Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 56 inbound Pith citation observations for arXiv:2312.14197.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-08T20:57:43.602204Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z
0 of 0 outbound references displayed
External citation measurements
9
arxiv_reference, observed 2026-08-05T02:28:24.338817Z
No outbound reference observations are available for this paper version.
Observation 97817b41-db3e-41fd-8e9d-f58974c5f7ff · inbound
Defending Against Indirect Prompt Injection Attacks With Spotlighting Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 634df275-c0b3-42b6-993e-17572a6d9b11 · inbound
LLM Agents can Autonomously Exploit One-day Vulnerabilities Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 196cfb2e-0fa5-4054-b31e-bfa081355095 · inbound
The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation d352e1af-4809-454a-9774-144f23f1472d · inbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8e27a0e4-8b48-4c9a-999d-38612545cce3 · inbound
Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 157
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8bcc4d61-5791-4f0f-9293-c6aa22d3d377 · inbound
Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 73
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41a497e6-9ae9-4b69-bfe5-5cc3204fd3a7 · inbound
Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 140
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1bec698a-1e6d-4541-b8ff-39f77ebb7b5b · inbound
IHEval: Evaluating Language Models on Following the Instruction Hierarchy Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6c012428-57fa-4c01-9a96-0fe31bc4bc35 · inbound
Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a00eec65-66f6-4758-a934-70a4f8216626 · inbound
EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ed10cf18-6a79-4b5b-bef3-d9087450a1c8 · inbound
Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3f184b0b-621e-427d-97b3-bcef0124352b · inbound
Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f8bffdc9-cb67-4366-8440-8cd448565bba · inbound
A Critical Evaluation of Defenses against Prompt Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · inbound
LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0693264-866e-4e60-9f8e-589c4dda26a7 · inbound
JavelinGuard: Low-Cost Transformer Architectures for LLM Security Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · inbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 089d26cc-1fdc-429c-99e4-2da7b551d9a5 · inbound
BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · inbound
Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 176dae2d-28d1-42fe-8986-b5645525b5c9 · inbound
WebGuard: Building a Generalizable Guardrail for Web Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1bc81062-1a6c-4fe0-9237-9da26b29fbe2 · inbound
Lexical Hints of Accuracy in LLM Reasoning Chains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f3cba737-1295-4552-94ac-1eadc91f1413 · inbound
Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 538c7225-0d0a-4c6b-ac48-d2634878d9c3 · inbound
When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 35a8932a-22a3-494c-81c9-d86984fec96d · inbound
Many-Tier Instruction Hierarchy in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 21110f35-c167-4750-b0ab-02728ebe78ad · inbound
An AI Agent Execution Environment to Safeguard User Data Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ddf3556a-3549-46ad-a5f2-bdcf15b60da8 · inbound
Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6f2a28f4-9667-48d1-9ac0-280daa79c69f · inbound
Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5cea8fcf-d59d-48f1-89e0-2a4697a3e2a9 · inbound
Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5deca162-d313-4484-9760-fe45fbd8fd38 · inbound
Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 4df578a0-c781-4de1-b581-4a218ecc0751 · inbound
Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5ed01e6b-6fc6-47c6-a027-c680e263f2dc · inbound
MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 94dece42-48ac-4aa4-9809-3eabdf2dff25 · inbound
Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9ecdb9c3-bf96-487c-82c8-3cb9a3d65a2a · inbound
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation d7ea9cee-c29a-424c-a1fc-95159a7899e7 · inbound
Web Agents Should Adopt the Plan-Then-Execute Paradigm Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6d920e85-e211-42f2-9b1c-b84621608982 · inbound
An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 96d1112b-1e1f-4495-906d-adc3117086d0 · inbound
Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9ba8124f-19fb-4857-8068-ac007779b074 · inbound
Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f181d1bb-35c0-4a36-a207-e8d540d349f4 · inbound
From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 555d4ea9-e22d-4319-b0a9-e4c6f1242427 · inbound
Gate AI: LLM Security Benchmark Evaluation Methodology and Results Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 3e4c895e-cfc9-4a55-9b54-7af85df3f8db · inbound
Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 38171ffc-1869-4d10-8738-4d7cc4d694bb · inbound
Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b33c16d6-51a3-4269-abf3-cd2c764d9730 · inbound
Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 39a76038-c48d-4c09-89e8-23658ccc3593 · inbound
Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a20cd9a1-eef5-4e8f-8222-55fe1691cca6 · inbound
MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8d9d6654-035b-4a06-81d5-39432b32e719 · inbound
Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 317cc991-7106-429f-8973-67bdeb1617af · inbound
PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 33fe266d-6331-498b-95b6-950f61ab31a0 · inbound
Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 850b25ab-2f1e-4164-817f-87a33240546e · inbound
A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c2abf31c-073e-42f1-a60a-a9089c3a6ac8 · inbound
Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a47829da-290b-4947-a457-56cd4adcb915 · inbound
Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 882da221-d8ed-4050-bd80-7898a459ec4b · inbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 322d5c44-c7ab-417d-9221-8c2d96b559fe · inbound
Information Discernment in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation db4457de-bbd2-4963-a793-ecef3e38fac2 · inbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 755f590a-9840-4bb8-8040-56b56c73a6aa · inbound
Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6e8d9b35-c683-43d6-a186-a5732b86ad10 · inbound
Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4e0f8e47-dc08-487c-af06-d08f1e1e2669 · inbound
MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6bc4f208-44ae-4ffd-991b-98915cc36574 · inbound
Robust Context-Aware Detection of Malicious Instructions in Text Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.