Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links
Paper Citation Record · LEDGER
As of 11 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 51 inbound Pith citation observations for arXiv:2407.12784.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-11T04:46:07.020415Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-05T02:28:24.338817Z
0 of 0 outbound references displayed
External citation measurements
9
pith, observed 2026-08-05T02:28:24.338817Z
No outbound reference observations are available for this paper version.
Observation 5cfcf83a-be81-421e-82a6-f48ab34cadbc · inbound
Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 91
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 31e42e9a-df9a-4191-825f-6f337a7fcd28 · inbound
AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 3daf39e5-a1f0-472b-ad1f-5402d4e215c9 · inbound
Defining and Detecting the Defects of the Large Language Model-based Autonomous Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 28c74b67-2321-4a39-b155-cd3080f3a81a · inbound
Beyond Reward Hacking: Causal Rewards for Large Language Model Alignment AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation be427a9f-f618-4f83-86f3-7b787b629d29 · inbound
A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 112
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d3be1a2-b8fb-4a6e-849c-808561abf87a · inbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2017
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f429a656-02b3-4290-ac26-9fb1f3fdf92c · inbound
Report on NSF Workshop on Science of Safe AI AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3fc33e66-667c-42e2-854d-96ffaa93215f · inbound
Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 167
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1b2b7402-03bb-4e96-9078-9a9b26b4179b · inbound
From Seed to Harvest: Augmenting Human Creativity with AI for Red-teaming Text-to-Image Models AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 33451500-2922-4100-8d9f-25563c283b73 · inbound
Evaluation and Benchmarking of LLM Agents: A Survey AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0eeb9873-0e1e-404a-9666-4243f9eb9691 · inbound
Adaptive Content Restriction for Large Language Models via Suffix Optimization AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 775c5b2b-5fa9-4dd4-ad9e-07ac9ea80e56 · inbound
Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 152
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1b8bdbd9-4ff1-4dee-a03b-f658ca9d67c1 · inbound
A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fcde5a73-f3cd-43e1-b136-ffb441eeaac8 · inbound
LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 00be42cd-3382-4fa4-9220-cd11eb44916b · inbound
Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1c56c68b-b20a-42bc-ac3d-92179512421b · inbound
How Well Do AI Systems Solve AP Physics? A Comparative Evaluation of Large Language Models on Algebra-Based Free Response Questions AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e6c1aa8-ba7e-4997-9a73-3ae484825a58 · inbound
Security Considerations for Multi-agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 88
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 001b5b4e-cb7a-4a58-90cc-94b4585e9216 · inbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 22702ab2-e43c-4599-bc3e-d96b2b602d23 · inbound
Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 08eba912-b742-4998-8cbc-6336b23982be · inbound
An AI Agent Execution Environment to Safeguard User Data AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation d5f87eb4-697c-4701-b6f8-ea700a2e9fcf · inbound
A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 82b6be5e-6ddc-4568-9fde-11b86519cff7 · inbound
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation f596f878-f217-4937-87ad-021b972e0335 · inbound
Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 1eb65ed0-2dcb-4a39-933c-3a0b924afd96 · inbound
MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 66696e20-0b76-4694-893d-c150e2d4b973 · inbound
MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation feca86c2-699d-439c-862d-c539df9af9d4 · inbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 056d4b75-b4cb-4f89-969d-40572e6b79d8 · inbound
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation d89984f9-e28a-47cf-9fae-31ded5417a31 · inbound
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 0744b8cf-b3f2-44a3-9332-671e32c74815 · inbound
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 6f24d99b-ca39-4adc-9aad-f81134e994c3 · inbound
MemLineage: Lineage-Guided Enforcement for LLM Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 4b9fdf3f-7778-40d7-9dd2-9f12810ad2a9 · inbound
Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation d0944feb-5abe-49be-8a9d-ff46edd4414d · inbound
An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 885b460a-9981-4218-8503-be554bbee6e0 · inbound
Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 5dbe1982-4951-4ba8-8a69-6af267fa387d · inbound
Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation dd122455-abff-4fbf-afc3-00c38deb1e40 · inbound
Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 0e5802d9-c1f3-4928-af7f-89335483ebbc · inbound
MRMMIA: Membership Inference Attacks on Memory in Chat Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 52671b79-e699-4221-8cdc-6a0ccfbf57f2 · inbound
From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation b1cdde4e-44b8-4f45-9784-86217c2dbc46 · inbound
Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 068d0dd2-5733-4988-809f-2d6de2f4c3a0 · inbound
Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation b7652133-b240-4baf-939b-c5405616b075 · inbound
Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 8b842b60-a1e6-4660-969d-f34e9af75f3e · inbound
SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 357d372b-9030-4144-9dda-57e14ebd6aeb · inbound
Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 6ac276be-fc7c-4255-b230-231d93a7cedf · inbound
Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation ce9ab948-19ab-4aca-b71c-b318eb9f7c67 · inbound
Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation d9ee5e00-aedb-4094-a6e2-83ecff6c5b12 · inbound
MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 56a97f66-a1d2-4f9a-9b58-4713293a3685 · inbound
What to Keep, What to Forget: A Rate--Distortion View of Memory Compaction in LLMs and Agents AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation f539b97a-aa33-4733-be60-33718a89f0bb · inbound
The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc9aa206-7414-431b-99a6-114554ae6539 · inbound
Ground Truth First: A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover in Memory-Architecture Rankings AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b54c425-948d-4c8b-9c5d-9d039f9d9878 · inbound
ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a99f3443-9331-4b8c-b203-2baa877823e5 · inbound
ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f332cb43-44ed-47b3-bb15-2d598316e784 · inbound
Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.