Pith. sign in

Paper Citation Record · LEDGER

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

As of 18 August 2026, this Paper Citation Record lists 39 of 39 outbound references and 27 inbound Pith citation observations for arXiv:2502.05174.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.05174 v4

Coverage vector

measured 39 of 39 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-08T20:06:58.396831Z

measured 66 of 66 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 27 of 27 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-14T04:23:15.028834Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

39 of 39 outbound references displayed

  • verified exact0
  • verified fuzzy17
  • unresolved22
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bf1d06bc-9a3e-448a-8ba7-829bd0768f4e · outbound

This paper cites write newline.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents write newline

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.210635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.210635Z digest=sha256:9f337c10bbc8857ae40bfc064aa48238eeb1235dd4a89a42fd9fdace8090043c

Observation dea9f8ed-8631-4d93-a512-34e00a5d8c8f · outbound

This paper cites https://learnprompting.org/docs/prompt_hacking/defensive_measures/sandwich_defense, 2023.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents https://learnprompting.org/docs/prompt_hacking/defensive_measures/sandwich_defense, 2023

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.975034Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.216987Z digest=sha256:d9d6fd6fa8a027eb96a49a37df176b76e3a84706745c25716eff5864e509af2c

Observation 7b77f22d-bffb-416f-a020-46cc078078a2 · outbound

This paper cites Claude 3.5 models and computer use, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Claude 3.5 models and computer use, 2024

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.961017Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.222289Z digest=sha256:4ff9da306627965df201f7c8291a107307f71b9a4d66cb50e3a39eabb543b27b

Observation b80735f8-ab6a-4cc9-9bf5-ddab069b1e30 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents StruQ: Defending Against Prompt Injection with Structured Queries

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.227628Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.227628Z digest=sha256:9790676e0e8a564e682c77917fb1f330faf15bcfb5b497dfaf235cc23ad862af

Observation 9dae070a-56be-4e5f-b63a-539284747a04 · outbound

This paper cites SecAlign: Defending Against Prompt Injection with Preference Optimization.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents SecAlign: Defending Against Prompt Injection with Preference Optimization

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.233116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.233116Z digest=sha256:d34808e941f68604044d0747978e9a5555aeed1a11b476956773bcc44b0d2622

Observation 84b70a05-e67c-4f99-960d-baf286abf793 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.946981Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.238658Z digest=sha256:79e14a3526b3c3faa10351d78a23c6dbc94babbef07f5fcf33e40f9478eb5cbc

Observation 292d00cc-2e23-4846-914f-3dc3ae942497 · outbound

This paper cites Deepseek function calling guide.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Deepseek function calling guide

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.932465Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.243672Z digest=sha256:455cf2a78c8d588c6b26ccfc500a09f09299572b76fed4a76f163d9a67d12590

Observation 223ee63e-2043-45f2-bff2-5f55c802e61d · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.248872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.248872Z digest=sha256:9554de46045da78124b47cd8172312d226d758bd90c7d4bcd9d700317130bec1

Observation b1dc6c89-9d97-48be-a6eb-b3b54354f6ec · outbound

This paper cites Attention Tracker: Detecting Prompt Injection Attacks in LLMs.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attention Tracker: Detecting Prompt Injection Attacks in LLMs

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.253925Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.253925Z digest=sha256:e7adba3177297795a4bb812b473e82e42638c7db72bd4c6df1cf29ae7b6c93f3

Observation 6975a179-af4f-48af-95dc-e328b3791da9 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.258918Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.258918Z digest=sha256:d22541d79067c88376adcc0e1e3f9179f290fbb61c8fa9b2047ca644c2148416

Observation 81c623e0-dee3-419b-9334-f00aa2f7ef84 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.263834Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.263834Z digest=sha256:ac6974a3a057aa30523103aeb61bf021101aba62ede51bafeff96d7b27097f72

Observation f927fbde-b04d-4b53-8ffb-d1a5ce0c29d2 · outbound

This paper cites an unresolved cited work.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-08T20:06:58.917814Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.269070Z digest=sha256:fdf9e07ec00121c36c72d80445fe8f1f37f8478fe8e173e2a6f32972d0890e79

Observation 2958124b-7daa-4ad6-9b3d-69e447113e6f · outbound

This paper cites Llama3.3 model cards, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama3.3 model cards, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.902871Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.273661Z digest=sha256:55c7caa116bc3d2291fc6667ba04250c02c90b64168de14fd4d9759c48e92fc9

Observation 2300653e-959b-4b9f-81f3-71f10a7ff7dc · outbound

This paper cites Ultimate ChatGPT prompt engineering guide for general users and developers.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ultimate ChatGPT prompt engineering guide for general users and developers

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.888824Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.278368Z digest=sha256:322d5d5a4328b606381003451454d9cda2df17bb8b8938fe6308fae5599a2891

Observation 3c8a0ba8-6613-4941-80b3-81b203a0e047 · outbound

This paper cites Testing Language Model Agents Safely in the Wild.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Testing Language Model Agents Safely in the Wild

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.282814Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.282814Z digest=sha256:da5b5c576d93defa23089ab485f3dc0a2547911ffc10753536d811978a9bb125

Observation e8786f57-27dc-434f-9fea-c06eba48afa7 · outbound

This paper cites Openai text embeddings, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai text embeddings, 2024

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.874469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.287513Z digest=sha256:6792e33618192346fdbabeaea4be24e7a9549fd0458e6b4b16691a04ae922374

Observation 4d3cfb36-3fbd-498f-a0ef-efef24db98f6 · outbound

This paper cites Openai function calling guide, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai function calling guide, 2024

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.859955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.292137Z digest=sha256:0e886891864f7f76c02da6c323d2a3aa5c908604f84d3874162acf5e634d0159

Observation ed056a33-5c43-4096-9f46-5aad6e97aea0 · outbound

This paper cites GoEX: Perspectives and Designs Towards a Runtime for Autonomous LLM Applications.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents GoEX: Perspectives and Designs Towards a Runtime for Autonomous LLM Applications

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.296667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.296667Z digest=sha256:5195894c727517fe4f3207b1aae9f50fc6d384dfc1f5a0d8f9d507b4695e8cde

Observation 15640117-b63f-482d-acfd-5ba149c2421a · outbound

This paper cites and Ribeiro, I.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents and Ribeiro, I

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.844863Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.301706Z digest=sha256:7017c496923784b53141f23fa1cbac6ab279003e7e04094ba0fa56302d45f24d

Observation fa310591-321c-4cb8-9946-08b5fb4d3ea7 · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.829647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.306771Z digest=sha256:b755d8ed16d09c6fc971576f44af3424ccccb5cc43cdda9a8ad55d174208951b

Observation b9f42e10-c581-4f3f-9cea-e68f9267f892 · outbound

This paper cites J., and Hashimoto, T.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents J., and Hashimoto, T

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.813875Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.311563Z digest=sha256:bad393f6c1d3508a9807784b3d66ee42cd848a5300b20025ac6086668c153e1d

Observation bab47efd-26d4-4e4e-87e7-df91a32a3d55 · outbound

This paper cites Ignore this title and H ack AP rompt: Exposing systemic vulnerabilities of LLM s through a global prompt hacking competition.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ignore this title and H ack AP rompt: Exposing systemic vulnerabilities of LLM s through a global prompt hacking competition

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.316068Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.316068Z digest=sha256:45a39d1c93623d7810d6c12071f1d3412f19f85682def77648e815f8629103d5

Observation f52a6040-3dc9-475a-a901-78344b38a012 · outbound

This paper cites A., Svegliato, J., Bailey, L., Wang, T., Ong, I., Elmaaroufi, K., Abbeel, P., Darrell, T., Ritter, A., and Russell, S.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A., Svegliato, J., Bailey, L., Wang, T., Ong, I., Elmaaroufi, K., Abbeel, P., Darrell, T., Ritter, A., and Russell, S

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.798731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.321013Z digest=sha256:cbe2154e3d0520228b6d370710862f2ddb63092fe5c8ac2356d0774e334cb010

Observation ee407b4a-e4f6-47c2-b901-5d6f7b07b83b · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.325586Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.325586Z digest=sha256:08857eceb8bc8b6882186ea69953743945a4e0059ed9a3c23ab3f952e9deb0f6

Observation 6b492243-a40a-46b2-99eb-196c045e6598 · outbound

This paper cites Prompt injection attacks against GPT-3.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Prompt injection attacks against GPT-3

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.782338Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.330790Z digest=sha256:2597270eaecb8a98d0d006c369c07f0ae7ac4d752c305a6ad0abd65ba6e2cf73

Observation f2a6f917-3765-4e79-9c51-501658165f08 · outbound

This paper cites Delimiters won’t save you from prompt injection.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Delimiters won’t save you from prompt injection

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.767633Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.335473Z digest=sha256:7619c8502577080c0d0ce8138ba9bdcaeda4ddf8b707ccaebede1233ba5dc12c

Observation 6a90feb9-8f8c-46df-9d07-11fed6300970 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.339855Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.339855Z digest=sha256:9d953167e9e3e0b106f38d558b8ae9780d1538951e85d5b5836506f0c7f742ff

Observation 90c09a10-0c7b-4026-acca-d88284c82bed · outbound

This paper cites System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.344908Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.344908Z digest=sha256:7017433b823c6e5fac09dac5d6d01f69375fc08571870d295a3e4306472f6ba1

Observation 3d187030-68c4-41d5-8272-38aaf24193f0 · outbound

This paper cites A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.349652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.349652Z digest=sha256:3c5569dffe4f9a7c0f70b7e93e76ef3f3f93f0f775a77548c41fce8372c3239d

Observation f395f473-974b-4c1b-90aa-e96b3dcf682c · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.752762Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.354320Z digest=sha256:aebb6e4f56d190f38f1231caba75d29b27468cc832c3c17e115ffd4bbe38a39f

Observation 51c834a0-bcc7-4ef8-ae66-97d23a97fdcf · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.358737Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.358737Z digest=sha256:4179f787a2efe256c2d4b9ddd64229ca1808c80f38ea2e4ebf40fbd97f1c14b4

Observation a54c5ddd-84e9-4792-90b9-959a80102c65 · outbound

This paper cites Assessing Prompt Injection Risks in 200+ Custom GPTs.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Assessing Prompt Injection Risks in 200+ Custom GPTs

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.363694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.363694Z digest=sha256:7648aad944f5523e49c4af5d9598d8af454ea8c501ea2512b06a01b264e34dab

Observation 9728db56-fcdf-4bc8-9110-f538457876f7 · outbound

This paper cites R-judge: Benchmarking safety risk awareness for LLM agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents R-judge: Benchmarking safety risk awareness for LLM agents

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.737887Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.368510Z digest=sha256:f8146ecafe5db8b8fde83e2b304feae5f9034c5b1ee65115887ca44df18d5f89

Observation b9ef8ef5-a886-4dba-b054-fc56eaea1a55 · outbound

This paper cites I njec A gent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents I njec A gent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.372999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.372999Z digest=sha256:feba3ea3f2e0b5f1fac39a7d6c6d2eac706a2c75d3e330d5d2a7b82a90453d5b

Observation 68c84e93-8235-4f7b-91ac-d9b1d83476b2 · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.377603Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.377603Z digest=sha256:610366a2907f18c6def732390d18b786804bbfcf4cb79107b60c0d2c2c097597

Observation 4dbf589f-f2cd-4380-a814-c3ac8c22a68a · outbound

This paper cites Attacking vision-language computer agents via pop-ups, 2024 b.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attacking vision-language computer agents via pop-ups, 2024 b

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.722556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.382660Z digest=sha256:8877cd23c386933aa5ea0a1f262b03fa3a0a42cf4936e59ae8831e19e8a8ad3f

Observation 6e8a3080-e8a4-4803-9599-75eaf82c2e79 · outbound

This paper cites Poisoning retrieval corpora by injecting adversarial passages.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Poisoning retrieval corpora by injecting adversarial passages

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.387249Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.387249Z digest=sha256:e9fa96eca044802b12d60b8c5bd07d5cf474c92509f58372b7f7adfd6bab075e

Observation 2ec90ab3-1ff6-4bcb-9c8a-40b346d24fd5 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.391995Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.391995Z digest=sha256:995183fd959f68e71414c4cd6275a05d1449587f28af5dd711a9ed60a306c47f

Observation 27efaa9a-50aa-4e30-87aa-399eeb3fc73b · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.396831Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.396831Z digest=sha256:b14fe2f7c73112647b14efd749e458c40533993df795a4dcc4ad602a67fdba79

Pith citing papers

Observation bc0da62c-e2b2-4b9e-9729-d62b6bba9bf5 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.071951Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:f0b8ad1a03915d2112fe88a802c52ffd363cb7eb0f3b43494f59c04bef96fa88

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · inbound

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment cites this paper.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:cc94a7a91d327d2dae27737f3c416735053b96cbb2c6fc462aa67be568322725

Observation f04d6e3a-abbb-4b23-900d-a43dd7764acf · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 72

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.076283Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:be7906d66373ea954e5bd2fd6d2535f32c0051a985558a3da45c7d10e42d2470

Observation 83db55d0-db33-4d19-ae2a-643819ab73e1 · inbound

Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection cites this paper.

Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T15:20:17.375618Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-21T15:18:58.274360Z digest=sha256:f17d90a9b70da8cadc0f534af44c576715f9b801c93e4c1c6cd4eea60b3a7346

Observation eaa09e39-4804-40ab-97b3-d721ad91f20f · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-10T11:55:21.358611Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-10T04:42:33.450658Z digest=sha256:e21f91655a6464ac10dc6928193b1308f30edf9c4423733dc0f08ab19a10b3ce

Observation dc536703-e33e-4e4c-810f-60d43b326d45 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-21T00:53:53.086682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-21T00:51:22.907932Z digest=sha256:fef241543423975e6fdbd0397ab3292534e561bd9872cc322c23afd7da8f5550

Observation 27bc2e11-4352-471d-ba9a-ac370452f911 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T15:56:49.153150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:56:49.153150Z digest=sha256:cb54e05c178d112abed5e4f53c56f0601bc212e54dc864bbd93c7800f4ab2ebf

Observation af9bf477-2843-42a9-acb7-81f110a10627 · inbound

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cites this paper.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.500382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:0cfcbd610e6703520314217c59d31a98dd3b28e878f85d92aa25ffb527707434

Observation 27d2da28-7187-47eb-9ce5-535bf8f5b342 · inbound

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization cites this paper.

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-08T17:53:53.269765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-08T17:49:39.533090Z digest=sha256:0b1669adc02b40ffb892ea088b528eee0212306220c5ae7b1802a15c46b6a7ab

Observation e4adebc1-6504-4c7c-8f20-a8d6b2fd0806 · inbound

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection cites this paper.

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:56:13.752504Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-05-07T15:59:49.513500Z digest=sha256:2c15192f9d45d80a86a4110c99506f296efc8b07ea09c522bdce361748b86615

Observation b5f50e10-3b71-4af1-8562-22cb40fb556b · inbound

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents cites this paper.

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:32:02.602437Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-13T01:31:34.468389Z digest=sha256:e840de6aaf32749a70e57eefe8de0b02fa1704efabc66919aec615cb87e1c7bf

Observation e8a283c1-48e1-42d5-9cd8-fe9247005d92 · inbound

The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck cites this paper.

The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:32:02.864173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-13T01:31:13.100257Z digest=sha256:3f45ce24fb46b6a454f03286b0258c9b38d180da3ca2423d52c2e7125bb8fc60

Observation 692f3850-3a5e-4ad4-8cad-e516b7b8185c · inbound

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection cites this paper.

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-20T10:03:14.260886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-20T10:03:05.696380Z digest=sha256:a7d57e12420164a8a89355de2e3271a04003c59a1af0cc76589b014d6908996f

Observation 91bae419-35f8-4a06-987b-eadb178dd4bf · inbound

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection cites this paper.

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-06-30T18:55:00.614674Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-30T18:48:32.929392Z digest=sha256:d1d478e427dcd03858ef7dec75df3495f284927938ce0465bb1f6be9d616dca4

Observation dc44d31b-78bd-47b2-8f94-db0762f749a9 · inbound

Reframing LLM Agent Security as an Agent-Human Interaction Problem cites this paper.

Reframing LLM Agent Security as an Agent-Human Interaction Problem MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 68

Resolution
verified exact
arxiv_id, observed 2026-06-30T13:54:43.862943Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-30T13:52:06.272229Z digest=sha256:897685e9185f4dbd50c3552e2c2bbf99ecc74ac660c1d3e914204c68bd11368a

Observation 727f71f4-65f5-463d-aabb-c7f8ff8c006b · inbound

AIRGuard: Guarding Agent Actions with Runtime Authority Control cites this paper.

AIRGuard: Guarding Agent Actions with Runtime Authority Control MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-06-29T12:53:27.162560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-06-29T11:27:11.944532Z digest=sha256:9fcf08df407eabe1658d2f1224601220fa83bb58c969ca6bd79d7e2b7720b22d

Observation 7b8f0d67-b24c-4feb-bfce-0496f8f3e59f · inbound

Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity cites this paper.

Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-06-28T22:32:43.991088Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-28T22:30:14.098291Z digest=sha256:d39c4f4ce60852445c4944a42c73b360b09392357b03d562231fad985fdb4d46

Observation 87627205-3b01-4073-870b-ecf8c197cf77 · inbound

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models cites this paper.

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 17

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T19:22:34.416763Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-06-28T19:19:17.673497Z digest=sha256:43cbc9d978edc2ed2515924ffeb44b790a99f7d94115b782d41d5c56454eb7b2

Observation e1954abd-ca21-444a-a120-b1ed758cffee · inbound

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning cites this paper.

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 22

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T04:59:36.379930Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-06-26T16:32:09.625729Z digest=sha256:e332e1621d62dc46a3dc060c9671861033d7829af2784e5d1514ef4d34e7810d

Observation d79a76aa-5e44-4487-b491-db217ecb54fc · inbound

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents cites this paper.

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:09:45.221940Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-26T09:05:22.096955Z digest=sha256:9889637424c6b91cf85a2f21b0245055e041aa8701520ae49c35abeab10b530f

Observation fa054f62-2795-4ad7-98c8-6a2a4f9a53cc · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 43

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:e5842d9fdd89ea52042ca904504008ab6da0615ba50eb1866c2463f45bea4ddd

Observation 8788fdd6-120c-41e7-ba17-e306332bd7e0 · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 51

Resolution
verified exact
local_arxiv, observed 2026-07-11T02:47:50.246193Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:572dda4328b11c7762c780659954e27833c684b653fec023a1a9de19722b85c3

Observation 7409786b-0f30-4634-bcd7-e1b343f720f1 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 206

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.304739Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.304739Z digest=sha256:706da796e4eb95d7daab2327e5fb26419dedb777db821aa43609b9827b9133d1

Observation f2ebbed9-42ad-4d66-a74d-b17e01676a42 · inbound

Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions cites this paper.

Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-04T22:27:22.453591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T22:27:22.453591Z digest=sha256:70e47c1e4669a2fe446e3eb67e83658620497305b44b7da5f0e34969065bae55

Observation 7de49ffb-9ea8-48b1-bdce-4bda27c3e421 · inbound

AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection cites this paper.

AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-08T00:51:38.030612Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T00:51:38.030612Z digest=sha256:3c4c19ecd749754c928dd7903165ddc9a1c041cbd4cda89a0b363d5a461b5bf6

Observation f4992c41-56f8-4f5f-aa4a-0a8bde72ae61 · inbound

Robust Context-Aware Detection of Malicious Instructions in Text cites this paper.

Robust Context-Aware Detection of Malicious Instructions in Text MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-08T13:19:01.988614Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T13:19:01.988614Z digest=sha256:72e50639c22d7925c65de96b71215d4cfb691c60f22d325390f8ece0cb275fc1

Observation 54992195-e40d-41b8-bca5-1cc9f50365a6 · inbound

Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection cites this paper.

Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-14T04:23:15.028834Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-14T04:23:15.028834Z digest=sha256:34bcaf5542b54408306b23741ce3424b227f4afacfa188fee76a9fe95654a2e0