Pith. sign in

Paper Citation Record · LEDGER

AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

As of 11 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 51 inbound Pith citation observations for arXiv:2407.12784.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2407.12784 v1

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 51 of 51 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00

measured 51 of 51 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-11T04:46:07.020415Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

9
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 5cfcf83a-be81-421e-82a6-f48ab34cadbc · inbound

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents cites this paper.

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 91

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.109054Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=arxiv_source observed=2026-05-12T13:36:57.011451Z digest=sha256:81fd54e5a816cd2bf9dd0cfade998f93e3efc69aba4153da770b3f95b554253c

Observation 31e42e9a-df9a-4191-825f-6f337a7fcd28 · inbound

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents cites this paper.

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-05-14T01:35:51.271144Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=arxiv_source observed=2026-05-14T01:35:50.992477Z digest=sha256:b389bcc9ad9a29a411823edb3c0c80bac6c7c694bf9231f9df62e39b2f50d34a

Observation 3daf39e5-a1f0-472b-ad1f-5402d4e215c9 · inbound

Defining and Detecting the Defects of the Large Language Model-based Autonomous Agents cites this paper.

Defining and Detecting the Defects of the Large Language Model-based Autonomous Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-11T04:46:07.020415Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T04:46:07.020415Z digest=sha256:9f2497aefe772a0df0c5a8fd400dc2b06fcf86c5b54cd0e5d73a50dacefc2519

Observation 28c74b67-2321-4a39-b155-cd3080f3a81a · inbound

Beyond Reward Hacking: Causal Rewards for Large Language Model Alignment cites this paper.

Beyond Reward Hacking: Causal Rewards for Large Language Model Alignment AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-10T19:55:50.530651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-10T19:55:50.530651Z digest=sha256:72ca0058efabe1c5fdf980b63569c0823e94f799c79c3ebe61fa128babda6d40

Observation be427a9f-f618-4f83-86f3-7b787b629d29 · inbound

A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations cites this paper.

A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 112

Resolution
unresolved
no resolver link, observed 2026-08-09T00:50:00.479235Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T00:50:00.479235Z digest=sha256:b476f480f492d5a44d492ad3de6778bbb120d95cfee0bb68b6700ed931e10214

Observation 7d3be1a2-b8fb-4a6e-849c-808561abf87a · inbound

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks cites this paper.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2017

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.364091Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.364091Z digest=sha256:1de62ad7911d97cc1cdce5504f984736fcf294c79b8b6bfd167de99551fa97b7

Observation f429a656-02b3-4290-ac26-9fb1f3fdf92c · inbound

Report on NSF Workshop on Science of Safe AI cites this paper.

Report on NSF Workshop on Science of Safe AI AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T23:01:43.172473Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:01:43.172473Z digest=sha256:a53832ca20dee33a892387475d730257182305f8347eab5d0d055179e65d060e

Observation 3fc33e66-667c-42e2-854d-96ffaa93215f · inbound

Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques cites this paper.

Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 167

Resolution
unresolved
no resolver link, observed 2026-08-06T16:24:30.470926Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:24:30.470926Z digest=sha256:94c4cdf06a81cf2907b4287037ecd38c7d2f0860d9718a053380d6d8692f79bf

Observation 1b2b7402-03bb-4e96-9078-9a9b26b4179b · inbound

From Seed to Harvest: Augmenting Human Creativity with AI for Red-teaming Text-to-Image Models cites this paper.

From Seed to Harvest: Augmenting Human Creativity with AI for Red-teaming Text-to-Image Models AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T14:45:20.413049Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T14:45:20.413049Z digest=sha256:c6615b1d6430046e6fc66833f0d3480c4998257648e1e876a132ecb7492daf58

Observation 33451500-2922-4100-8d9f-25563c283b73 · inbound

Evaluation and Benchmarking of LLM Agents: A Survey cites this paper.

Evaluation and Benchmarking of LLM Agents: A Survey AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T12:44:21.530025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:44:21.530025Z digest=sha256:b49f5a274d5f707a3b58f012bbf7a24a91d3052b9c59fc32b10bff930a26399e

Observation 0eeb9873-0e1e-404a-9666-4243f9eb9691 · inbound

Adaptive Content Restriction for Large Language Models via Suffix Optimization cites this paper.

Adaptive Content Restriction for Large Language Models via Suffix Optimization AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T05:53:58.311875Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:53:58.311875Z digest=sha256:d17556b087a1c798f629f39e2a56e85922927d00f3ae25a2c159f181e382af43

Observation 775c5b2b-5fa9-4dd4-ad9e-07ac9ea80e56 · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 152

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:46.673384Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:46.673384Z digest=sha256:5bb336a84ffff3f6a955f81222e0eaf8e6c786b4d9e6feff16815bafc00f17a6

Observation 1b8bdbd9-4ff1-4dee-a03b-f658ca9d67c1 · inbound

A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See cites this paper.

A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T14:20:11.612893Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T14:20:11.612893Z digest=sha256:7ce0d148f26602f7326cb3b4ee4dad6fcbd67a9dd77e85b20b0b2299271fa770

Observation fcde5a73-f3cd-43e1-b136-ffb441eeaac8 · inbound

LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems cites this paper.

LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-04T17:46:15.064636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T17:46:15.064636Z digest=sha256:d537d0024b1917ac04ca166270293ef4f40c8fb81705710cb81662ab36f81e25

Observation 00be42cd-3382-4fa4-9220-cd11eb44916b · inbound

Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval cites this paper.

Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T19:27:04.067874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T19:27:04.067874Z digest=sha256:e1151f0d8543b94ffec8dfc7ec1890f796aa4d62be208a31090b485317648d1b

Observation 1c56c68b-b20a-42bc-ac3d-92179512421b · inbound

How Well Do AI Systems Solve AP Physics? A Comparative Evaluation of Large Language Models on Algebra-Based Free Response Questions cites this paper.

How Well Do AI Systems Solve AP Physics? A Comparative Evaluation of Large Language Models on Algebra-Based Free Response Questions AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 38

Resolution
unresolved
no resolver link, observed 2026-07-15T13:15:31.225992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-15T13:15:31.225992Z digest=sha256:e1c779f51651f2e6b898eda51bd3c7f29d0bc15e82526c0b3c70a55d3ebc3dfe

Observation 7e6c1aa8-ba7e-4997-9a73-3ae484825a58 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 88

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T14:15:55.919512Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:e161c9ed2b1f38a6786d0122dea2a83606b565808c531f63b6182cf4548e9e20

Observation 001b5b4e-cb7a-4a58-90cc-94b4585e9216 · inbound

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw cites this paper.

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T23:05:49.143007Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-10T19:20:52.845052Z digest=sha256:fd6a3f4536e42121f1c62fb966b7c8f631ebbefbd2311b0c697f85465fcdd83c

Observation 22702ab2-e43c-4599-bc3e-d96b2b602d23 · inbound

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs cites this paper.

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:11:05.393842Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-10T15:06:43.140580Z digest=sha256:972c2cbb1d845b9f248e7e3049598dcd44a1930f32221217e2955c20e1c77e3f

Observation 08eba912-b742-4998-8cbc-6336b23982be · inbound

An AI Agent Execution Environment to Safeguard User Data cites this paper.

An AI Agent Execution Environment to Safeguard User Data AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-11T13:11:05.899324Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-10T02:14:40.639143Z digest=sha256:ed3e9e80573ab277246a43b36044a11c2dffeddbdd05e07b87b9bc0afcae3a72

Observation d5f87eb4-697c-4701-b6f8-ea700a2e9fcf · inbound

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework cites this paper.

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:51:09.036744Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-08T07:53:13.746141Z digest=sha256:565fe101ad6014ca19736a6d5445d21d3d31134c50aaf91b232f6a38240ccd9d

Observation 82b6be5e-6ddc-4568-9fde-11b86519cff7 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-09T21:38:30.740427Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-09T17:13:47.722098Z digest=sha256:ab6535db3871180586e57ac400bdb33154c581ec09b3aa850a2367d662b954c8

Observation f596f878-f217-4937-87ad-021b972e0335 · inbound

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios cites this paper.

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T23:31:13.050357Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=arxiv_source observed=2026-05-07T16:57:28.155229Z digest=sha256:92eb27e35a7d40ef003fe0465abadb31e3e20765d2c2e3f6c9bb3c1a7d83e45d

Observation 1eb65ed0-2dcb-4a39-933c-3a0b924afd96 · inbound

MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents cites this paper.

MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 4

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T00:01:14.267439Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-07T15:57:39.809778Z digest=sha256:4ae9d01732cae4fd38c988cffe93a2af2d0815f5f7008a6c76ec64da3e58d358

Observation 66696e20-0b76-4694-893d-c150e2d4b973 · inbound

MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents cites this paper.

MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 4

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:10:41.460813Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-08T18:50:41.401393Z digest=sha256:82763d117f413ac5bf08a6cbd818dd816e0fa47561ce9957d5e0fbca6130cf6f

Observation feca86c2-699d-439c-862d-c539df9af9d4 · inbound

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation cites this paper.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.087888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:59cf1a055233a816302e7ae9283e602dbd99db02d108fa23337bb50441ca1858

Observation 056d4b75-b4cb-4f89-969d-40572e6b79d8 · inbound

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts cites this paper.

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-12T07:37:04.869744Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-12T02:27:03.154390Z digest=sha256:782bc42427db3ba85896229a4ce87289ddc24c37bfa13c35fb7602a44dca431e

Observation d89984f9-e28a-47cf-9fae-31ded5417a31 · inbound

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts cites this paper.

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-15T06:09:49.147914Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-15T06:09:36.338641Z digest=sha256:6924bfe89fc4b38774466a19cd8f779662ce13913c1424762112261a2358d49e

Observation 0744b8cf-b3f2-44a3-9332-671e32c74815 · inbound

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts cites this paper.

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-19T17:42:42.343448Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-19T17:38:45.919637Z digest=sha256:06452fa8d4cbe19b635d4b34c2fd4f28e028d34cdf314cd1950ca15b1b960be6

Observation 6f24d99b-ca39-4adc-9aad-f81134e994c3 · inbound

MemLineage: Lineage-Guided Enforcement for LLM Agent Memory cites this paper.

MemLineage: Lineage-Guided Enforcement for LLM Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:23:31.637232Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-15T02:21:32.356516Z digest=sha256:1679fe32c2bc6070819dc91a1974f99a12458f05e7db22e07de2c56e047b92aa

Observation 4b9fdf3f-7778-40d7-9dd2-9f12810ad2a9 · inbound

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents cites this paper.

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-21T01:43:57.001946Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=arxiv_source observed=2026-05-21T01:42:55.693115Z digest=sha256:f1ba2533ba5a9ecda7157ec136304faeaab4aa3a2fee9ace683061c4e1adb3e0

Observation d0944feb-5abe-49be-8a9d-ff46edd4414d · inbound

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments cites this paper.

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:58:10.927620Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-20T09:58:05.349147Z digest=sha256:4aed2fd1cafde0e81ec2efbd111f38c0c9ea414fb0a30a252537db75f2ac473a

Observation 885b460a-9981-4218-8503-be554bbee6e0 · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-22T05:51:08.079203Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-22T05:50:28.114140Z digest=sha256:4ce5bdd47e08ef1c8425e31b215beff6a74d1982d209f3c041249c4876380359

Observation 5dbe1982-4951-4ba8-8a69-6af267fa387d · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-25T06:06:43.041641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-25T06:05:27.736494Z digest=sha256:3a5ac9ea94ac33a3c6b5674a7e4b19f6635123c5534440107fc66bf7891028de

Observation dd122455-abff-4fbf-afc3-00c38deb1e40 · inbound

Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof cites this paper.

Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-07-01T13:35:46.625765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-30T22:57:58.989954Z digest=sha256:eae5905d51bae839a019594f7926c9bc36243563964cef3eb93f07f9864cf8fc

Observation 0e5802d9-c1f3-4928-af7f-89335483ebbc · inbound

MRMMIA: Membership Inference Attacks on Memory in Chat Agents cites this paper.

MRMMIA: Membership Inference Attacks on Memory in Chat Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-29T12:13:27.069505Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-29T12:04:53.511344Z digest=sha256:c1c8d128bd4b318a8548bcbd96d6136b68a18bba2033a97fc5e1b33696134b38

Observation 52671b79-e699-4221-8cdc-6a0ccfbf57f2 · inbound

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors cites this paper.

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-06-28T22:12:41.452735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=arxiv_source observed=2026-06-28T22:06:41.245543Z digest=sha256:fa4ac07420a0c988291781c20a82a1ed858d69868046502a4e4f6c493c79df8f

Observation b1cdde4e-44b8-4f45-9784-86217c2dbc46 · inbound

Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems cites this paper.

Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-02T17:47:17.779501Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-27T21:53:37.616447Z digest=sha256:54aef0d40c3acf124e76192b644d6d6bf75b81a4962634422838bb22e10527d8

Observation 068d0dd2-5733-4988-809f-2d6de2f4c3a0 · inbound

Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs cites this paper.

Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T01:07:30.147675Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-27T16:49:14.243931Z digest=sha256:08c3a6dddbf32a08b7607868060a90b4145e453ef589d35516a69e8a82afabee

Observation b7652133-b240-4baf-939b-c5405616b075 · inbound

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval cites this paper.

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-07-03T11:58:06.290527Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-27T09:13:58.485088Z digest=sha256:7ae9e44adc9904bd359fab87d5035d4bfec22c2cba379d928a68fdca1cceed55

Observation 8b842b60-a1e6-4660-969d-f34e9af75f3e · inbound

SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems cites this paper.

SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-07-03T12:28:07.763218Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-27T08:58:09.574794Z digest=sha256:e122fea59b2d9b5ed733e5f5d2eb23a1cf15e1b723d9018c18a86401bdf37ea4

Observation 357d372b-9030-4144-9dda-57e14ebd6aeb · inbound

Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees cites this paper.

Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T17:30:00.237657Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-25T23:40:36.181525Z digest=sha256:24d75b8cc212e82cb8c6e6f2dfdada064fbc6d93907dbd41bf7cf1917855f93a

Observation 6ac276be-fc7c-4255-b230-231d93a7cedf · inbound

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents cites this paper.

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-07-04T14:09:53.328653Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-26T04:29:16.386339Z digest=sha256:65409f7d40ab82284e1bd1b6c3ea55dd27873830f511c7800a778a0435b4a438

Observation ce9ab948-19ab-4aca-b71c-b318eb9f7c67 · inbound

Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents cites this paper.

Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T15:15:48.387224Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-30T03:44:51.320606Z digest=sha256:cbd6fc14abc54bc6cca9e3d36134eb72ec2fee80da3600c9293cf0eee78cd151

Observation d9ee5e00-aedb-4094-a6e2-83ecff6c5b12 · inbound

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems cites this paper.

MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 37

Resolution
verified exact
arxiv_id, observed 2026-06-30T16:14:53.962560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-30T04:48:51.748711Z digest=sha256:d23a3e33d4f23b1e661a8601a02679e064adcb5f4a2f296f0ab55e390bfa4d58

Observation 56a97f66-a1d2-4f9a-9b58-4713293a3685 · inbound

What to Keep, What to Forget: A Rate--Distortion View of Memory Compaction in LLMs and Agents cites this paper.

What to Keep, What to Forget: A Rate--Distortion View of Memory Compaction in LLMs and Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 18

Resolution
verified exact
local_arxiv, observed 2026-07-10T01:36:44.254321Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-07-10T01:26:59.421158Z digest=sha256:45a6f44c0c49b9f58796808d15ac0ebdbe882265facac48ac7161f91267fc105

Observation f539b97a-aa33-4733-be60-33718a89f0bb · inbound

The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI cites this paper.

The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T15:05:18.672207Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:05:18.672207Z digest=sha256:2f2b793fd3e5ac6c0ed29e4729f1ae1fe8f66b6fd58ed0369589956adf9a859e

Observation dc9aa206-7414-431b-99a6-114554ae6539 · inbound

Ground Truth First: A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover in Memory-Architecture Rankings cites this paper.

Ground Truth First: A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover in Memory-Architecture Rankings AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T06:17:59.762921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:17:59.762921Z digest=sha256:b4cd66fb4e878913e0ff425cb2deeb864f31d879f3b7b915703e209636be848f

Observation 6b54c425-948d-4c8b-9c5d-9d039f9d9878 · inbound

ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory cites this paper.

ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T01:42:11.391147Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T01:42:11.391147Z digest=sha256:721674e44de7ba7c6607a6595b078347626ca137fc667316f10a3bba87ec2468

Observation a99f3443-9331-4b8c-b203-2baa877823e5 · inbound

ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory cites this paper.

ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T04:16:42.011864Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T04:16:42.011864Z digest=sha256:fdd7996848810147863d7d85ae787907ff14a2edc853c2d0219c8d36b8ca01a2

Observation f332cb43-44ed-47b3-bb15-2d598316e784 · inbound

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance cites this paper.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.283898Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.283898Z digest=sha256:ccf220a6335fe4e931f51a8dfafd707060dd57766bfc0132d1861285b7d1baba