Pith. sign in

Paper Citation Record · LEDGER

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

As of 4 August 2026, this Paper Citation Record lists 79 of 79 outbound references and 96 inbound Pith citation observations for arXiv:2406.13352.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2406.13352 v3

Coverage vector

measured 79 of 79 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-13T06:35:13.331872Z

measured 175 of 175 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00

measured 96 of 96 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T09:25:38.687859Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-11T02:47:49.867984Z

Reference resolution

79 of 79 outbound references displayed

  • verified exact37
  • verified fuzzy35
  • unresolved3
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch3

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 89a9c5c8-b9f9-489d-a65d-c45d3298d0d1 · outbound

This paper cites Croissant: A metadata format for ml-ready datasets.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Croissant: A metadata format for ml-ready datasets

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.387085Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c0bd3fe49dbc0f0dc90a63725c9c105c9d96151e37a48b7b14e4fa392cbc310e

Observation b56a0a3d-0a6f-4ada-a6df-c527f0dd9a8f · outbound

This paper cites The Claude 3 Model Family: Opus, Sonnet, Haiku.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Claude 3 Model Family: Opus, Sonnet, Haiku

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.552364Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:72f313edeee6cf385c13b80694f6aa2f30ba281038ff19650c4327ac788bf9e9

Observation e570c438-9dcc-4f2c-b99f-990a46667af4 · outbound

This paper cites Tool use (function calling).

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Tool use (function calling)

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.588539Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:2c052beed62791a7d91654d2bc06d569f9121fd09e92331bd4f8b21c98fa83ff

Observation 9138d2ac-a93b-48c4-93b7-748952c6f4f9 · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 4

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.407091Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:ba3364b7f141b023b2c43673c20bb2865f1dd29ae6621a8d49476a8802ec5939

Observation 953b48fe-7719-4e63-ad9b-9c27dd491b80 · outbound

This paper cites Language models are few-shot learners.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models are few-shot learners

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.628747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:510fe68eae6910e9544c1d7e5dcf2b4046092c8fe18a953880d8f93cf42c8065

Observation 4fd8827a-8983-44d3-a2d1-5c80a793f94c · outbound

This paper cites A critique of the DeepSec Platform for Security Analysis of Deep Learning Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents A critique of the DeepSec Platform for Security Analysis of Deep Learning Models

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-07-04T23:38:16.946516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:81e9d062bede3ee6b2eb2b73c6664c9d26630bf29bbd91aa96240f79b927e5ea

Observation c452888b-062f-401a-a538-ab96428606af · outbound

This paper cites JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-05-15T06:08:05.732086Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d94de44422765d1a984abb137659e9a5e5ad73f88f91a112524e09612c0ea430

Observation bfc9291a-c1de-4504-9997-3d6a8cfbe7f8 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents StruQ: Defending Against Prompt Injection with Structured Queries

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.423186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d0aae0add596b15f5543e7e5abe254e58802c1fc4e5f138fdb10676ccbbacd17

Observation 5429174b-7370-4691-b2b6-dbe509bd5efc · outbound

This paper cites Introducing Command R+: Our new, most powerful model in the Command R family.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Introducing Command R+: Our new, most powerful model in the Command R family

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.561358Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:65843b3c2e48f1b3cfdd2dc5c214de2bc66ac5ea45547ffb85d72d3ffdc2ea27

Observation 1aaa3615-8856-4d9f-86ca-a0404237e649 · outbound

This paper cites RobustBench: a standardized adversarial robustness benchmark.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents RobustBench: a standardized adversarial robustness benchmark

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.616780Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:6d7d5c7bcae7f7c95cea861e2422b4d585ba2a0d43fea3d828673c00d8bbaba6

Observation 7060773a-bedf-4c51-bb63-5ac68fe02c20 · outbound

This paper cites Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.595729Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:77f16ab1de626bed2c0ce58441a46dc0d1cfb7aeab17a9516b726602d1e389f2

Observation 46eab58b-a96d-4a7f-b56c-b0214647c0b1 · outbound

This paper cites Dataset and Lessons Learned from the 2024 SaTML LLM Capture-the-Flag Competition.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Dataset and Lessons Learned from the 2024 SaTML LLM Capture-the-Flag Competition

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.428523Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:2a94db984b2d7aaf87c05093accef495294a27b71fe772f84fec57fc31ccb349

Observation 22929a5e-c96d-4f5c-b69b-781da42f1b5e · outbound

This paper cites Misusing Tools in Large Language Models With Visual Adversarial Examples.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Misusing Tools in Large Language Models With Visual Adversarial Examples

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.396512Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:dfae418047efa03df31ca267489f3e036fb5412f6998e527ad53951616a9f812

Observation 2e67bca7-fdd3-43b5-bc71-06e41963c640 · outbound

This paper cites PAL: Program-aided language models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents PAL: Program-aided language models

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.583356Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:68bb57e8f0c41cf8e47821353fe20b9e0daa3b53d95a456b82a91542c32c93dd

Observation 12ec3800-2704-4bd4-a5a2-56b77f154a14 · outbound

This paper cites Coercing LLMs to do and reveal (almost) anything.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Coercing LLMs to do and reveal (almost) anything

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.433785Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:3308707d8f5ed17e782f86afe6800c73112bf8706829b52fa2a8c9d7528a361b

Observation fdf395f8-aedb-4dad-b473-2a9e770a712b · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Gemini: A Family of Highly Capable Multimodal Models

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.440104Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:42683c4253ddc4fc7d0b8a03738a1d4290b84a270ee8257c47891e153950009a

Observation a6680ea7-a0bb-477f-be13-578cd47e3483 · outbound

This paper cites Exploiting GPT-3 prompts with malicious inputs that order the model to ignore its previous directions.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Exploiting GPT-3 prompts with malicious inputs that order the model to ignore its previous directions

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.445172Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:382c2fd7915fecbeab5751942e83083c9b6d1afed8cd304f5d0c8a7670b59e0d

Observation b763d4c3-75d6-4655-ba2a-66aced532e98 · outbound

This paper cites Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 18

Resolution
verified exact
doi, observed 2026-05-13T06:35:13.381921Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:ad7f30011ab1cab67955d54bcce96161919eb8549aacc710ae2cc88b737fcdb9

Observation 3b16a231-0ac6-4ecf-8d37-faf42f5e381c · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-14T22:28:55.556742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:0f689cbbee83ffefd02b558055a4852acae73d75cc20d8c947179089f8e19fa9

Observation ff004233-d55a-4973-8215-430a69a41b80 · outbound

This paper cites Language models as zero-shot planners: Extracting actionable knowledge for embodied agents.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models as zero-shot planners: Extracting actionable knowledge for embodied agents

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.601636Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:257eeddc96a45b6c231c0f61b86ca0d0a02f87e81efcc3c3cab001f997a26405

Observation 0d533d86-bf1d-4c7c-bfcc-6eded8f0ef3e · outbound

This paper cites Llama-3 Function Calling Demo.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Llama-3 Function Calling Demo

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.604039Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:87114bfc6fd016fd881ec060d70c2825618355e2157e3b4313677b0839311039

Observation 138936e7-ea59-42ce-932d-4a29faf02673 · outbound

This paper cites Function calling.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Function calling

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.607156Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c7e1df3f991790bb436b0578af464ebc7bc61a23593eedf2655fd22d955ab403

Observation a189a154-10b5-4c98-96f6-eb1403e05e07 · outbound

This paper cites Exploiting programmatic behavior of llms: Dual-use through standard security attacks.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Exploiting programmatic behavior of llms: Dual-use through standard security attacks

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.609711Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:a93fcdc806bdc798fd0052ba7eb225d9c2aef6a8d5c38a2ea98eef1af768f473

Observation 7ed3ebfc-7c53-439f-8f8d-1111e6f3edfd · outbound

This paper cites Intro to Large Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Intro to Large Language Models

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.612081Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:741484b11e81f593d7ec67fb655c9e4f2622c99fb1230adc90e8cd7c42cc9ec3

Observation 28c6a111-7d60-40ef-be71-70a005878f26 · outbound

This paper cites Language models can solve computer tasks.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models can solve computer tasks

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.614409Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:75d6a751461ce9abf4b24e24532388570070db2ab624823a847d12b4c832ca71

Observation e7ee29c8-aa5f-43a1-9aa4-247e47cd87ce · outbound

This paper cites Evaluating Language-Model Agents on Realistic Autonomous Tasks.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Evaluating Language-Model Agents on Realistic Autonomous Tasks

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.377228Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:23c3a275c3c1dbf24a45187f64c021d09e733138d8094199943a8dac8d175165

Observation b4b20713-a35c-42fe-914b-b8452d7f2ab6 · outbound

This paper cites Large language models are zero-shot reasoners.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Large language models are zero-shot reasoners

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.619634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:80ef609a7cb5172dc7ec3fe426b46f629966aee377e39524e8b302b288ab0ad8

Observation 6a9d5bf3-1b0b-4dae-9ab2-beeffbec5364 · outbound

This paper cites ChainGuard.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ChainGuard

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.621884Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c40f994f3cec5b168635d5c3e66790f77365d54068e862ac6c1c05bdb5130f47

Observation 050c8764-3496-440f-ae57-2db65fe39050 · outbound

This paper cites Hugging Face prompt injection identification.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Hugging Face prompt injection identification

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.624340Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:e7ed49a6c9f8eccb50ad37099645c94d22ade45b3d17ff296ba273b755433e93

Observation 0ddc7093-f791-4aba-b399-9ff46ed3d8f5 · outbound

This paper cites Sandwich Defense.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Sandwich Defense

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.626533Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:44b67feee061ecee18d285a83dc0c3def1d295dc3a4576fcdafc6cc205121329

Observation 5fa1c041-6c39-4105-a389-8048cc188233 · outbound

This paper cites AgentSims: An Open-Source Sandbox for Large Language Model Evaluation.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents AgentSims: An Open-Source Sandbox for Large Language Model Evaluation

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.453486Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d7019548780e25fab07bf2cc0c547f8f98b91493f87f6690f69c70e59a0351a7

Observation dd6ace60-0919-4fb1-a14f-3b02003d9500 · outbound

This paper cites AgentBench: Evaluating LLMs as Agents.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents AgentBench: Evaluating LLMs as Agents

Reference 32

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.457513Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d16995cd87527633a16f8ff7057ce75b4c5c115c1a60ab980728c52bcbbc41df

Observation 30dad74b-8226-46c6-9624-10bb0e3faa27 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt Injection attack against LLM-integrated Applications

Reference 33

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.461945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:57293fb3c6aac825f08bc7b303c05c7a1df8c41a7abfc5667b9675d2a4868e0a

Observation 6eb7b17d-a90c-4fc2-8414-37f5a5c48b69 · outbound

This paper cites Prompt Injection Attacks and Defenses in LLM-Integrated Applications.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt Injection Attacks and Defenses in LLM-Integrated Applications

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.467174Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:0bd8b4f5979471ff666ebc0841ba315a81b52828362b6f20bbbb7028eb2eb1e4

Observation 12afe5fa-cf85-45a8-87ad-3757a169b0a7 · outbound

This paper cites Chameleon: Plug-and-play compositional reasoning with large language models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Chameleon: Plug-and-play compositional reasoning with large language models

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.637864Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f536dbe640314ecebc5a7b40cfb5790b4d4b28da0a8cee7215eb82ba9ee085d9

Observation 736089f3-4a8e-4705-afe9-7c96d906784d · outbound

This paper cites HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal

Reference 36

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.472307Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:11a2a856ac9aa7a10acf851c59848ef02a401f18380c8048e581a0977cd39d1f

Observation c6b2f7b9-6de7-48bc-8196-3b7866750f79 · outbound

This paper cites Inverse Scaling Prize: Second Round Winners.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Inverse Scaling Prize: Second Round Winners

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.642480Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:b7483c02facf7110101b0fcc6f2ac62909dd1d9db6194b81064aa214193ccf98

Observation 8ed30a97-a648-4d9a-b493-5215ca33d997 · outbound

This paper cites Inverse Scaling: When Bigger Isn't Better.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Inverse Scaling: When Bigger Isn't Better

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.477819Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:971adf9aabdc211b56096dfb531a9772bff33a10c68dfcc1e244bfcc6a5e23b2

Observation 6907c167-55b2-40a6-b898-a276972b3309 · outbound

This paper cites Can LLMs Follow Simple Rules?.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Can LLMs Follow Simple Rules?

Reference 39

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.482038Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:74c24e9f5cbb13b2a3cfbb0a4a2e1db733e9e37d905b246c745b71e7dec5fa6c

Observation 6ad776cf-7741-4bac-a374-4dc961fa27fd · outbound

This paper cites WebGPT: Browser-assisted question-answering with human feedback.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebGPT: Browser-assisted question-answering with human feedback

Reference 40

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.485984Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:31233a91e2ad899447f078676e28c815868cee13328ed4b77bc0433984610c3a

Observation 17793c88-76f3-495f-8f74-5c0e4eab2097 · outbound

This paper cites Training language models to follow instructions with human feedback.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Training language models to follow instructions with human feedback

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.547002Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:e539887aa87d36fd57a5fcf7733d0c6190f55dd050fc65bada5d8a193a8af48d

Observation c79b8249-09cf-4b2b-b2aa-d2490ca9d575 · outbound

This paper cites Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.490917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:66186ff660491c858a2c8afe3460e6a69e98ac3cb59bd1221edcc4b191ec3f8b

Observation f75b22c9-ef3d-467a-a0bb-45ced0536cb7 · outbound

This paper cites Gorilla: Large Language Model Connected with Massive APIs.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Gorilla: Large Language Model Connected with Massive APIs

Reference 43

Resolution
metadata mismatch
local_arxiv, observed 2026-05-13T06:35:13.494151Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:5c8894371feb020a1f8d174d252fe41273cc721a3a6a3836809927e734969b81

Observation 5dfd70e5-a53e-40c3-9ec5-86eb0a112b5f · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ignore Previous Prompt: Attack Techniques For Language Models

Reference 44

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.497861Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:55bafc190a034495df9f62a493b19571469aeb64b30ae0225dedcccd7f06ca45

Observation d9c2dd97-c24c-4792-be2e-8890fdacc08e · outbound

This paper cites Fine-Tuned DeBERTa-v3-base for Prompt Injection Detection.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Fine-Tuned DeBERTa-v3-base for Prompt Injection Detection

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.558050Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:ebea4766e4c6039247477b31c843969e35c6eaf64620190632b5dedd90375a42

Observation 4d94d931-6d7c-465d-a0f1-6de64f232b37 · outbound

This paper cites Ferrario and M.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ferrario and M

Reference 46

Resolution
metadata mismatch
doi, observed 2026-05-13T06:35:13.371446Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f51aa6d87150b52225aeaf63913d586456e63ef2aab3994ce7287a51a0558f69

Observation dc77fb29-ad00-4364-9971-134b47951aef · outbound

This paper cites ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs

Reference 47

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.501925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:e3f88126f948e0ff912ce1bf6c5322890773469fd638570cc84166b96e65be8c

Observation 4d3d63fc-fd61-4acf-a028-da7e60fe01bf · outbound

This paper cites an unresolved cited work.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work

Reference 48

Resolution
unresolved
raw_fallback, observed 2026-05-13T06:35:13.567218Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d6b9e0a3ee486a1ad2cfca899ffe1f4f95376c7a1ea02b16b814a25f59cc8404

Observation f765be89-858b-471a-8308-8b3fffea7e77 · outbound

This paper cites A Generalist Agent.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents A Generalist Agent

Reference 49

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.505440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f13a7af278a8c72da09137e5dc2ce412249ec7d931eca7715f5902e6d7d15001

Observation cbed452d-a5ad-46f9-971b-b3220c1daf39 · outbound

This paper cites Identifying the Risks of LM Agents with an LM-Emulated Sandbox.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Identifying the Risks of LM Agents with an LM-Emulated Sandbox

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.574124Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:bccd08a682815be374ca03e3c10458dab4ada73b6d53559829de4af03c550a0b

Observation 67787891-3bed-47a3-ad4f-b623d37cbddc · outbound

This paper cites ToolFormer: Language Models Can Teach Themselves to Use Tools.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolFormer: Language Models Can Teach Themselves to Use Tools

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.577911Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:381ea771cc89d5a36680ec5ea72756f67448c44651d2960e651f5f1a07126ae6

Observation a36945c7-8084-4c47-8bb5-6035b5581c55 · outbound

This paper cites Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs Through a Global Prompt Hacking Competition.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs Through a Global Prompt Hacking Competition

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.580632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:090e2b4f5be5c86d4ae343629e966bc17a620962877eb7788cc6ffaf883ba279

Observation 4633d987-49ba-4ef0-bd71-d006c2155764 · outbound

This paper cites HuggingGPT: Solving AI tasks with ChatGPT and its friends in Hugging Face.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents HuggingGPT: Solving AI tasks with ChatGPT and its friends in Hugging Face

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.585862Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:53a1cb062539fc245ad70f1d300dffd98b53ec36e935125524b6322550f9610b

Observation 887aa387-3fc8-4522-a27c-33ab572c08c7 · outbound

This paper cites ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-15T23:03:48.638764Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:01b9f342d11bf7dc80839b7b097505a8f57ee38f3cc447b3f343b2562e50ef75

Observation 67799eab-511e-4e91-bdc8-87f06455f885 · outbound

This paper cites LaMDA: Language Models for Dialog Applications.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents LaMDA: Language Models for Dialog Applications

Reference 55

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.513112Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:063ee7bb02d0781fb784e40230a52951d31c2ca77cf0efa7c19730f11dd566a7

Observation 5e82e77e-880e-4956-af17-92b4028e3c91 · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents LLaMA: Open and Efficient Foundation Language Models

Reference 56

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.516678Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f1e831472251a46c0a465b8ed4ef514e36c715fefd1cbe7b3ee686cdac6c81d5

Observation d629e88a-7f94-45c8-ac53-8a0ce87dc0db · outbound

This paper cites Tensor Trust: Interpretable Prompt Injection Attacks from an Online Game.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Tensor Trust: Interpretable Prompt Injection Attacks from an Online Game

Reference 57

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.366955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c23cf86b096bf2a791e0438c2449d83e8432d34d59d15d75aa08bcb6394fc87f

Observation a41e7317-49bb-463a-bdeb-3ae0ea4a3a4f · outbound

This paper cites On Adaptive Attacks to Adversarial Example Defenses.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents On Adaptive Attacks to Adversarial Example Defenses

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.631216Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f543dae256a245e7a5b6a98285e04bd264aba40b8428ddec069a62f0460fd5cf

Observation 8d3e5858-2051-4112-8d0f-b8ac2c59bee8 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 59

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.520049Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:83fd6fa12fe7eed455c332b3b3d8b8b6df78122d8b745b382e97511b138504e9

Observation f8a2b545-9b39-419f-ad4f-9dcc330bebf8 · outbound

This paper cites Chain-of-thought prompting elicits reasoning in large language models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Chain-of-thought prompting elicits reasoning in large language models

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.635669Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:b00375d877f90ec988ec682a1976aaf905029f725ddf925f327b64798c7c7f05

Observation b8cc1885-0c6b-4555-9f1d-8136a9ccaaa8 · outbound

This paper cites Delimiters won’t save you from prompt injection.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Delimiters won’t save you from prompt injection

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.640044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:622201e098d66959807aa457db5fbc2ab7f11956156f8f28e7aa6021fd80bfc7

Observation 15a0d934-0313-498b-b3a9-f15a484617e5 · outbound

This paper cites Prompt injection attacks against GPT-3.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt injection attacks against GPT-3

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.644608Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c81712702ff974a07cae220e65de5621184e12c37a032ff859b90a1e9c828dea

Observation 31887075-db0a-4631-8a2b-e037ff304695 · outbound

This paper cites The Dual LLM pattern for building AI assistants that can resist prompt injection.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Dual LLM pattern for building AI assistants that can resist prompt injection

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.646857Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:bd2fc9d3286c4e66476d3906b7f06bf14bd2ac23cfe2f7d66eb4e8bae8c48ffd

Observation 6760c282-5a9e-48b2-b330-912bfc12d9fa · outbound

This paper cites You can’t solve AI security problems with more AI.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents You can’t solve AI security problems with more AI

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.649080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:5e7317fa33cb03694ff9adf9d1f8339f2635b1b1584268e3ba94a1b0fdb556ac

Observation d8053d49-8ffc-46f4-b6b1-78c150ca985b · outbound

This paper cites Intelligent agents: Theory and practice.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Intelligent agents: Theory and practice

Reference 65

Resolution
malformed identifier
raw_fallback, observed 2026-05-13T06:35:13.549711Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:dcdf26909eddf9bdbddab970c149ed1ac4ec84c4eec18b0bc62357b716d3163a

Observation 2c8c0462-de83-4073-b1a6-a6feb0b957b0 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 66

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.524586Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:7a656bddcf49fd9e10de103973ba6f7407164038ebea05a12f234c0f1718117e

Observation b47c137a-096a-4e30-a15a-ed0c5a4f26d1 · outbound

This paper cites Patil, Ion Stoica, and Joseph E.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Patil, Ion Stoica, and Joseph E

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.554968Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:499dbd2341e78c8418dbcfc4875aa1f3084156fe3351eaa1e5e69d1528fa2c31

Observation 3f9d2a67-f999-4b00-a600-dc1e8e5606e6 · outbound

This paper cites WebShop: Towards scal- able real-world web interaction with grounded language agents.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebShop: Towards scal- able real-world web interaction with grounded language agents

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.564496Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:1a2eab6f723140eb312389a87fb29173685c8c4e9523b0a096ec6d3a1c21f5fd

Observation b2e74fb0-7a93-444d-a374-5196be604bfa · outbound

This paper cites ReAct: Synergizing Reasoning and Acting in Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ReAct: Synergizing Reasoning and Acting in Language Models

Reference 69

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.528496Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:37b4e2662a0fc5ae022ed8452fb41b26c1269cf644f8add91996e17e2efaed9f

Observation d352e1af-4809-454a-9774-144f23f1472d · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.402235Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:84bb1a7b1ab727724df2d0576ea1ca5866e80fd6375a6b8ba284bfa3c1fc9d71

Observation 9c6125cb-c32d-4627-b5f7-f8ea00afff5d · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-13T21:40:06.567267Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:ae7b24f57ad39d6e09331e6f6aacdb391f42653c55227b171cb88724136d3157

Observation fee48bd9-05a6-47d3-b79d-f6d61876a178 · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 72

Resolution
verified exact
local_arxiv, observed 2026-05-13T06:35:13.536309Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:52f252dc18f6f3a786e2b8f26e1999693faf9e509e0f6e76442ee2efde3f1d5a

Observation d9c4eff1-78e4-4d0c-af2c-c8aeac3843c4 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 73

Resolution
metadata mismatch
local_arxiv, observed 2026-05-13T06:35:13.539981Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:d39198c5d07de7678b45369f655c525b925d3a08f33152583ab317439d696e6c

Observation 46fec84a-dbcb-4e7e-8d3f-a40d8fa35f43 · outbound

This paper cites Can LLMs Separate Instructions From Data? And What Do We Even Mean By That?.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Can LLMs Separate Instructions From Data? And What Do We Even Mean By That?

Reference 74

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.544043Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:4d85c9460143950fcdc07143afb8de634461ab10ac19324057c6c4d00b91243b

Observation cb002e5c-9137-4add-94ef-121f102afae4 · outbound

This paper cites an unresolved cited work.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work

Reference 75

Resolution
unresolved
raw_fallback, observed 2026-05-13T06:35:13.570361Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:f5350dcefd277c45f531772013d7a90c026a4ba1cd6690c8a2179803a6bda8d5

Observation bcde0b29-840d-4b87-b504-05f4e1289ca4 · outbound

This paper cites (a) Did you state the full set of assumptions of all theoretical results? [N/A] (b) Did you include complete proofs of all theoretical results? [N/A].

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents (a) Did you state the full set of assumptions of all theoretical results? [N/A] (b) Did you include complete proofs of all theoretical results? [N/A]

Reference 76

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.592558Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:c96d4c11e73bc6320e7b89689439509223e1cd0764deb0f43019da0aa5eb2d38

Observation bcd0b5f9-639c-4471-9923-75e36162c586 · outbound

This paper cites for benchmarks).

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents for benchmarks)

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-05-13T06:35:13.598808Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:4c635d109da4cbe742733b62e27148c505dabb6a83624b45df1add2b41e86753

Observation 98b07d70-0cd8-4967-ac2a-441b327b959a · outbound

This paper cites an unresolved cited work.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work

Reference 78

Resolution
unresolved
raw_fallback, observed 2026-05-13T06:35:13.633403Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:5c976362b1274f3a0aa10e294716169ac4db1ed3b429be5ef8fe0327b6012d70

Observation 1fb1e9cf-c268-4ec1-9567-ba60880d251f · outbound

This paper cites Send the Facebook security code received via email from security@fb.com to eve@mail.com.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Send the Facebook security code received via email from security@fb.com to eve@mail.com

Reference 79

Resolution
verified exact
doi, observed 2026-05-13T06:35:13.390601Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:af6c08d1f628b830f5fa3ec57a84544d31e023eb6718c55a0815f00e303224d3

Pith citing papers

Observation 30d05291-0f12-4cf3-b7c4-1fdde80ed998 · inbound

Peering Behind the Shield: Guardrail Identification in Large Language Models cites this paper.

Peering Behind the Shield: Guardrail Identification in Large Language Models AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
verified exact
local_arxiv, observed 2026-05-23T03:45:21.431564Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-23T03:45:14.234545Z digest=sha256:551fd5b05a5cd776c6991ddc8663c804cd6aaec26867df34837d799c87d213de

Observation ed98329e-0ffe-4fa5-9d71-eb885dd125ed · inbound

The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections cites this paper.

The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 1

Resolution
metadata mismatch
local_arxiv, observed 2026-05-16T18:53:24.689725Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-11T11:50:26.030339Z digest=sha256:f4d4250d80fae5f88e2c04effab52a24e73397fda943ce76557ea3f67d11db67

Observation 0a0ab53c-274f-4eea-9840-214d7c8b968b · inbound

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses cites this paper.

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-04T09:25:38.687859Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T09:25:38.687859Z digest=sha256:948a1565503301b7aa70a99077e5a31007dec5b7f7c4a4284fec01dd2e43c419

Observation 23a7eeec-518f-4f7a-b732-bb2272008759 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 192

Resolution
verified exact
local_arxiv, observed 2026-05-18T03:42:22.400493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:c7447393e70cc2632b3276b5fc7c8d361d1f7d8aa83e115dd5373474e99bf125

Observation af809779-a57c-4792-a76c-53d8f178c1ca · inbound

Safety Alignment of LMs via Non-cooperative Games cites this paper.

Safety Alignment of LMs via Non-cooperative Games AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-03T14:24:20.592814Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T14:24:20.592814Z digest=sha256:6926c51107ee22a22d9ff9a1ecccc77ecc5bdbd990b3329b27727ef6b6c16b93

Observation f95c9a94-86ae-45ea-8534-980ab2ced78e · inbound

Beyond Benchmark Islands: Toward Representative Trustworthiness Evaluation for Agentic AI cites this paper.

Beyond Benchmark Islands: Toward Representative Trustworthiness Evaluation for Agentic AI AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2

Resolution
verified exact
local_arxiv, observed 2026-05-22T10:21:23.291188Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-22T10:19:56.003219Z digest=sha256:1318593063a219e0532653abbfba48cfb0c014ef6759174858df8b88156d1fd3

Observation 9a34f3ce-b1cc-4e89-9cd2-14cc4df36301 · inbound

Agent-Sentry: Bounding LLM Agents via Execution Provenance cites this paper.

Agent-Sentry: Bounding LLM Agents via Execution Provenance AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
verified exact
local_arxiv, observed 2026-05-15T01:18:26.431574Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T01:17:40.860439Z digest=sha256:d308c3c6066bd8d31ebcf76f354953e3d598da6724133aa10015f9b430c2cd73

Observation e84540e6-9de9-46d1-90cb-392d7ea970ad · inbound

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw cites this paper.

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 3

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T19:20:52.845052Z digest=sha256:8c3e4408bc606476ee4ac1537a382f8c5b99eac0b86297251ed61e27ab93c710

Observation 46f0b412-409f-4e5f-a34d-94fe5e00d6c6 · inbound

SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement cites this paper.

SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-13T11:36:41.748710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T11:36:41.748710Z digest=sha256:761fee48cf29afd7c55517d8cdfe1af1cdebb774fe1f3f73bb4af6e0f7836846

Observation 24362374-0bbb-43a4-acc9-54681f1918d4 · inbound

Swiss-Bench 003: Evaluating LLM Reliability and Adversarial Security for Swiss Regulatory Contexts cites this paper.

Swiss-Bench 003: Evaluating LLM Reliability and Adversarial Security for Swiss Regulatory Contexts AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 8

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T19:44:26.931344Z digest=sha256:6d52ecc5cccbcb091ddf6438d8e4d636e624e76eb0cb79340f1aa5414a46d513

Observation dc250877-5c5e-4f0e-acd2-3e99a8242651 · inbound

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection cites this paper.

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T16:05:47.517157Z digest=sha256:b9ce9658faa7ab762dc1a304e53ccd7b1badc4f9f7c8864e0070de91a9023f5a

Observation dfae0e02-d4a6-4fdf-af68-5b8ef8d4ae1b · inbound

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection cites this paper.

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-12T04:17:07.080092Z digest=sha256:daf15e65a444609944785f0da19891cc4da6a869772f05c892918f1418cc41c0

Observation e40f8581-2e32-4521-8b15-5c22de4f9974 · inbound

Policy-Invisible Violations in LLM-Based Agents cites this paper.

Policy-Invisible Violations in LLM-Based Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T16:20:14.720123Z digest=sha256:20ba2bf97c20ffb7a1c786c599956c2e528e40970fcfd4625401acb39f2b97e2

Observation d0dc535a-c74e-4d9b-9c85-398cc41c4ed7 · inbound

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? cites this paper.

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T10:32:37.967401Z digest=sha256:0b3264ac978e2c0a64316883327bf2cb94f5537fa8426922c85e92589f02fb78

Observation dc779b38-37e2-4cf6-99ab-44b2c25acc82 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T04:42:33.450658Z digest=sha256:0b2ae0fa01f0b3118702d188998d57a98c418dc48052f5656ca76195a31f44a7

Observation cd8b93cb-162f-45f8-90dc-b56fa9260764 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 5

Resolution
verified exact
local_arxiv, observed 2026-05-21T00:53:53.091146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-21T00:51:22.907932Z digest=sha256:7791ca2683e8b456dae2188e38b19d1e6dbe534f8ed6a96cb2a47dba5dffca1c

Observation 1c0a687c-91b6-4399-bc0f-cf50fca1128f · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T15:56:47.681500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:56:47.681500Z digest=sha256:1117ffa47fc5be0a74c96c111ddd5edb3129c5f0896acc216630ff27923fd508

Observation d27b412e-7742-4cb9-8757-67285e49356c · inbound

From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers cites this paper.

From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T04:51:51.568400Z digest=sha256:491eb9756e7bf8395366338aa958a1497dc1fcfdc3974c4d630764b59b87c784

Observation 9440cc5a-8988-43c1-b964-b4bb45ab179f · inbound

From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers cites this paper.

From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
verified exact
local_arxiv, observed 2026-05-21T01:19:20.951421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-21T01:14:48.342176Z digest=sha256:fddb49c980bdf97c108d556b01511811f5ea4f11dd36d2a341b4b8da63f7eb9b

Observation f7c9cc1d-0c58-41d8-8c90-507f96aac854 · inbound

An AI Agent Execution Environment to Safeguard User Data cites this paper.

An AI Agent Execution Environment to Safeguard User Data AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T02:14:40.639143Z digest=sha256:6ce19559748d3e984e6f091a05b15cf14101b6c554fa4a1e591ea4cabbce1fa3

Observation 8ca8a1fc-bb43-43ab-bc10-fff860a9b826 · inbound

Auto-ART: Structured Literature Synthesis and Automated Adversarial Robustness Testing cites this paper.

Auto-ART: Structured Literature Synthesis and Automated Adversarial Robustness Testing AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 37

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T00:39:43.196010Z digest=sha256:d0e4575095a4e8d2ffa31823f3cc615081b1f69aa46d46726828ae0a68a9b48a

Observation 942fe2a4-f747-4c9d-aa45-a1df055c4578 · inbound

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models cites this paper.

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T00:02:35.167281Z digest=sha256:5ece54cb6ab86d6d5c0b220609b26c8b9f4c89fe77c7a37159e7bdf528652701

Observation 91de15d5-2172-4825-8cf3-9540c8542154 · inbound

RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents cites this paper.

RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-05-08T11:26:53.382527Z digest=sha256:be0356a50ffaa4e04899b2d86820a923965707999af12e74b3571501e3842c7e

Observation 78e9fee3-194d-406f-80d5-f9cffbe1444c · inbound

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework cites this paper.

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 141

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T07:53:13.746141Z digest=sha256:26649f383eadf27a0547c8d6a3d52e7ad5a4a8263e4f6ef1747024f5fe430dd4

Observation bb1a6388-d31f-440b-b172-d05c4aa09739 · inbound

Alignment Contracts for Agentic Security Systems cites this paper.

Alignment Contracts for Agentic Security Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-09T20:47:28.506174Z digest=sha256:fa3f8ad5ef21c8ebddb30ef0cee46670af17ba38bf276f8eb72fdf161363c360

Observation 69c0d805-4a7a-4375-ac7d-71ddaa3a74e7 · inbound

Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis cites this paper.

Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-09T19:58:28.584941Z digest=sha256:e16498d119eaac6341afe0805636f0af12c294ebc5a40314d0e148560c6f8389

Observation 9ecdd87d-3bbe-4287-b4b0-76fc53ceb6f2 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-09T17:13:47.722098Z digest=sha256:0cbab89101034132e6d80f51ef2195858d0c688e6f7f1dd15956cdcd209eeb55

Observation 79808040-253d-4f7f-bfab-716add888dea · inbound

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates cites this paper.

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T19:17:06.375875Z digest=sha256:efa17b88918f73de4221bfdbbff58b96da1cc46c6f7405e41436a2fa961cb6f6

Observation 8617504c-fc44-42fd-9bcc-b0416d57ac27 · inbound

LoopTrap: Termination Poisoning Attacks on LLM Agents cites this paper.

LoopTrap: Termination Poisoning Attacks on LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T09:25:11.059634Z digest=sha256:0ea6d6173a664f142c89c60929eac4a18df27ea16d96cf6fd0c973ff09dc0fd6

Observation caedab10-38be-483a-a0d6-aa57bda95a27 · inbound

SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills cites this paper.

SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T09:33:30.464441Z digest=sha256:0980abc75b0c3f8c835de680d071ab74155b95d3cc55f48aba00d8c650e636ba

Observation 3790cb3c-65a3-4eb4-9d82-9fa95ff9aab5 · inbound

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation cites this paper.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:f04fab6d9d749b0eeffd70081617ac2f3387028da7b3cecff22489eab03e486e

Observation 1b876bbc-9c86-408d-8e5b-5b81ebe6e118 · inbound

Can Agent Benchmarks Support Their Scores? Evidence-Supported Bounds for Interactive-Agent Evaluation cites this paper.

Can Agent Benchmarks Support Their Scores? Evidence-Supported Bounds for Interactive-Agent Evaluation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-12T05:05:55.592359Z digest=sha256:e70120804541ea287aebe30f1b82c4014106b4f8b3ec3569e741123e50442645

Observation 8f512b75-6b18-4819-a9fb-50ec2961aaf3 · inbound

Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems cites this paper.

Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-12T04:17:12.046360Z digest=sha256:84525321d7a60001d013fea5424f3a013ba965a81f29ef6337e83ea35df32aa3

Observation cb26b08e-4fd7-494a-8888-e51de008dbc6 · inbound

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents cites this paper.

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T01:31:34.468389Z digest=sha256:85a0d264cf1b121d0a3128a59bcf403151a8d4076f467598ed81c056ae1d54a0

Observation 11a01580-ed35-45a0-9875-4b5092d32e16 · inbound

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection cites this paper.

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T05:46:07.132408Z digest=sha256:9d4cfb822dda8151b67815ddf066593dfb513f300e1794b612df11d817efe3c8

Observation 879c3eff-4e41-44a0-a7f3-22f72b08b904 · inbound

Language-Based Agent Control cites this paper.

Language-Based Agent Control AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
verified exact
local_arxiv, observed 2026-07-01T14:25:45.923788Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T21:41:37.021482Z digest=sha256:4096a88074fad9dc684eafc2b21f505fe47a9dfbd45f1e5b8861161656be346f

Observation d3efb9a7-d109-4a21-850c-fa349aed3050 · inbound

Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents cites this paper.

Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
verified exact
local_arxiv, observed 2026-05-14T18:22:33.630937Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-14T18:21:06.872045Z digest=sha256:9445b5a777fce5cdc98dc04f75dfd33945b0a8be6d15aad967b05268a44ba92e

Observation e3f6b385-ca71-4e0c-a6e9-df57d030bc0c · inbound

AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills cites this paper.

AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 3

Resolution
metadata mismatch
local_arxiv, observed 2026-05-15T05:45:06.738689Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T05:40:52.709457Z digest=sha256:cd049161836fb050474eac402960d2499a33f24a5a149df67b998024802aef73

Observation 5fe32da3-8e3c-4503-9be4-9a793e562934 · inbound

Web Agents Should Adopt the Plan-Then-Execute Paradigm cites this paper.

Web Agents Should Adopt the Plan-Then-Execute Paradigm AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 8

Resolution
verified exact
local_arxiv, observed 2026-05-15T02:43:33.390770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T02:42:05.644536Z digest=sha256:fb46e8c85f69a60e7fc8b07d8e0f86c147e95c68b2ecdd2dff319973d407a5f6

Observation af150bb3-df58-4229-9cb1-9952b74d847a · inbound

Do Coding Agents Understand Least-Privilege Authorization? cites this paper.

Do Coding Agents Understand Least-Privilege Authorization? AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 33

Resolution
verified exact
local_arxiv, observed 2026-05-19T16:37:40.072263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T16:34:14.379419Z digest=sha256:cd27102f80419f3df12c3184662fac0d6e66e361639c893b3c6d3afe082b23ff

Observation 317b4b9f-2ad6-44b5-87e3-6709fa52abb7 · inbound

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents cites this paper.

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-05-21T01:43:56.937545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-05-21T01:42:55.693115Z digest=sha256:59025647cb8d7c00e0a614334a660a0df27345f8e04c7de892b501409eaedb0c

Observation 9a9291f2-2fda-4ca3-beea-e84e0c920e30 · inbound

Securing LLM Agents Need Intent-to-Execution Integrity cites this paper.

Securing LLM Agents Need Intent-to-Execution Integrity AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 27

Resolution
verified exact
local_arxiv, observed 2026-05-19T20:17:45.538684Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T20:17:04.049686Z digest=sha256:e5f52de946d8aab871307cf05b2bd810b367ef30c82cd4fba87de63cfd8cdbd1

Observation 02e55ae4-2c9b-42ba-a2b8-7a7087d6f24a · inbound

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments cites this paper.

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-05-20T09:58:10.834218Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-20T09:58:05.349147Z digest=sha256:6a84f975f0e65395fba23eab5e66a194ef6456acd48902a358d167a707d00088

Observation aec41180-216c-4bc0-969d-f7424c34cf6d · inbound

Opir: Efficient Multi-Task Safety Classification for Toxicity, Jailbreaks, Hate Speech, and Harmful Content cites this paper.

Opir: Efficient Multi-Task Safety Classification for Toxicity, Jailbreaks, Hate Speech, and Harmful Content AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 8

Resolution
verified exact
local_arxiv, observed 2026-06-29T09:13:16.008758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-29T09:11:58.843585Z digest=sha256:c1084ec795ced2d47e230c5a0c5dc390a756912aaad62ebc10721ad60c8c5eac

Observation 18bb0984-6bd1-46ee-b277-35e34aad5b46 · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 23

Resolution
verified exact
local_arxiv, observed 2026-07-01T23:36:22.954847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:0b8e3122aaee8386f27a76ab7acd9d57ac88ea311ed7e826937861fc4eed09f1

Observation dde41c9f-18b0-4c51-b51b-0e7622e8179e · inbound

SkillGuard: A Permission-Centric Framework for Agent Skill Security cites this paper.

SkillGuard: A Permission-Centric Framework for Agent Skill Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-07-02T03:26:28.567926Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T10:07:36.872590Z digest=sha256:81f517f03cdce85d3f01923f44dcc7661c9f91ddde2ffb508ccad76a448cb722

Observation 5542bc3e-7415-4e21-a4f5-99dc34860483 · inbound

SkillGuard: A Permission-Centric Framework for Agent Skill Security cites this paper.

SkillGuard: A Permission-Centric Framework for Agent Skill Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-14T18:32:00.165926Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T18:32:00.165926Z digest=sha256:fbaddd5a5d28c85dd2b3172847f1632c79e67b86b0993d49f9b9d17a6faf50a9

Observation 7d11ff01-04da-495c-8f7b-104026eb1327 · inbound

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents cites this paper.

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 5

Resolution
verified exact
local_arxiv, observed 2026-07-02T04:16:36.065303Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T09:15:57.044886Z digest=sha256:c2b7925f937089b8aec7b28e2140901eee781646cd71289e28a07773893c3686

Observation e4a7d3ec-6a9c-4bdc-b63c-7740c646021b · inbound

Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming cites this paper.

Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 4

Resolution
metadata mismatch
local_arxiv, observed 2026-07-02T08:06:48.201108Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T06:22:03.848058Z digest=sha256:83c4002f58031b515dab85179128b5c2a0b5c47cba70557088e610891d06b141

Observation 7c95bd8e-460c-43b9-893f-2beaa62f3b76 · inbound

MalSkillBench: A Runtime-Verified Benchmark of Malicious Agent Skills cites this paper.

MalSkillBench: A Runtime-Verified Benchmark of Malicious Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-06-27T21:51:18.647089Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T21:44:55.308871Z digest=sha256:beba89f61d1e6414aeb51494312dfd6f49d02314ee2c1ffa8117b24affc677a9

Observation bbf746c7-10c3-4c38-b8bc-ada130482443 · inbound

Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems cites this paper.

Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 17

Resolution
verified exact
local_arxiv, observed 2026-07-02T17:47:17.795514Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T21:53:37.616447Z digest=sha256:51835f6a52e99a399c1f3df761b278b7dd672a2bdfe9b6747058ba7b1c3404da

Observation 7d99e4e1-789a-4268-a8d1-eb3e35aef32e · inbound

What makes a harness a harness: necessary and sufficient conditions for an agent harness cites this paper.

What makes a harness a harness: necessary and sufficient conditions for an agent harness AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-06-27T19:31:10.763998Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T15:15:57.372858Z digest=sha256:b911e2b6ed356b28a1a60024ee92ecdc548d68917d2cef8961453c2c8541ffac

Observation c6256fd3-9d9c-478a-ae6a-deb9bdc6208d · inbound

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents cites this paper.

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
metadata mismatch
local_arxiv, observed 2026-07-03T04:57:38.189356Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-06-27T13:33:24.087333Z digest=sha256:a69b68f7d6697da8e657fdaea36e65aeafa77add15f52a3b3acd209961155269

Observation 63c68b64-6b2c-45f4-8e3e-9181647187e7 · inbound

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs cites this paper.

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 17

Resolution
verified exact
local_arxiv, observed 2026-07-03T05:47:41.217168Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T13:05:57.618969Z digest=sha256:ac063c8f5d991f82a554cf0844732675aa46fb7d41d3758e18ef9d1102368e9e

Observation 178ae034-1097-4fcf-b79e-8610f6c32b11 · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.857461Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:709aaef57e6d9140a950ed094d324d1971cbe720c6f09be3be1879dd5219056e

Observation f100781b-b9ed-464d-9b28-86f172f8e45d · inbound

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval cites this paper.

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 36

Resolution
verified exact
local_arxiv, observed 2026-07-03T11:58:06.309031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T09:13:58.485088Z digest=sha256:bdfa429b8948ba111d0e282b8f3ea131c41c00c2dc05d88ebc95d48a186e0ab6

Observation 7e8ba950-a637-4bdb-9b18-24c5e7d9b125 · inbound

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents cites this paper.

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-07-03T10:17:57.602508Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T10:09:35.461423Z digest=sha256:b76a11f5bed4349134b3c5f418ed33d4722f22dadcac37feb6b7e44983b4a32c

Observation 500e4ca8-4171-41ed-8beb-803f4e90a215 · inbound

OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents cites this paper.

OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-07-03T11:58:06.918487Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T09:11:42.204778Z digest=sha256:021000105b94f97a37d4d365364f5a8bb94f37d832eab65ba02b6cad0545824b

Observation dda5fbee-69a1-43b6-949c-1f47710b80df · inbound

An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios cites this paper.

An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-07-03T17:48:46.340833Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T03:39:36.657903Z digest=sha256:ce03c06f8a74fc4d1748b1897e64926ff0a835bd5f15777572bc501753707758

Observation b3d83305-a218-4ca3-b110-60ba7af92010 · inbound

SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents cites this paper.

SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
local_arxiv, observed 2026-07-03T22:18:59.725787Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T23:40:53.439549Z digest=sha256:bf1b77f53c400d5d6b7eb5e6d3ac0fbb032ca059c358e85a4380c1c4c952dcaf

Observation d1a3f0ae-45e1-4bc2-9898-b77884e37346 · inbound

The Gate Is Only as Honest as Its Contracts: ContractGuard for the Contract Layer of Risk-Aware Causal Gating cites this paper.

The Gate Is Only as Honest as Its Contracts: ContractGuard for the Contract Layer of Risk-Aware Causal Gating AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
local_arxiv, observed 2026-07-04T00:49:18.321344Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T20:58:24.056435Z digest=sha256:f4674cecb8f1542b82f20c7ac10293f89006246e98c9893f6f4152690c1f31dc

Observation b8ef15ad-48ce-4796-962e-2c398d00f31d · inbound

Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference cites this paper.

Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
verified exact
local_arxiv, observed 2026-07-04T09:19:44.168714Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T10:07:23.015655Z digest=sha256:8a6616a58e0e69bdfda962ff781e1232b905ceda907579e76afb6a75c3bbb471

Observation de6b5fe5-d724-4c49-8866-523c5e1b536e · inbound

PhoneBuddy: Training Open Models for Agentic Phone Use cites this paper.

PhoneBuddy: Training Open Models for Agentic Phone Use AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 69

Resolution
metadata mismatch
local_arxiv, observed 2026-07-04T10:59:46.403482Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-06-26T08:15:49.428124Z digest=sha256:702134683d0453920a7e715822d6cd9e51576d963c04b2c9e1d724a5e938d277

Observation 609c963e-c9a5-4b8d-89fc-e3c4770727a8 · inbound

AdversaBench: Automated LLM Red-Teaming with Multi-Judge Confirmation and Cross-Model Transferability cites this paper.

AdversaBench: Automated LLM Red-Teaming with Multi-Judge Confirmation and Cross-Model Transferability AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 3

Resolution
verified exact
local_arxiv, observed 2026-07-04T17:20:00.224489Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-06-25T23:49:17.752279Z digest=sha256:b9aff4b36324613b2d2284bc71c6d30708ae4aac3985823aafecb61aa9f71b4c

Observation 865d15c6-7e04-4b67-8ace-521e01645232 · inbound

Instruction Bleed: Cross-Module Interference in Prompt-Composed Agentic Systems cites this paper.

Instruction Bleed: Cross-Module Interference in Prompt-Composed Agentic Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
metadata mismatch
local_arxiv, observed 2026-07-04T15:19:56.808838Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-06-26T01:42:22.071423Z digest=sha256:3c21377988259fb1845a94130830fdf3a7a526a675717193874d9530be10f419

Observation 3ba48789-8040-4847-a1ec-918f892bfd72 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 37

Resolution
verified exact
local_arxiv, observed 2026-07-04T13:39:51.365420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:016859021f053a3d52c2f25777a6c3ecc904f9a18d9dfb79d60e278781e126d8

Observation 4c7e139a-087d-4712-bdc2-72ba58177369 · inbound

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents cites this paper.

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 29

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:09:53.245984Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T04:29:16.386339Z digest=sha256:b85e6c0cdda7d777b5c0b75560b2d52ca540fb7542d5644482a7af0959c96162

Observation facb84fe-9fec-4969-ae71-36147ca8ca32 · inbound

Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks cites this paper.

Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-06-30T10:14:36.003989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T10:13:22.634230Z digest=sha256:d16d62c2f4c87187648e1bc1f62a215f9c3304c1d1fd8ae34a897a83f441acaa

Observation ee39c90f-3b38-4d15-85f0-6f3b8bc86c95 · inbound

From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes cites this paper.

From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-06-30T09:24:32.785879Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T09:15:20.593625Z digest=sha256:712428533adc490d68ca3e476c1b037071161fd6f08c5f499d570e83825c605a

Observation 50867cfe-172d-4bf7-82ba-972feaa49ee4 · inbound

PolicyGuard: A Dialogue-Grounded Sub-Agent Verifier for Policy Adherence in LLM Agents cites this paper.

PolicyGuard: A Dialogue-Grounded Sub-Agent Verifier for Policy Adherence in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 22

Resolution
metadata mismatch
local_arxiv, observed 2026-06-30T07:54:22.256590Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-06-30T07:48:36.924294Z digest=sha256:088a2479e31c2c1aa7f251c27d3ca078df2c27e665ce3c72ff3caf5b08fba500

Observation a21b9661-8786-45ee-bac8-a9c50c9ec0c5 · inbound

OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks cites this paper.

OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 12

Resolution
verified exact
local_arxiv, observed 2026-06-30T07:14:21.219776Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T07:10:38.909339Z digest=sha256:7d437fa90e26b5093358541d4f20e3c333ff06529fd642156ed52fcefa2a2050

Observation 0822cdb2-d7f7-4e3d-bc79-e97693caba7d · inbound

OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks cites this paper.

OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-07-15T10:24:53.345620Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-15T10:24:53.345620Z digest=sha256:1af02f34a34d4b841e0f4bb46e5935281a1839d4deb4aedaddb4099b7bda16aa

Observation af5a73e0-915f-4a68-b848-f0658247918b · inbound

Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents cites this paper.

Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
metadata mismatch
local_arxiv, observed 2026-07-01T15:15:48.384194Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T03:44:51.320606Z digest=sha256:de683afd47c4e7bc1402047c5c4f56d106b16d89daeacf892ff82597ec965c7f

Observation 198a9dd2-5b7a-41eb-ae77-7435b508e571 · inbound

Whose Side Is Your Agent On? Multi-Party Principal Loyalty in LLM Agents cites this paper.

Whose Side Is Your Agent On? Multi-Party Principal Loyalty in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-06-30T13:44:41.466230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T05:48:15.990443Z digest=sha256:6a50a8ab145e4f931f5047c9d1773eecbc970b31e5fb86ea552f62beaeb4cab3

Observation dd5f8aaf-afc2-4f4a-90bc-403fa1db3591 · inbound

The Decomposition Is the Fingerprint: Per-Component Identity for Agent Skills cites this paper.

The Decomposition Is the Fingerprint: Per-Component Identity for Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
verified exact
local_arxiv, observed 2026-07-01T10:15:44.226042Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-01T05:44:44.015852Z digest=sha256:7b0564f9e704caabe374cc8c15e5b0a218845b4f65a523b846f4fcd317023f6d

Observation a8ae2483-73c7-457d-a3e6-fd0ce874e158 · inbound

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems cites this paper.

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 31

Resolution
verified exact
local_arxiv, observed 2026-07-01T11:05:42.304149Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-01T04:44:23.543728Z digest=sha256:f9bc184bf812b0c225d300d304808557e661b861090c0a29a2c27e824fedd395

Observation c0db0c18-7085-42b6-aca0-8029263558f4 · inbound

MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents cites this paper.

MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-12T06:34:07.307906Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T06:34:07.307906Z digest=sha256:ca35a64ed44c3d9d6c91d8fd78bfd054effc4a85566dc97aff7894ecf27e3add

Observation 1bda5eb4-8c60-4fa4-85c1-75185cd8d7eb · inbound

PatchOptic for Shared-State LLM Workflows with Projected Views and Verified Structured Updates cites this paper.

PatchOptic for Shared-State LLM Workflows with Projected Views and Verified Structured Updates AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-11T07:27:13.586286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T07:27:13.586286Z digest=sha256:373f67b3ec65bde380db087aee9e88cfb34895f1682c602ed1501a2d87546742

Observation c0ddd73e-d30e-463a-83c4-e9b2723a7a75 · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 25

Resolution
verified exact
local_arxiv, observed 2026-07-11T02:47:49.893444Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:558a46604cb422cd82abb111c3ce5a5dc67a9246656314b17d0498519a758dd3

Observation e19acec7-242c-473c-ac4b-852b39f7b1aa · inbound

SkillCenter: A Large-Scale Source-Grounded Skill Library for Autonomous AI Agents cites this paper.

SkillCenter: A Large-Scale Source-Grounded Skill Library for Autonomous AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 33

Resolution
verified exact
local_arxiv, observed 2026-07-09T03:05:54.910197Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-09T03:01:02.743557Z digest=sha256:81eb21e7151a31411733be852ddf22c96b3036cf8b46a0e7b98c005a5b4c5fad

Observation bb9fffc1-fab4-4989-8e6a-5364c47ebf1e · inbound

Cross-Layer Misalignment Detection in Agent Skills: A Progressive Loading-Aware Contrastive Learning Approach cites this paper.

Cross-Layer Misalignment Detection in Agent Skills: A Progressive Loading-Aware Contrastive Learning Approach AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-07-14T11:00:53.732771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T11:00:53.732771Z digest=sha256:77989a61afca65a28fd07fc5632bd1558d22b31cc9b3af253c14cc2016f0c559

Observation 045f7432-0ec7-4939-ac6a-0f1652381e62 · inbound

Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability cites this paper.

Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-14T07:09:56.559355Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T07:09:56.559355Z digest=sha256:7f64b66c5119fa80835a5f6a0bed8911979309e2b7d60e6582c7eacf2ed46192

Observation 77db2a3f-1581-4c02-8689-f5739195167c · inbound

When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems cites this paper.

When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 3

Resolution
unresolved
no resolver link, observed 2026-07-14T03:26:15.676915Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-14T03:26:15.676915Z digest=sha256:a8a8452f4bbcafedbf2e44eb9a2ea7eb0993a86c6c20472098b933f5180d054e

Observation 0ffe9b14-f5a6-47c1-9b4a-ea6780a7c09f · inbound

Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives cites this paper.

Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-02T05:15:04.635408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T05:15:04.635408Z digest=sha256:e2679aef34f6a3d5b564f5c80d7129547efaab8c96f410cd8368615fc37b9eb3

Observation ffc75da8-0cea-4346-99f2-95bdd71fb870 · inbound

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control cites this paper.

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-01T16:35:19.029397Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T16:35:19.029397Z digest=sha256:5da93e0f8589bb97ca066d0bb81e8042588db315ac7715bbc210612b663a284b

Observation 20af0eb7-595f-4044-ac48-05c1df91ff6a · inbound

Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security cites this paper.

Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-01T16:19:08.615174Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T16:19:08.615174Z digest=sha256:b6329ed0d92c6f7b6b368edb1c07d44df3589179d6484816f6eff66ccf19b2fc

Observation 82f28bfb-55d9-45a7-98a4-e743b9210001 · inbound

They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface cites this paper.

They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T12:59:47.924753Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T12:59:47.924753Z digest=sha256:0a6607a3cdf3b439514d26aa4cdff8efd84bcfa3dd738391c4066feb708c6d5e

Observation 707e6df5-b157-4010-89ce-b5f06de4baab · inbound

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests cites this paper.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.184109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.184109Z digest=sha256:d6ca72cbd8128ce89030cc7b050fa23d64a93665143287e6e5be530c6108c810

Observation 03d99116-2a6c-42d7-a133-65f741bf37b5 · inbound

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents cites this paper.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.522434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.522434Z digest=sha256:6ed215a3bba9e84924eb61fd5372edc93f44e348504938182ffadeaadc5795ea

Observation ed1c6a41-01bc-413f-afda-f1ea1b4c21b3 · inbound

Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents cites this paper.

Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-31T10:25:15.498142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T10:25:15.498142Z digest=sha256:204846331ac327a1441b1069ed398aa15adce2d9e1baddfac58c6e1bc98a7dbf

Observation 293a6212-7cae-4f9a-bf56-d3a53af48d8c · inbound

SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems cites this paper.

SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T03:01:01.131934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T03:01:01.131934Z digest=sha256:758def8135a370622a6bcc131a73a60f0101f730627f0f2e50ea82c16bb31db9

Observation 7be87c14-6d5f-4a38-83dc-6b1456f5942a · inbound

GPT-Red: Automated Red Teaming via Self-Play at Scale cites this paper.

GPT-Red: Automated Red Teaming via Self-Play at Scale AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T01:12:44.130108Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T01:12:44.130108Z digest=sha256:9be02a916bcb1dd4ee72f6addd80e7296cbf3e8c174bdff8abf2c945d32c17e9

Observation a0a97666-e4d5-465b-be62-c1bad4654660 · inbound

FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs cites this paper.

FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T11:00:07.379881Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T11:00:07.379881Z digest=sha256:913ca040c2ce3d51998d250812a1bc42169729f1f75897a1b40b6fef261eea8b

Observation a07a1851-a34c-4d38-99bb-677067aee1d7 · inbound

Safety, or Just Capability? A Validity Audit of Agent-Safety Benchmarks cites this paper.

Safety, or Just Capability? A Validity Audit of Agent-Safety Benchmarks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-03T00:45:58.624640Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T00:45:58.624640Z digest=sha256:869c2c8644bee16ce0f4149e1ba3b72b304e7b63409f54b4fdee392804fe1d9c

Observation 742e4277-9a71-49de-9c24-87fa0d59f084 · inbound

CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents cites this paper.

CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-03T12:01:12.135104Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T12:01:12.135104Z digest=sha256:c4965afb7ce16b10e37ca9b533e248af4d0921b79782e22dfc65bf5af9e37112

Observation 44fb06ff-73b0-4697-b56b-6f6f22096a90 · inbound

Beyond Component Testing: Validating Agentic AI Systems cites this paper.

Beyond Component Testing: Validating Agentic AI Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-03T07:41:24.239002Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T07:41:24.239002Z digest=sha256:f07740faccefb4a5f0aff1fb81ed7abadc492dfff0a4754941385eb608850311