{"as_of":"2026-08-13T04:21:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:e48306674a6f87947feaf2657b86dff16a68208c797a12b3e1f584e6d4d00260","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":9,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":9,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-12T06:34:41.77262+00:00","state":"measured"},{"denominator":9,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":9,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T20:36:02.276204Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-07-03T06:17:41.932219Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2406.13352","last_updated":"2024-11-24T22:04:23Z","snapshot_observed_at":"2026-07-06T18:33:32.806635Z","submitted_at":"2024-06-19T08:55:56Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","version":3},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-05-13T06:35:13.331872Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2406.13352"},"observation_digest":"sha256:6b4af162f22fbd53d2e29643a8055a14cf8694056e5b5129ba5e2627b9b4b9dc","observation_id":"c79b8249-09cf-4b2b-b2aa-d2490ca9d575","resolution":{"observed_at":"2026-05-13T06:35:13.490917Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2409.10102","last_updated":"2026-05-16T07:15:07Z","snapshot_observed_at":"2026-08-04T19:12:49.508911Z","submitted_at":"2024-09-16T09:06:44Z","title":"Trustworthiness in Retrieval-Augmented Generation Systems: A Survey","version":2},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-05-23T21:08:11.787013Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2409.10102"},"observation_digest":"sha256:4d551bb2f2ea830ba24b90bd1401e612982680ae8c77acab23b273f790fb7f99","observation_id":"c8ebc6a3-9899-4fe2-a37f-29e2aa065586","resolution":{"observed_at":"2026-05-23T21:08:25.793746Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-08-12T20:36:02.276204Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.09523","last_updated":"2024-11-14T15:40:04Z","snapshot_observed_at":"2026-08-12T20:31:28.080469Z","submitted_at":"2024-11-14T15:40:04Z","title":"Navigating the Risks: A Survey of Security, Privacy, and Ethics Threats in LLM-Based Agents","version":1},"reference_index":202,"source":"pdf_text","source_observed_at":"2026-08-12T20:36:02.276204Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2411.09523"},"observation_digest":"sha256:dda1355467d969f486ea2b895f93d2db0b3d4dde76be1d7f4e9c516e569042ab","observation_id":"933761b1-e20d-4097-9755-dcd55dc6ad8e","resolution":{"observed_at":"2026-08-12T20:36:02.276204Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-08-10T19:44:46.798448Z","title":"Available: https://arxiv.org/abs/2403.03792","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.09798","last_updated":"2025-05-10T02:36:13Z","snapshot_observed_at":"2026-08-10T21:58:42.525514Z","submitted_at":"2025-01-16T19:01:25Z","title":"Fun-tuning: Characterizing the Vulnerability of Proprietary LLMs to Optimization-based Prompt Injection Attacks via the Fine-Tuning Interface","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-10T19:44:46.798448Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2501.09798"},"observation_digest":"sha256:c4da7518b84e8e5b9e9d7168b86f0599c24b9ccaba6459577f9c1dd1b9f3c29b","observation_id":"27a7fa14-653a-47e3-aebd-1be0f2c28992","resolution":{"observed_at":"2026-08-10T19:44:46.798448Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2504.20984","last_updated":"2025-09-10T19:03:48Z","snapshot_observed_at":"2026-08-12T23:40:41.340437Z","submitted_at":"2025-04-29T17:55:52Z","title":"ACE: A Security Architecture for LLM-Integrated App Systems","version":3},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-05-22T18:05:50.363944Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2504.20984"},"observation_digest":"sha256:2f09fb98863a2a299d0f8edece255dc2f9fc0a24be0fe4e9f41b9390682afa7a","observation_id":"6eec70c6-d9d9-4528-b7ec-176ac6786d63","resolution":{"observed_at":"2026-05-22T18:06:54.283250Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-08-07T14:27:03.612380Z","title":"Neural exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.18889","last_updated":"2025-08-24T03:15:13Z","snapshot_observed_at":"2026-08-12T00:50:28.355545Z","submitted_at":"2025-05-24T22:22:43Z","title":"Security Concerns for Large Language Models: A Survey","version":5},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:03.612380Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2505.18889"},"observation_digest":"sha256:d26e6661f8bd07aa3a0d0876e86b7acc4ab741c0d9a95e537c3499c9bb57f566","observation_id":"c6fa50bd-3b22-4322-b72c-ce82f7a1333f","resolution":{"observed_at":"2026-08-07T14:27:03.612380Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2604.23887","last_updated":"2026-05-12T22:23:22Z","snapshot_observed_at":"2026-08-13T02:05:32.557207Z","submitted_at":"2026-04-26T21:22:35Z","title":"Evaluation of Prompt Injection Defenses in Large Language Models","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-05-08T05:50:20.608166Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2604.23887"},"observation_digest":"sha256:527808346238df6b293544f4ef460564cbb502df7697c04ed57f53202d4c81a9","observation_id":"dbc0bacd-8c3f-4cba-a325-a0d8f8378f07","resolution":{"observed_at":"2026-05-11T21:21:12.084417Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2604.23887","last_updated":"2026-05-12T22:23:22Z","snapshot_observed_at":"2026-08-13T02:05:32.557207Z","submitted_at":"2026-04-26T21:22:35Z","title":"Evaluation of Prompt Injection Defenses in Large Language Models","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-05-14T21:05:23.800356Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2604.23887"},"observation_digest":"sha256:8617d63d370d5b0e56255e7d91ba77a0ab4ff3936ee7345f34b87815e985eea8","observation_id":"ac41caa6-ad5a-4e55-96bc-c81b4b2ceda0","resolution":{"observed_at":"2026-05-14T21:19:28.492228Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2403.03792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2403.03792","snapshot_observed_at":"2026-07-03T06:17:41.932219Z","title":"Neu- ral exec: Learning (and learning from) execution triggers for prompt injection attacks","venue":null,"work_id":"47349134-5f8f-469c-b2b0-eabf8e389cd2","year":2024},"citing_paper":{"arxiv_id":"2606.10525","last_updated":"2026-06-09T07:54:58Z","snapshot_observed_at":"2026-08-12T14:50:05.354392Z","submitted_at":"2026-06-09T07:54:58Z","title":"Assessing Automated Prompt Injection Attacks in Agentic Environments","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-06-27T12:47:09.467463Z"},"links":{"cited_paper":"/paper/2403.03792","citing_paper":"/paper/2606.10525"},"observation_digest":"sha256:1b70317ed31f495bfbfc430d646fed03c0f7bcc26f4d96c3ed1868693b6056fe","observation_id":"64bd7d9f-4c8d-4548-8f2e-014e775cf0b1","resolution":{"observed_at":"2026-07-03T06:17:41.936259Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2403.03792/citation-record","integrity":"/paper/2403.03792/integrity","json":"/paper/2403.03792/citation-record.json","paper":"/paper/2403.03792"},"outbound":[],"paper":{"arxiv_id":"2403.03792","last_updated":"2024-05-02T09:25:38Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-13T04:02:09.950658Z","submitted_at":"2024-03-06T15:40:30Z","title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"thesis":"As of 13 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 9 inbound Pith citation observations for arXiv:2403.03792."}