{"title":"Defending against indirect prompt injection attacks with spotlighting","work_id":"c18cd975-e731-4e0f-a99f-a37d846cdd31","shared_citers":4},{"title":"The Rise and Potential of Large Language Model Based Agents: A Survey","work_id":"985ca219-7e34-4c4f-bdc5-ccd39763ad61","shared_citers":4},{"title":"Toolformer: Language Models Can Teach Themselves to Use Tools","work_id":"9bce40c8-cfd7-4983-80e0-c3bd4402322a","shared_citers":4},{"title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","shared_citers":3},{"title":"AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation","work_id":"92b7eb9c-c3d8-4518-a376-06fa15dd895b","shared_citers":3},{"title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","work_id":"db5870ca-177b-4d1d-a08d-ee5ceab17fe3","shared_citers":3},{"title":"Detecting language model attacks with perplexity","work_id":"8fac4469-dd8b-4784-9ff6-13d2e74e57fb","shared_citers":3},{"title":"Formal Policy Enforcement for Real-World Agentic Systems","work_id":"dc0c6fb4-ef13-485c-8109-a5a138684d7e","shared_citers":3},{"title":"Gorilla: Large Language Model Connected with Massive APIs","work_id":"126a464a-4a73-495f-b669-de1e44aa8f09","shared_citers":3},{"title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","work_id":"3d4c3b66-d749-4939-b1bc-62b10b2ebbb6","shared_citers":3},{"title":"MemGPT: Towards LLMs as Operating Systems","work_id":"2698f5ad-c84c-40ca-b839-0912dae10ba2","shared_citers":3}],"time_series":[{"n":1,"year":2023},{"n":33,"year":2026}],"dependency_candidates":[]},"authors":[{"id":"a64014f8-d5d9-46fc-a8b0-881fae679f49","orcid":null,"display_name":"Christoph Endres","source":"manual","import_confidence":0.72},{"id":"dc5d5343-95a0-47bc-b7ad-bd51c93091e7","orcid":null,"display_name":"Kai Greshake","source":"manual","import_confidence":0.72},{"id":"deba94d7-8c2f-4bd0-9c94-0061188322a1","orcid":null,"display_name":"Mario Fritz","source":"manual","import_confidence":0.72},{"id":"5c61e930-789f-4841-abe0-867e9c2ec954","orcid":null,"display_name":"Sahar Abdelnabi","source":"manual","import_confidence":0.72},{"id":"2a50b49b-83e1-4965-ae1f-a87e698bde0c","orcid":null,"display_name":"Shailesh Mishra","source":"manual","import_confidence":0.72},{"id":"94182073-eecb-4406-9a46-b266f0086c40","orcid":null,"display_name":"Thorsten Holz","source":"manual","import_confidence":0.72}]}}