{"as_of":"2026-08-10T01:10:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:6fb178ef1668f5f8f287633bd9fdc59cde37eb172382b2fd8cd49621991e9f44","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":56,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":56,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":56,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":56,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-08T20:57:43.602204Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":9,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2403.14720","last_updated":"2024-03-20T15:26:23Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-03-20T15:26:23Z","title":"Defending Against Indirect Prompt Injection Attacks With Spotlighting","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-14T22:28:55.370749Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2403.14720"},"observation_digest":"sha256:624c59d560cd8ce349ef7f6205a10188866376e4ccde3fdc86114b962c54babe","observation_id":"97817b41-db3e-41fd-8e9d-f58974c5f7ff","resolution":{"observed_at":"2026-05-14T22:28:55.424003Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2404.08144","last_updated":"2024-04-17T04:34:39Z","snapshot_observed_at":"2026-08-08T10:18:09.304124Z","submitted_at":"2024-04-11T22:07:19Z","title":"LLM Agents can Autonomously Exploit One-day Vulnerabilities","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-05-18T04:18:27.597704Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2404.08144"},"observation_digest":"sha256:a76eacffd45f7b84ae944d07bfef60c8c33e355c89baca0988e3c93b73ac6830","observation_id":"634df275-c0b3-42b6-993e-17572a6d9b11","resolution":{"observed_at":"2026-05-18T04:18:27.662132Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-02T11:48:17.206729Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-12T10:59:30.728091Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2404.13208"},"observation_digest":"sha256:7c34d2dfa44b831575d3ebecb6bac1279d6c13d18584269ad854f1de1c0deef2","observation_id":"196cfb2e-0fa5-4054-b31e-bfa081355095","resolution":{"observed_at":"2026-05-12T10:59:30.797232Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2406.13352","last_updated":"2024-11-24T22:04:23Z","snapshot_observed_at":"2026-07-06T18:33:32.806635Z","submitted_at":"2024-06-19T08:55:56Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","version":3},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-05-13T06:35:13.331872Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2406.13352"},"observation_digest":"sha256:64574493e16cfc22a2a1c8c9b39a79c3921026b2bd14452a57c44af807c85015","observation_id":"d352e1af-4809-454a-9774-144f23f1472d","resolution":{"observed_at":"2026-05-13T06:35:13.402235Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"reference_index":157,"source":"arxiv_source","source_observed_at":"2026-05-12T13:36:57.011451Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2410.02644"},"observation_digest":"sha256:38cbd04ea5cd9e9b910df47be494bd090ab87a5d5cbfa047ba7c67bd6abbc600","observation_id":"8e27a0e4-8b48-4c9a-999d-38612545cce3","resolution":{"observed_at":"2026-05-12T13:36:57.224615Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-08T20:57:43.602204Z","title":"Bench- marking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.04951","last_updated":"2025-06-13T04:49:36Z","snapshot_observed_at":"2026-08-08T20:49:41.495000Z","submitted_at":"2025-02-07T14:15:46Z","title":"Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search","version":3},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-08T20:57:43.602204Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2502.04951"},"observation_digest":"sha256:ee537ad8bab56987709ce83845b9c084721db00cb3f038ad3445a0e7967fb323","observation_id":"8bcc4d61-5791-4f0f-9293-c6aa22d3d377","resolution":{"observed_at":"2026-08-08T20:57:43.602204Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"reference_index":140,"source":"pdf_text","source_observed_at":"2026-05-23T04:39:04.591722Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2502.05206"},"observation_digest":"sha256:f1fa07308c444a9f72f41d7c136f6cf2e70959f5cd513e1deba856e141b0d11f","observation_id":"41a497e6-9ae9-4b69-bfe5-5cc3204fd3a7","resolution":{"observed_at":"2026-05-23T04:42:34.016624Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T23:56:00.128652Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2502.08745","last_updated":"2025-03-26T20:35:30Z","snapshot_observed_at":"2026-08-08T01:24:44.588510Z","submitted_at":"2025-02-12T19:35:28Z","title":"IHEval: Evaluating Language Models on Following the Instruction Hierarchy","version":2},"reference_index":36,"source":"arxiv_source","source_observed_at":"2026-08-07T23:56:00.128652Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2502.08745"},"observation_digest":"sha256:3619191f6e085ab30af93270103761296731a7426d21d451b3df433876721c3a","observation_id":"1bec698a-1e6d-4541-b8ff-39f77ebb7b5b","resolution":{"observed_at":"2026-08-07T23:56:00.128652Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2504.20472","last_updated":"2026-04-09T06:57:42Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-04-29T07:13:53Z","title":"Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction","version":2},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-05-22T19:10:55.009810Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2504.20472"},"observation_digest":"sha256:3cbdac2fab53b349dc3d02a463be194e59c9225becb24e87d54631503ada7050","observation_id":"6c012428-57fa-4c01-9a96-0fe31bc4bc35","resolution":{"observed_at":"2026-05-22T19:11:58.044991Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T15:41:24.481852Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.14289","last_updated":"2026-06-05T10:24:33Z","snapshot_observed_at":"2026-08-07T15:34:54.479489Z","submitted_at":"2025-05-20T12:41:05Z","title":"EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-07T15:41:24.481852Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2505.14289"},"observation_digest":"sha256:a190ca414ff764c72b99328d7f9bb6d9cf4da021fc7ad774a1b69043d66917b5","observation_id":"a00eec65-66f6-4758-a934-70a4f8216626","resolution":{"observed_at":"2026-08-07T15:41:24.481852Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T15:14:46.395816Z","title":"Benchmarking and defending against indirect prompt injection attacks","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.16014","last_updated":"2026-06-02T10:15:17Z","snapshot_observed_at":"2026-08-09T00:27:14.897803Z","submitted_at":"2025-05-21T20:57:16Z","title":"Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains","version":5},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-08-07T15:14:46.395816Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2505.16014"},"observation_digest":"sha256:5ede886c80e02e77b5c293f20a4dec3076e88b9f6294173112fd05753f179beb","observation_id":"ed10cf18-6a79-4b5b-bef3-d9087450a1c8","resolution":{"observed_at":"2026-08-07T15:14:46.395816Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T14:55:02.679214Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.16957","last_updated":"2025-05-22T17:36:33Z","snapshot_observed_at":"2026-08-09T00:25:53.983420Z","submitted_at":"2025-05-22T17:36:33Z","title":"Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-08-07T14:55:02.679214Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2505.16957"},"observation_digest":"sha256:632ce789339e9a6d94b0d728d5a8ebe65a55bb7559cc0a823a46ab19114289c7","observation_id":"3f184b0b-621e-427d-97b3-bcef0124352b","resolution":{"observed_at":"2026-08-07T14:55:02.679214Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T14:36:12.693088Z","title":"Bench- marking and defending against indirect prompt injection at tacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.18333","last_updated":"2025-05-23T19:39:56Z","snapshot_observed_at":"2026-08-07T14:30:46.734293Z","submitted_at":"2025-05-23T19:39:56Z","title":"A Critical Evaluation of Defenses against Prompt Injection Attacks","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T14:36:12.693088Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2505.18333"},"observation_digest":"sha256:10f2dcc23cdcf7710d4ec907707d8cfc2d17bcf80b4502a0e2d1e09a713463ed","observation_id":"f8bffdc9-cb67-4366-8440-8cd448565bba","resolution":{"observed_at":"2026-08-07T14:36:12.693088Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T12:42:15.984482Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models.arXiv preprint arXiv:2312.14197, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.24019","last_updated":"2025-05-29T21:39:08Z","snapshot_observed_at":"2026-08-07T20:58:14.169872Z","submitted_at":"2025-05-29T21:39:08Z","title":"LLM Agents Should Employ Security Principles","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-07T12:42:15.984482Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2505.24019"},"observation_digest":"sha256:123e05aeec13f18c2afefe71b4d883a6f0986461eec5342acfe58e98b7203fed","observation_id":"54353bad-a6dc-49d0-b7fd-50f97b2bc4ab","resolution":{"observed_at":"2026-08-07T12:42:15.984482Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-07T05:41:25.529733Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.07330","last_updated":"2025-06-09T00:11:06Z","snapshot_observed_at":"2026-08-08T01:51:03.511040Z","submitted_at":"2025-06-09T00:11:06Z","title":"JavelinGuard: Low-Cost Transformer Architectures for LLM Security","version":1},"reference_index":55,"source":"arxiv_source","source_observed_at":"2026-08-07T05:41:25.529733Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2506.07330"},"observation_digest":"sha256:cf568ecdc06361a1225d3e3601382441f4f37de78870910dfbdc73ec4fd7a105","observation_id":"b0693264-866e-4e60-9f8e-589c4dda26a7","resolution":{"observed_at":"2026-08-07T05:41:25.529733Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-06T23:59:59.158675Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models.arXiv preprint arXiv:2312.14197,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.17318","last_updated":"2025-06-18T14:29:02Z","snapshot_observed_at":"2026-08-06T23:52:05.545407Z","submitted_at":"2025-06-18T14:29:02Z","title":"Context manipulation attacks : Web agents are susceptible to corrupted memory","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-06T23:59:59.158675Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2506.17318"},"observation_digest":"sha256:49c288289c291af2a712cf601db2a38bf6c84b4df574972d9cbbee12fca0eb63","observation_id":"3acf0b93-0149-488e-824d-e8f5aa16dca9","resolution":{"observed_at":"2026-08-06T23:59:59.158675Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-06T22:40:38.187097Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.21033","last_updated":"2025-06-26T06:16:33Z","snapshot_observed_at":"2026-08-09T22:24:25.759085Z","submitted_at":"2025-06-26T06:16:33Z","title":"BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-06T22:40:38.187097Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2506.21033"},"observation_digest":"sha256:c3c317fc19057dc1384a9d3d1c0b39354fce25294eac52fdcc228a3f740fc610","observation_id":"089d26cc-1fdc-429c-99e4-2da7b551d9a5","resolution":{"observed_at":"2026-08-06T22:40:38.187097Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-06T16:34:04.277916Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2507.13169","last_updated":"2025-07-17T14:33:36Z","snapshot_observed_at":"2026-08-07T22:34:49.318621Z","submitted_at":"2025-07-17T14:33:36Z","title":"Prompt Injection 2.0: Hybrid AI Threats","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-06T16:34:04.277916Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2507.13169"},"observation_digest":"sha256:7a772ed46e896130c9b3fa17cb7f6a458db0e76dd62cf64a6321cc3ca18c5af8","observation_id":"2783b487-2406-40aa-aff0-c2ebdf3fd4ae","resolution":{"observed_at":"2026-08-06T16:34:04.277916Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-06T16:12:51.333428Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2507.14293","last_updated":"2025-07-18T18:06:27Z","snapshot_observed_at":"2026-08-06T15:57:20.673152Z","submitted_at":"2025-07-18T18:06:27Z","title":"WebGuard: Building a Generalizable Guardrail for Web Agents","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-06T16:12:51.333428Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2507.14293"},"observation_digest":"sha256:22b86b0314e03aa5998f39d744c798b5e799ef6300deca69d9ed3c5ed72e18a9","observation_id":"176dae2d-28d1-42fe-8986-b5645525b5c9","resolution":{"observed_at":"2026-08-06T16:12:51.333428Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T18:48:50.863975Z","title":"Benchmarking and defending against indi- rect prompt injection attacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2508.15842","last_updated":"2025-08-19T18:20:38Z","snapshot_observed_at":"2026-08-07T08:36:52.541508Z","submitted_at":"2025-08-19T18:20:38Z","title":"Lexical Hints of Accuracy in LLM Reasoning Chains","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-05T18:48:50.863975Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2508.15842"},"observation_digest":"sha256:21041c893ec4cc7dcae425c1bc78975724bb2d205d9be0d60825214f4f667743","observation_id":"1bc81062-1a6c-4fe0-9237-9da26b29fbe2","resolution":{"observed_at":"2026-08-05T18:48:50.863975Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T16:50:29.954752Z","title":"arXiv preprint arXiv:2312.14197 (2023)","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2508.19287","last_updated":"2025-08-25T05:20:11Z","snapshot_observed_at":"2026-08-09T06:50:20.259382Z","submitted_at":"2025-08-25T05:20:11Z","title":"Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-05T16:50:29.954752Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2508.19287"},"observation_digest":"sha256:3730749143aaa41dc2974ac56b2e151701af3d37b131c8a62208713916d0f1e6","observation_id":"f3cba737-1295-4552-94ac-1eadc91f1413","resolution":{"observed_at":"2026-08-05T16:50:29.954752Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-02T23:22:38.844788Z","title":"Qiusi Zhan, Zhixiang Liang, Zifan Ying, and Daniel Kang","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2602.14161","last_updated":"2026-07-19T13:10:02Z","snapshot_observed_at":"2026-08-08T04:45:44.090544Z","submitted_at":"2026-02-15T14:21:43Z","title":"When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-02T23:22:38.844788Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2602.14161"},"observation_digest":"sha256:c02062cfbfc04dd9d580f69f2c3bd85f7462ca100db87b44c278a6cd62bd44a5","observation_id":"538c7225-0d0a-4c6b-ac48-d2634878d9c3","resolution":{"observed_at":"2026-08-02T23:22:38.844788Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.09443","last_updated":"2026-04-14T15:04:47Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-10T16:00:04Z","title":"Many-Tier Instruction Hierarchy in LLM Agents","version":3},"reference_index":31,"source":"arxiv_source","source_observed_at":"2026-05-10T17:15:10.392678Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.09443"},"observation_digest":"sha256:d69d627706301c1fcd81ed1cb832ea3b554c409a6a7c09fc23a68f5792d73e2a","observation_id":"35a8932a-22a3-494c-81c9-d86984fec96d","resolution":{"observed_at":"2026-05-11T07:16:01.976213Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.19657","last_updated":"2026-04-21T16:45:30Z","snapshot_observed_at":"2026-07-06T23:06:16.972438Z","submitted_at":"2026-04-21T16:45:30Z","title":"An AI Agent Execution Environment to Safeguard User Data","version":1},"reference_index":82,"source":"pdf_text","source_observed_at":"2026-05-10T02:14:40.639143Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.19657"},"observation_digest":"sha256:48f574d33c3ff341f3aa1a28c83de4a667f101ef3501c7cdee4e7a0bccfd2fa3","observation_id":"21110f35-c167-4750-b0ab-02728ebe78ad","resolution":{"observed_at":"2026-05-11T13:11:05.750535Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.23374","last_updated":"2026-04-25T16:39:16Z","snapshot_observed_at":"2026-07-06T23:09:38.799345Z","submitted_at":"2026-04-25T16:39:16Z","title":"Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-05-08T08:08:24.524671Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.23374"},"observation_digest":"sha256:b663c2a552e935803a3af02613d04dc73a6cd497457bc774424654e23e8ec5c7","observation_id":"ddf3556a-3549-46ad-a5f2-bdcf15b60da8","resolution":{"observed_at":"2026-05-08T22:39:20.577096Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.23887","last_updated":"2026-05-12T22:23:22Z","snapshot_observed_at":"2026-08-06T06:35:27.092178Z","submitted_at":"2026-04-26T21:22:35Z","title":"Evaluation of Prompt Injection Defenses in Large Language Models","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-05-08T05:50:20.608166Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.23887"},"observation_digest":"sha256:b92436650f162a08e5089fcc2931478a1dc58931fa2c8f5c876a129064bdd91e","observation_id":"6f2a28f4-9667-48d1-9ac0-280daa79c69f","resolution":{"observed_at":"2026-05-11T21:21:12.079621Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.23887","last_updated":"2026-05-12T22:23:22Z","snapshot_observed_at":"2026-08-06T06:35:27.092178Z","submitted_at":"2026-04-26T21:22:35Z","title":"Evaluation of Prompt Injection Defenses in Large Language Models","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-05-14T21:05:23.800356Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.23887"},"observation_digest":"sha256:0a67ab176ba89aa4bda909e96b034bb62f1a31824509c5911af903ba08c8c26a","observation_id":"5cea8fcf-d59d-48f1-89e0-2a4697a3e2a9","resolution":{"observed_at":"2026-05-14T21:19:28.460702Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2604.25109","last_updated":"2026-04-28T01:32:27Z","snapshot_observed_at":"2026-07-06T23:11:02.043135Z","submitted_at":"2026-04-28T01:32:27Z","title":"Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-05-07T16:22:49.737626Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2604.25109"},"observation_digest":"sha256:c1d1d9774062da0ec789c25cbdd969975c4ea4a73af436f4bbbebebcb5a49546","observation_id":"5deca162-d313-4484-9760-fe45fbd8fd38","resolution":{"observed_at":"2026-05-11T23:46:15.850426Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.02236","last_updated":"2026-05-05T08:03:21Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-05-04T05:16:43Z","title":"Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-05-08T19:17:06.375875Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.02236"},"observation_digest":"sha256:76e7bd0b04e1df1b6415c327e5de997a9ac7530a9d4aeb8e5780bcff1ed1879c","observation_id":"4df578a0-c781-4de1-b581-4a218ecc0751","resolution":{"observed_at":"2026-05-09T05:55:31.844341Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.07269","last_updated":"2026-05-08T05:34:28Z","snapshot_observed_at":"2026-07-06T23:19:41.053744Z","submitted_at":"2026-05-08T05:34:28Z","title":"MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-11T02:29:13.992357Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.07269"},"observation_digest":"sha256:40609f0e2f94481b9c0588235b41f3c8bd3a3181eb192fbb5fbc6f4ae560e2c8","observation_id":"5ed01e6b-6fc6-47c6-a027-c680e263f2dc","resolution":{"observed_at":"2026-05-11T02:30:55.043183Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.08258","last_updated":"2026-05-07T21:42:43Z","snapshot_observed_at":"2026-07-06T23:20:28.875586Z","submitted_at":"2026-05-07T21:42:43Z","title":"Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-05-12T01:28:08.332456Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.08258"},"observation_digest":"sha256:d106cef54e8f2e812eb2b63018af07fedb6ee6263155ab770f424fe5f7209f30","observation_id":"94dece42-48ac-4aa4-9809-3eabdf2dff25","resolution":{"observed_at":"2026-05-12T07:56:31.056812Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.11868","last_updated":"2026-05-12T09:48:53Z","snapshot_observed_at":"2026-07-06T23:23:39.723268Z","submitted_at":"2026-05-12T09:48:53Z","title":"IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-13T05:46:07.132408Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.11868"},"observation_digest":"sha256:2307a5cbba0aea4bc8f2639ffc4820b441330af48ba30019945f79a91f511e6e","observation_id":"9ecdb9c3-bf96-487c-82c8-3cb9a3d65a2a","resolution":{"observed_at":"2026-05-13T05:47:21.316847Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.14290","last_updated":"2026-05-14T02:48:57Z","snapshot_observed_at":"2026-08-03T04:50:16.568616Z","submitted_at":"2026-05-14T02:48:57Z","title":"Web Agents Should Adopt the Plan-Then-Execute Paradigm","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-05-15T02:42:05.644536Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.14290"},"observation_digest":"sha256:8ac904495e657c924288d9d46317dab586c79d40a8f44445ec261d0db129494e","observation_id":"d7ea9cee-c29a-424c-a1fc-95159a7899e7","resolution":{"observed_at":"2026-05-15T02:49:41.559958Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.18133","last_updated":"2026-05-18T09:38:18Z","snapshot_observed_at":"2026-07-06T23:29:04.241654Z","submitted_at":"2026-05-18T09:38:18Z","title":"An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-05-20T09:58:05.349147Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.18133"},"observation_digest":"sha256:e9be6238aea71cb61ef830b6cfbcca7510db9a0ad05a4cc673fa1ef0924a1a11","observation_id":"6d920e85-e211-42f2-9b1c-b84621608982","resolution":{"observed_at":"2026-05-20T09:58:10.879410Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.19192","last_updated":"2026-05-20T21:49:08Z","snapshot_observed_at":"2026-08-03T06:06:31.296336Z","submitted_at":"2026-05-18T23:40:43Z","title":"Hallucination as Exploit: Evidence-Carrying Multimodal Agents","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-05-20T09:46:42.413501Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.19192"},"observation_digest":"sha256:b6028ce702df7af41988cb663c2f3b1f115cfcf6b07824daad01d32156449ea4","observation_id":"96d1112b-1e1f-4495-906d-adc3117086d0","resolution":{"observed_at":"2026-05-20T09:48:11.595740Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.19192","last_updated":"2026-05-20T21:49:08Z","snapshot_observed_at":"2026-08-03T06:06:31.296336Z","submitted_at":"2026-05-18T23:40:43Z","title":"Hallucination as Exploit: Evidence-Carrying Multimodal Agents","version":2},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-05-22T08:57:29.491043Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.19192"},"observation_digest":"sha256:53c3bda653941806c9e96c7c07c5761881d9965ea88a6f857c256f97971a9858","observation_id":"9ba8124f-19fb-4857-8068-ac007779b074","resolution":{"observed_at":"2026-05-22T09:01:20.110761Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2605.31042","last_updated":"2026-05-29T09:19:07Z","snapshot_observed_at":"2026-07-06T23:40:17.605034Z","submitted_at":"2026-05-29T09:19:07Z","title":"From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-06-28T22:06:41.245543Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2605.31042"},"observation_digest":"sha256:f479917a29719f860a95619c4e143c9e424c952c3a7ec4d54e32d2c4960058bf","observation_id":"f181d1bb-35c0-4a36-a207-e8d540d349f4","resolution":{"observed_at":"2026-06-28T22:12:41.463500Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.02959","last_updated":"2026-06-01T23:29:58Z","snapshot_observed_at":"2026-08-05T09:07:58.107278Z","submitted_at":"2026-06-01T23:29:58Z","title":"Gate AI: LLM Security Benchmark Evaluation Methodology and Results","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-06-28T15:05:08.411286Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.02959"},"observation_digest":"sha256:0a7615dfce1d0278bab36008c3f39c1917e3865267c98cc0b27254c9b172ac86","observation_id":"555d4ea9-e22d-4319-b0a9-e4c6f1242427","resolution":{"observed_at":"2026-07-01T22:46:19.188961Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.04109","last_updated":"2026-06-08T04:40:12Z","snapshot_observed_at":"2026-08-07T20:39:01.290780Z","submitted_at":"2026-06-02T18:12:57Z","title":"Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-28T10:13:48.860754Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.04109"},"observation_digest":"sha256:5afc9785964110779213d73433a363403e6a5a74c786fd408c9ea2e30ebe5967","observation_id":"3e4c895e-cfc9-4a55-9b54-7af85df3f8db","resolution":{"observed_at":"2026-07-02T03:16:33.675784Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.04141","last_updated":"2026-06-02T18:53:17Z","snapshot_observed_at":"2026-08-02T13:02:03.082813Z","submitted_at":"2026-06-02T18:53:17Z","title":"Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-06-28T09:15:57.044886Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.04141"},"observation_digest":"sha256:f4a0983fef5a26bccac21c0ad95e722403400a97edaa0acb666d152a68e35e50","observation_id":"38171ffc-1869-4d10-8738-4d7cc4d694bb","resolution":{"observed_at":"2026-07-02T04:16:36.037768Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.08021","last_updated":"2026-06-06T07:31:04Z","snapshot_observed_at":"2026-08-08T11:34:10.009553Z","submitted_at":"2026-06-06T07:31:04Z","title":"Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-06-27T20:15:56.875933Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.08021"},"observation_digest":"sha256:525423ded15f4cdcfec3578b788cadf6719ebd30b7d6626f893c4ffbf476226b","observation_id":"b33c16d6-51a3-4269-abf3-cd2c764d9730","resolution":{"observed_at":"2026-07-02T20:47:22.530818Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.09315","last_updated":"2026-06-08T10:19:34Z","snapshot_observed_at":"2026-07-06T23:48:39.574979Z","submitted_at":"2026-06-08T10:19:34Z","title":"Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-06-27T16:15:47.454172Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.09315"},"observation_digest":"sha256:55b4a3ea3ece0b9661624b8de4f5ed82450e9fe220640f19ff2dd0e64e923193","observation_id":"39a76038-c48d-4c09-89e8-23658ccc3593","resolution":{"observed_at":"2026-07-03T01:47:31.928375Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.10304","last_updated":"2026-06-09T01:45:19Z","snapshot_observed_at":"2026-07-06T23:49:32.647742Z","submitted_at":"2026-06-09T01:45:19Z","title":"MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents","version":1},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-06-27T13:33:24.087333Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.10304"},"observation_digest":"sha256:9312800348ab8f91a529cc9073e2b1dfbc7f6285301c8b68505ea5eb151a84f8","observation_id":"a20cd9a1-eef5-4e8f-8222-55fe1691cca6","resolution":{"observed_at":"2026-07-03T04:57:38.192366Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.10322","last_updated":"2026-06-09T02:18:44Z","snapshot_observed_at":"2026-08-07T13:25:53.329421Z","submitted_at":"2026-06-09T02:18:44Z","title":"Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-06-27T13:05:57.618969Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.10322"},"observation_digest":"sha256:28b6c5769b9ab6ade56a724ef37d6f1aa36bf5f97d954630dfb5200dbc0974cb","observation_id":"8d9d6654-035b-4a06-81d5-39432b32e719","resolution":{"observed_at":"2026-07-03T05:47:41.229355Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-02T11:07:07.442032Z","title":"Hakan Inan, Kartikeya Upasani, Jianfeng Chi, Rashi Rungta, Krithika Iyer, Yuning Mao, Michael Tontchev, Qing Hu, Brian Fuller, Davide Testuggine, and Madian Khabsa","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2606.17467","last_updated":"2026-07-21T14:56:46Z","snapshot_observed_at":"2026-08-09T16:09:15.893547Z","submitted_at":"2026-06-16T03:29:23Z","title":"PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-02T11:07:07.442032Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.17467"},"observation_digest":"sha256:82115c568b024429c7211d09d4bac79c36a48d6150405f5c38c6ed24cb53d666","observation_id":"317cc991-7106-429f-8973-67bdeb1617af","resolution":{"observed_at":"2026-08-02T11:07:07.442032Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.18530","last_updated":"2026-06-16T22:51:02Z","snapshot_observed_at":"2026-08-03T05:17:11.488222Z","submitted_at":"2026-06-16T22:51:02Z","title":"Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks","version":1},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-06-26T23:45:25.770548Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.18530"},"observation_digest":"sha256:53927b89bbfc29a0e6158a03cfe724a0a9bd1bfd07b92d5c6bf9916cffea3f69","observation_id":"33fe266d-6331-498b-95b6-950f61ab31a0","resolution":{"observed_at":"2026-07-03T22:08:59.310448Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.19660","last_updated":"2026-06-17T23:59:57Z","snapshot_observed_at":"2026-08-08T17:16:02.859263Z","submitted_at":"2026-06-17T23:59:57Z","title":"A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-06-26T20:00:14.036515Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.19660"},"observation_digest":"sha256:b5e19a0efcdd69d50e8918965d0e6c4161ed2889f48ede984e1cf6eda2a3f1d4","observation_id":"850b25ab-2f1e-4164-817f-87a33240546e","resolution":{"observed_at":"2026-07-04T02:09:22.497299Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.22659","last_updated":"2026-06-21T20:30:12Z","snapshot_observed_at":"2026-08-09T02:10:31.571138Z","submitted_at":"2026-06-21T20:30:12Z","title":"Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-06-26T09:55:08.178751Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.22659"},"observation_digest":"sha256:e304022acb0947a1b0002a525d42961b6386b70e6471579484d158d11feb7b66","observation_id":"c2abf31c-073e-42f1-a60a-a9089c3a6ac8","resolution":{"observed_at":"2026-07-04T09:29:44.070733Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":"2312.14197","doi":"10.48550/arxiv.2312.14197","metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":"arXiv (Cornell University)","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","year":2025},"citing_paper":{"arxiv_id":"2606.30783","last_updated":"2026-06-29T18:11:17Z","snapshot_observed_at":"2026-08-08T22:30:38.879886Z","submitted_at":"2026-06-29T18:11:17Z","title":"Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense","version":1},"reference_index":78,"source":"arxiv_source","source_observed_at":"2026-07-01T01:44:07.700127Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2606.30783"},"observation_digest":"sha256:a29929a85d622a43a454ba88848ce8bb7cefd312ab288ef069230e6281efe692","observation_id":"a47829da-290b-4947-a457-56cd4adcb915","resolution":{"observed_at":"2026-07-01T12:45:44.893169Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-07-11T23:43:28.649948Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.03821","last_updated":"2026-07-04T11:12:36Z","snapshot_observed_at":"2026-08-04T05:25:45.960823Z","submitted_at":"2026-07-04T11:12:36Z","title":"DualView: Preventing Indirect Prompt Injection in Personal AI Agents","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-07-11T23:43:28.649948Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2607.03821"},"observation_digest":"sha256:70958e64c7c183642d943ad818d492eca1cc81aa9605e5e262095cbb477b9a3c","observation_id":"882da221-d8ed-4050-bd80-7898a459ec4b","resolution":{"observed_at":"2026-07-11T23:43:28.649948Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-02T13:26:27.643188Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models, January 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.19355","last_updated":"2026-05-22T12:13:16Z","snapshot_observed_at":"2026-08-07T21:44:05.596114Z","submitted_at":"2026-05-22T12:13:16Z","title":"Information Discernment in Large Language Models","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-02T13:26:27.643188Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2607.19355"},"observation_digest":"sha256:ce3b4ee2f7c928fb6739e4403e5e59cdd962c31ba6aa6d64bf5d5b1da2951227","observation_id":"322d5c44-c7ab-417d-9221-8c2d96b559fe","resolution":{"observed_at":"2026-08-02T13:26:27.643188Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-07-31T23:24:19.576853Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.23999","last_updated":"2026-07-28T07:27:46Z","snapshot_observed_at":"2026-08-03T08:43:31.893929Z","submitted_at":"2026-07-27T04:51:20Z","title":"ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-07-31T23:24:19.576853Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2607.23999"},"observation_digest":"sha256:c05cd5493ebcf6c1d21da3030975a7ae1142c85f9bbff8f407f29d40e588a785","observation_id":"db4457de-bbd2-4963-a793-ecef3e38fac2","resolution":{"observed_at":"2026-07-31T23:24:19.576853Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-03T01:25:30.766287Z","title":"arXiv preprint arXiv:2312.14197 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.24343","last_updated":"2026-07-31T11:27:14Z","snapshot_observed_at":"2026-08-05T23:11:08.904977Z","submitted_at":"2026-07-27T12:21:18Z","title":"Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls","version":2},"reference_index":32,"source":"arxiv_source","source_observed_at":"2026-08-03T01:25:30.766287Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2607.24343"},"observation_digest":"sha256:752da9a4727dfaec6ddcd704662ebe26aa58939b3e8bfc2b53b84b920f3689e1","observation_id":"755f590a-9840-4bb8-8040-56b56c73a6aa","resolution":{"observed_at":"2026-08-03T01:25:30.766287Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-03T00:55:23.831248Z","title":"arXiv preprint arXiv:2312.14197 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.28636","last_updated":"2026-05-19T13:56:13Z","snapshot_observed_at":"2026-08-06T00:38:04.006327Z","submitted_at":"2026-05-19T13:56:13Z","title":"Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges","version":1},"reference_index":51,"source":"arxiv_source","source_observed_at":"2026-08-03T00:55:23.831248Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2607.28636"},"observation_digest":"sha256:ccc08ee7267d9f6b7c38266ed3cf7a65869e0863e10c93eaf8a731e8ecaaf463","observation_id":"6e8d9b35-c683-43d6-a186-a5732b86ad10","resolution":{"observed_at":"2026-08-03T00:55:23.831248Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-04T22:13:21.497262Z","title":"arXiv preprint arXiv:2312.14197 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.01719","last_updated":"2026-08-03T05:36:49Z","snapshot_observed_at":"2026-08-06T23:32:57.491630Z","submitted_at":"2026-08-03T05:36:49Z","title":"MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication","version":1},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-08-04T22:13:21.497262Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2608.01719"},"observation_digest":"sha256:748dded0fbf9978c161f0cc72f6acbabe04d0002c819bd5718bee2175ce2f098","observation_id":"4e0f8e47-dc08-487c-af06-d08f1e1e2669","resolution":{"observed_at":"2026-08-04T22:13:21.497262Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-08T13:19:01.961178Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2608.05430","last_updated":"2026-08-05T21:44:44Z","snapshot_observed_at":"2026-08-09T23:10:49.394955Z","submitted_at":"2026-08-05T21:44:44Z","title":"Robust Context-Aware Detection of Malicious Instructions in Text","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-08-08T13:19:01.961178Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2608.05430"},"observation_digest":"sha256:60c8a54ac9663d2aa7c09ec93f8372376678ff238ba7837dae8679d70541aba0","observation_id":"6bc4f208-44ae-4ffd-991b-98915cc36574","resolution":{"observed_at":"2026-08-08T13:19:01.961178Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2312.14197/citation-record","integrity":"/paper/2312.14197/integrity","json":"/paper/2312.14197/citation-record.json","paper":"/paper/2312.14197"},"outbound":[],"paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","latest_version":4,"primary_category":"cs.CL","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 10 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 56 inbound Pith citation observations for arXiv:2312.14197."}