Pith. sign in

Paper Citation Record · LEDGER

Automatic and Universal Prompt Injection Attacks against Large Language Models

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 46 inbound Pith citation observations for arXiv:2403.04957.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2403.04957 v1

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 46 of 46 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 46 of 46 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-08T20:57:43.488821Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T14:09:53.868428Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 00382ccd-a8c3-4c0f-9d44-dbd2cd791271 · inbound

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems cites this paper.

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-15T19:32:19.765944Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-15T19:32:19.405615Z digest=sha256:f9e171a9584fbef469d5fe0ef8af904fe4630beb035c573fd701a8aa23e4c906

Observation 4e27f4c2-676e-4012-9ade-1c690c0c6c55 · inbound

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search cites this paper.

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-08T20:57:43.488821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T20:57:43.488821Z digest=sha256:bafad405c5ce002ee132d788df653decb470b378d573698cd3089e560f4a3289

Observation f1eee7c9-bfff-4c8d-884b-262fe08e5200 · inbound

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety cites this paper.

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 131

Resolution
verified exact
arxiv_id, observed 2026-05-23T04:42:34.055523Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-23T04:39:04.591722Z digest=sha256:d642489b4c69baca178bc570a5f50b8ebdb781794e025037dba6e8c8e0959476

Observation 3b999406-817e-4c83-9279-6493d7118cf9 · inbound

Progent: Securing AI Agents with Privilege Control cites this paper.

Progent: Securing AI Agents with Privilege Control Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:12:08.509663Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T21:09:51.782808Z digest=sha256:ef353deffc9a0b8534b42a309a9ed423264f58adbc519e5d5412c1f3e4055e40

Observation a1da7caf-84ea-4269-be80-b8d459938655 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.033623Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:051de7da63b37d228e42857b923c79d790f0755c53e05277d02541d65a63fb17

Observation ba6ff266-a26c-450f-bec2-51e9c3c922a4 · inbound

A Critical Evaluation of Defenses against Prompt Injection Attacks cites this paper.

A Critical Evaluation of Defenses against Prompt Injection Attacks Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T14:36:10.639064Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:36:10.639064Z digest=sha256:b04995963a01f4245d1dd1dc87dacaf8f0e8a70a5cf4eb713f37bd93add0e15d

Observation 4ba3acef-79e5-48ee-86b5-c7196eac569b · inbound

LLM Agents Should Employ Security Principles cites this paper.

LLM Agents Should Employ Security Principles Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.656779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.656779Z digest=sha256:172d64858ca031480bb76d2f1dda6797f430a471675148a82d4682dc8fa09bb2

Observation 7342b699-7560-41fa-89d7-808daffcbee5 · inbound

A Red Teaming Roadmap Towards System-Level Safety cites this paper.

A Red Teaming Roadmap Towards System-Level Safety Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T12:11:20.996876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:11:20.996876Z digest=sha256:ed9a48e4dc4f8114d202f44cb76dcf8eb88f08583804f7b8998c82adc57bddd6

Observation 3afdebdd-3f5e-4b72-9cbc-eccb2bbb06a5 · inbound

JavelinGuard: Low-Cost Transformer Architectures for LLM Security cites this paper.

JavelinGuard: Low-Cost Transformer Architectures for LLM Security Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T05:41:25.442964Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T05:41:25.442964Z digest=sha256:dfa62a4df6787690c4df5fdb1135cef1013a8cb2acd67481016b002560338df8

Observation 3b5a2a5e-fb16-4246-99ba-a541103270ef · inbound

Optimus: A Robust Defense Framework for Mitigating Toxicity while Fine-Tuning Conversational AI cites this paper.

Optimus: A Robust Defense Framework for Mitigating Toxicity while Fine-Tuning Conversational AI Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 49

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:21:31.173740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T12:17:59.458633Z digest=sha256:09249f8e4e4e97cebb86919c86befc5d798f43645aa5f27921235f61688a75dd

Observation 4941f215-fcae-4a57-a01e-eb1d0761141e · inbound

Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms cites this paper.

Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T19:12:22.873103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:12:22.873103Z digest=sha256:7e7ed9dd91364024a969e9f3f188526824562b7c02973d600fe70a4c352a0072

Observation 98b6a98b-c918-43b7-83b6-5e56d436e594 · inbound

Defending Against Prompt Injection With a Few DefensiveTokens cites this paper.

Defending Against Prompt Injection With a Few DefensiveTokens Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T18:32:40.695022Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T18:32:40.695022Z digest=sha256:7a19789c16c4ad5fb82b4c57bb6ea16ba7fad9a64aefe80ef574a8b878232132

Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · inbound

Prompt Injection 2.0: Hybrid AI Threats cites this paper.

Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.407180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.407180Z digest=sha256:b8947baecdbddd03650441df9ac357b7441d29f1b80557f76318a0e42cbe0119

Observation e7e68571-f96e-4f65-ada3-7426759e29b2 · inbound

DeRAG: Black-box Adversarial Attacks on Multiple Retrieval-Augmented Generation Applications via Prompt Injection cites this paper.

DeRAG: Black-box Adversarial Attacks on Multiple Retrieval-Augmented Generation Applications via Prompt Injection Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T15:48:58.472087Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:48:58.472087Z digest=sha256:0451ee5e33028cbce9e9a278e7373d960aa746c3a19a5034237c5ccdc6af2952

Observation f957c792-a18c-485a-860c-8f06ffec6b56 · inbound

Multi-Stage Prompt Inference Attacks on Enterprise LLM Systems cites this paper.

Multi-Stage Prompt Inference Attacks on Enterprise LLM Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T15:32:52.654532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:32:52.654532Z digest=sha256:2310b98402e0b49cc187747ac5be440c4fdcb4ac12c0571a5d1ccea02f9aaea6

Observation 45f7d85a-76f8-497c-aeac-667ff1e2f1cb · inbound

Understanding the Supply Chain and Risks of Large Language Model Applications cites this paper.

Understanding the Supply Chain and Risks of Large Language Model Applications Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T14:45:42.873238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T14:45:42.873238Z digest=sha256:d2cb323f34fb3c252713f818fb5f99bc8b597a1c545e35b8e76987ed8eb5d65d

Observation 1c9450e4-55e6-4820-8f2f-2751a9d8581c · inbound

MedMKEB: A Comprehensive Knowledge Editing Benchmark for Medical Multimodal Large Language Models cites this paper.

MedMKEB: A Comprehensive Knowledge Editing Benchmark for Medical Multimodal Large Language Models Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T23:37:06.805902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T23:37:06.805902Z digest=sha256:27eab14033ef3b2593a9847c68ad5adb9e3e99d8f5f1d7633d3cff5644f4fb05

Observation d38b6893-beb6-47fd-90cc-11869f761d5d · inbound

Can You Trick the Grader? Adversarial Persuasion of LLM Judges cites this paper.

Can You Trick the Grader? Adversarial Persuasion of LLM Judges Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T21:55:58.592723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T21:55:58.592723Z digest=sha256:8ebd927faa1a4b919a7fa56886a8f92d6b25b29293cb0ce5ba7d02ad24af29ed

Observation eb2ddbd0-6ab7-48b3-8a03-042e64e1955d · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:33.469643Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:33.469643Z digest=sha256:380111b661270635c0ba1b7edd14ab2676a41e79a45ee27491d19bb5bad9cf06

Observation d7ec56af-1696-4abd-a490-5b82e13facb2 · inbound

Lexical Hints of Accuracy in LLM Reasoning Chains cites this paper.

Lexical Hints of Accuracy in LLM Reasoning Chains Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T18:48:51.940993Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:48:51.940993Z digest=sha256:5d2e41e011d42b7df6be1466ab0a7ad3b5df06d79f4a758b9b360a569295fecb

Observation ded80d7c-1156-4ac7-8bdd-2c9422582adc · inbound

UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation cites this paper.

UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T16:24:26.741048Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:24:26.741048Z digest=sha256:f42582d32d873fecae9a6189f842d838d116a107ac8bea4d9d45487ca50399d8

Observation 4b2a9e2e-c0a5-44ec-8b75-efc62a07db9b · inbound

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior cites this paper.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:28.896342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:28.896342Z digest=sha256:6bf621c2f8550ca040faaa3187b5db56581e6fe06a055046e45ea8ee519d55c8

Observation d85bae77-58fc-4950-ab87-e716d349490f · inbound

ImportSnare: Directed "Code Manual" Hijacking in Retrieval-Augmented Code Generation cites this paper.

ImportSnare: Directed "Code Manual" Hijacking in Retrieval-Augmented Code Generation Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-04T21:33:58.308885Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T21:33:58.308885Z digest=sha256:0813622e06631f8e4083b4111845015ea087843da35b9b337740369ded52b972

Observation 103324b5-ece7-446e-8f47-f3e500560bf1 · inbound

Commenotes: Synthesizing Organic Comments to Support Community-Based Fact-Checking cites this paper.

Commenotes: Synthesizing Organic Comments to Support Community-Based Fact-Checking Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-04T17:17:02.831895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T17:17:02.831895Z digest=sha256:a82eb343271fe7b3156e1370f8c8e350bf4172576dc9e6b4270f0269dc331fd8

Observation 14425be5-c3c8-4b12-acd4-9417b8db1c98 · inbound

Controlling the Risk of Corrupted Contexts for Language Models via Early-Exiting cites this paper.

Controlling the Risk of Corrupted Contexts for Language Models via Early-Exiting Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T12:45:26.210468Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:45:26.210468Z digest=sha256:db9f560a41b3c4878346cea6039ef558fd85041ade4c93fe54e748ab1e37c251

Observation 12515d4d-d0d6-45fc-9506-a68163e66f91 · inbound

Are LLMs Reliable Rankers? Rank Manipulation via Two-Stage Token Optimization cites this paper.

Are LLMs Reliable Rankers? Rank Manipulation via Two-Stage Token Optimization Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-04T11:11:01.037174Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T11:11:01.037174Z digest=sha256:f9c5584dabf414da229dcf80aa843582b6def491ff83a10d727b1b922f9e02e1

Observation 35f62a36-f6d6-4b33-99c6-d55049917d54 · inbound

MetaBreak: Jailbreaking Online LLM Services via Special Token Manipulation cites this paper.

MetaBreak: Jailbreaking Online LLM Services via Special Token Manipulation Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-04T10:22:06.011277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T10:22:06.011277Z digest=sha256:983226d37c5ae43a6382ee15b70b198579faafa740580377b9d4a021d574c91c

Observation ee967f60-f099-41ee-b92f-17942d1548d6 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 65

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.009079Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:524de26d4d0924db353667e4bc53a87990cbea3559de16c616af491b1f1bdcb9

Observation 408154a8-f508-4367-afa4-048f18760781 · inbound

From Rookie to Expert: Manipulating LLMs for Automated Vulnerability Exploitation in Enterprise Software cites this paper.

From Rookie to Expert: Manipulating LLMs for Automated Vulnerability Exploitation in Enterprise Software Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-16T20:03:22.145931Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-16T20:02:47.746439Z digest=sha256:8105fed8602e12ba828f6a08531aa588ea9f4bf6b6b1184bb2d5db2217a1506a

Observation 4526d02f-6b83-42d5-ab40-bc7dd1bbb73d · inbound

SoK: Security of Autonomous LLM Agents in Agentic Commerce cites this paper.

SoK: Security of Autonomous LLM Agents in Agentic Commerce Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 101

Resolution
verified exact
arxiv_id, observed 2026-05-10T14:00:29.387592Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T13:55:48.290563Z digest=sha256:6a0efcc11d6603f79e76318a002e229e6f5b19e6113b09ddf5f34c43dd757ac2

Observation 0758cb4a-9c1a-4ce4-84da-61f3390ff217 · inbound

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cites this paper.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 7

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.268382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:99de7927b845eef804c40a814c364c5622f688437b906d67394d23d810cd803d

Observation ba91c73c-6ae4-49b0-a59a-86a788265c5b · inbound

FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption cites this paper.

FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-12T10:16:28.309477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-07T06:49:56.316472Z digest=sha256:95359723770e9ca66b0e3b86a48d04ec3c7e913e1bb6b20d653f72cf083d2ded

Observation fc59cb35-51f7-43e1-b7e6-15f75d0971a1 · inbound

LoopTrap: Termination Poisoning Attacks on LLM Agents cites this paper.

LoopTrap: Termination Poisoning Attacks on LLM Agents Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:21:10.453091Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T09:25:11.059634Z digest=sha256:cf553e96fe549422cc888a29e7a5ac1221be31a8cd3c2172967504baedc5c1ae

Observation 74ef6be6-1a74-4257-a403-458a4761f635 · inbound

FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems cites this paper.

FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-05-13T02:07:08.987404Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T01:57:31.681480Z digest=sha256:b3c327601ac0cd6123734eaaecdd83ed2c8285305ec82418824960d2402610e0

Observation 53a783df-662d-4544-bc55-0476f227bbd4 · inbound

A Cross-Modal Prompt Injection Attack against Large Vision-Language Models with Image-Only Perturbation cites this paper.

A Cross-Modal Prompt Injection Attack against Large Vision-Language Models with Image-Only Perturbation Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-20T17:23:36.817531Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-20T17:20:54.445007Z digest=sha256:d49e9bfd94c19e9bf5ece68537ed68d8f070d9d8d6b99e302e45492b5ea9dced

Observation 9ac646db-f3bd-4e33-9b9d-5b0397533efe · inbound

Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents cites this paper.

Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-06-29T18:03:48.480356Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-29T17:36:40.290498Z digest=sha256:cf7bd38197a16192d86cd799139c08c5f92d9b0454e310b13d0cfab962470953

Observation 8fbe5b62-e271-4ffb-ac7d-91a3974b8609 · inbound

Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening cites this paper.

Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-06-29T11:23:21.322899Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-29T11:16:52.024973Z digest=sha256:6eaed14cae5c50b7a214f0a0422a435fb2da4d5bb3d71b6f4deb0fba59bd8470

Observation dd1de3f3-e303-4ea7-a748-b0fb390096e8 · inbound

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections cites this paper.

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 32

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T12:38:07.281630Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-27T08:56:12.882653Z digest=sha256:cf1f7ad81d312aff7d766dc8d4aa8071864becf05ee903c95b6a4deb3f3b647b

Observation a0547398-f7d4-412f-b5f7-ad90e615975f · inbound

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents cites this paper.

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-07-03T16:48:40.535730Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T04:57:54.827932Z digest=sha256:510bcdadfa318ff909fb51d145203530a6e347c8737d442b222e7abd1c3f2621

Observation 113ff2ba-f2ac-41fe-be99-ea424581b7b6 · inbound

Prompt Injection in Automated R\'esum\'e Screening with Large Language Models: Single and Multi-Injection Settings cites this paper.

Prompt Injection in Automated R\'esum\'e Screening with Large Language Models: Single and Multi-Injection Settings Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T14:09:53.870010Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-26T04:23:37.914215Z digest=sha256:a5bc45f4d705cce56e16cef03f1cb0b90735ef315b189e70e3a472fcf04f6aaa

Observation 032d25df-0e38-490a-aeff-8a46e75190c9 · inbound

Devil in the Lens: Analyzing and Defending Physical Prompt Injection Against Vision-Language Models on Wearable Devices cites this paper.

Devil in the Lens: Analyzing and Defending Physical Prompt Injection Against Vision-Language Models on Wearable Devices Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-14T13:02:42.673767Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T13:02:42.673767Z digest=sha256:0c713e16fc8681af97a21612ddde37a3fcc96d6e512243af2fce49a74f1e2837

Observation 9916d3ed-d2d1-4b3a-9855-7df8b8338b03 · inbound

From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows cites this paper.

From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T22:55:46.994600Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T22:55:46.994600Z digest=sha256:4cc432d54bff949e9aa72dc34530312d063c55b9a4b9d9f6075d8fa26dc81bfd

Observation e01e3bc2-893a-4045-b634-0ad6af8f1353 · inbound

The safety failures we are not instrumenting: a perspective on hidden safety-critical challenges in modern AI systems cites this paper.

The safety failures we are not instrumenting: a perspective on hidden safety-critical challenges in modern AI systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-01T12:54:34.702508Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T12:54:34.702508Z digest=sha256:fa0bb29fd49b5ce992b51e88ec3c4a6333fb16dd997b5c4cbdaf515014e2918b

Observation e8fef1f8-3d84-47fb-ad9c-b4e362f19cb2 · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T00:25:59.525435Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T00:25:59.525435Z digest=sha256:a74f9f7bf65cdabce594258b7362c2060d4761794ac6d5ef61490477aa54fc01

Observation 7b3561d9-29b1-40cc-91cb-e557b307c12c · inbound

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems cites this paper.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T04:17:02.594840Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.594840Z digest=sha256:e442a664a8c2bd8a0ba612062362b7d2a08e0328b5e876227e4c9532533a1354

Observation 68e00c90-cd07-4567-a3dc-f7ffb980e559 · inbound

Robust Context-Aware Detection of Malicious Instructions in Text cites this paper.

Robust Context-Aware Detection of Malicious Instructions in Text Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-08T13:19:01.860743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T13:19:01.860743Z digest=sha256:9d7b62e95d98f9c360fc28084adbd6e6ec21f5f69f42aaeaca7381796e511ab8