{"as_of":"2026-08-11T13:39:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:0ebaec98b9538b9d59451b899e2ccc40a67b81184cb78554349d90fd4e2ae91c","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":51,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":51,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-11T06:34:44.6726+00:00","state":"measured"},{"denominator":51,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":51,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-11T04:46:07.020415Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"pith","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":9,"observed_at":"2026-08-05T02:28:24.338817Z","source":"pith"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"reference_index":91,"source":"arxiv_source","source_observed_at":"2026-05-12T13:36:57.011451Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2410.02644"},"observation_digest":"sha256:81fd54e5a816cd2bf9dd0cfade998f93e3efc69aba4153da770b3f95b554253c","observation_id":"5cfcf83a-be81-421e-82a6-f48ab34cadbc","resolution":{"observed_at":"2026-05-12T13:36:57.109054Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2410.09024","last_updated":"2025-04-18T14:30:31Z","snapshot_observed_at":"2026-08-02T12:38:54.249632Z","submitted_at":"2024-10-11T17:39:22Z","title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","version":3},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-05-14T01:35:50.992477Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2410.09024"},"observation_digest":"sha256:b389bcc9ad9a29a411823edb3c0c80bac6c7c694bf9231f9df62e39b2f50d34a","observation_id":"31e42e9a-df9a-4191-825f-6f337a7fcd28","resolution":{"observed_at":"2026-05-14T01:35:51.271144Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-11T04:46:07.020415Z","title":"Available: https://arxiv.org/abs/2407.12784","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2412.18371","last_updated":"2024-12-25T09:32:18Z","snapshot_observed_at":"2026-08-11T05:44:04.069768Z","submitted_at":"2024-12-24T11:54:14Z","title":"Defining and Detecting the Defects of the Large Language Model-based Autonomous Agents","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-11T04:46:07.020415Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2412.18371"},"observation_digest":"sha256:9f2497aefe772a0df0c5a8fd400dc2b06fcf86c5b54cd0e5d73a50dacefc2519","observation_id":"3daf39e5-a1f0-472b-ad1f-5402d4e215c9","resolution":{"observed_at":"2026-08-11T04:46:07.020415Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-10T19:55:50.530651Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.09620","last_updated":"2025-05-29T02:21:03Z","snapshot_observed_at":"2026-08-10T19:47:49.643885Z","submitted_at":"2025-01-16T16:00:37Z","title":"Beyond Reward Hacking: Causal Rewards for Large Language Model Alignment","version":2},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-08-10T19:55:50.530651Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2501.09620"},"observation_digest":"sha256:72ca0058efabe1c5fdf980b63569c0823e94f799c79c3ebe61fa128babda6d40","observation_id":"28c74b67-2321-4a39-b155-cd3080f3a81a","resolution":{"observed_at":"2026-08-10T19:55:50.530651Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-09T00:50:00.479235Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2502.05224","last_updated":"2025-02-06T04:43:05Z","snapshot_observed_at":"2026-08-09T05:58:57.244749Z","submitted_at":"2025-02-06T04:43:05Z","title":"A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations","version":1},"reference_index":112,"source":"pdf_text","source_observed_at":"2026-08-09T00:50:00.479235Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2502.05224"},"observation_digest":"sha256:b476f480f492d5a44d492ad3de6778bbb120d95cfee0bb68b6700ed931e10214","observation_id":"be427a9f-f618-4f83-86f3-7b787b629d29","resolution":{"observed_at":"2026-08-09T00:50:00.479235Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-08T04:37:28.364091Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2502.08586","last_updated":"2025-02-12T17:19:36Z","snapshot_observed_at":"2026-08-08T23:24:16.398221Z","submitted_at":"2025-02-12T17:19:36Z","title":"Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks","version":1},"reference_index":2017,"source":"pdf_text","source_observed_at":"2026-08-08T04:37:28.364091Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2502.08586"},"observation_digest":"sha256:1de62ad7911d97cc1cdce5504f984736fcf294c79b8b6bfd167de99551fa97b7","observation_id":"7d3be1a2-b8fb-4a6e-849c-808561abf87a","resolution":{"observed_at":"2026-08-08T04:37:28.364091Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T23:01:43.172473Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.22492","last_updated":"2025-06-24T18:55:29Z","snapshot_observed_at":"2026-08-09T23:15:19.815077Z","submitted_at":"2025-06-24T18:55:29Z","title":"Report on NSF Workshop on Science of Safe AI","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-06T23:01:43.172473Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2506.22492"},"observation_digest":"sha256:a53832ca20dee33a892387475d730257182305f8347eab5d0d055179e65d060e","observation_id":"f429a656-02b3-4290-ac26-9fb1f3fdf92c","resolution":{"observed_at":"2026-08-06T23:01:43.172473Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T16:24:30.470926Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.13629","last_updated":"2025-07-18T03:41:18Z","snapshot_observed_at":"2026-08-11T02:36:37.124757Z","submitted_at":"2025-07-18T03:41:18Z","title":"Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques","version":1},"reference_index":167,"source":"pdf_text","source_observed_at":"2026-08-06T16:24:30.470926Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2507.13629"},"observation_digest":"sha256:94c4cdf06a81cf2907b4287037ecd38c7d2f0860d9718a053380d6d8692f79bf","observation_id":"3fc33e66-667c-42e2-854d-96ffaa93215f","resolution":{"observed_at":"2026-08-06T16:24:30.470926Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T14:45:20.413049Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.17922","last_updated":"2025-07-23T20:39:14Z","snapshot_observed_at":"2026-08-11T06:46:37.772853Z","submitted_at":"2025-07-23T20:39:14Z","title":"From Seed to Harvest: Augmenting Human Creativity with AI for Red-teaming Text-to-Image Models","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-06T14:45:20.413049Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2507.17922"},"observation_digest":"sha256:c6615b1d6430046e6fc66833f0d3480c4998257648e1e876a132ecb7492daf58","observation_id":"1b2b7402-03bb-4e96-9078-9a9b26b4179b","resolution":{"observed_at":"2026-08-06T14:45:20.413049Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T12:44:21.530025Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.21504","last_updated":"2025-07-29T04:57:02Z","snapshot_observed_at":"2026-08-06T15:35:42.279155Z","submitted_at":"2025-07-29T04:57:02Z","title":"Evaluation and Benchmarking of LLM Agents: A Survey","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-06T12:44:21.530025Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2507.21504"},"observation_digest":"sha256:b49f5a274d5f707a3b58f012bbf7a24a91d3052b9c59fc32b10bff930a26399e","observation_id":"33451500-2922-4100-8d9f-25563c283b73","resolution":{"observed_at":"2026-08-06T12:44:21.530025Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T05:53:58.311875Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.01198","last_updated":"2025-08-02T05:09:58Z","snapshot_observed_at":"2026-08-06T23:52:12.537659Z","submitted_at":"2025-08-02T05:09:58Z","title":"Adaptive Content Restriction for Large Language Models via Suffix Optimization","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-06T05:53:58.311875Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2508.01198"},"observation_digest":"sha256:d17556b087a1c798f629f39e2a56e85922927d00f3ae25a2c159f181e382af43","observation_id":"0eeb9873-0e1e-404a-9666-4243f9eb9691","resolution":{"observed_at":"2026-08-06T05:53:58.311875Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T20:31:46.673384Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-08T02:31:17.622343Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":152,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:46.673384Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:5bb336a84ffff3f6a955f81222e0eaf8e6c786b4d9e6feff16815bafc00f17a6","observation_id":"775c5b2b-5fa9-4dd4-ad9e-07ac9ea80e56","resolution":{"observed_at":"2026-08-05T20:31:46.673384Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T14:20:11.612893Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.00124","last_updated":"2025-08-29T08:14:52Z","snapshot_observed_at":"2026-08-07T07:48:03.397849Z","submitted_at":"2025-08-29T08:14:52Z","title":"A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-05T14:20:11.612893Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2509.00124"},"observation_digest":"sha256:7ce0d148f26602f7326cb3b4ee4dad6fcbd67a9dd77e85b20b0b2299271fa770","observation_id":"1b8bdbd9-4ff1-4dee-a03b-f658ca9d67c1","resolution":{"observed_at":"2026-08-05T14:20:11.612893Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-04T17:46:15.064636Z","title":"Agentpoison: Red- teaming LLM agents via poisoning memory or knowledge bases,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.10682","last_updated":"2025-09-12T20:26:16Z","snapshot_observed_at":"2026-08-09T23:59:45.617391Z","submitted_at":"2025-09-12T20:26:16Z","title":"LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-04T17:46:15.064636Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2509.10682"},"observation_digest":"sha256:d537d0024b1917ac04ca166270293ef4f40c8fb81705710cb81662ab36f81e25","observation_id":"fcde5a73-f3cd-43e1-b136-ffb441eeaac8","resolution":{"observed_at":"2026-08-04T17:46:15.064636Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-03T19:27:04.067874Z","title":"Available: https://arxiv.org/abs/2407.12784","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2512.00804","last_updated":"2026-06-24T09:21:42Z","snapshot_observed_at":"2026-08-09T15:28:57.622655Z","submitted_at":"2025-11-30T09:27:18Z","title":"Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval","version":3},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-03T19:27:04.067874Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2512.00804"},"observation_digest":"sha256:e1151f0d8543b94ffec8dfc7ec1890f796aa4d62be208a31090b485317648d1b","observation_id":"00be42cd-3382-4fa4-9220-cd11eb44916b","resolution":{"observed_at":"2026-08-03T19:27:04.067874Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-07-15T13:15:31.225992Z","title":"Available: https://arxiv.org/abs/2407.12784","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2603.07457","last_updated":"2026-03-08T04:16:06Z","snapshot_observed_at":"2026-08-08T01:21:30.388475Z","submitted_at":"2026-03-08T04:16:06Z","title":"How Well Do AI Systems Solve AP Physics? A Comparative Evaluation of Large Language Models on Algebra-Based Free Response Questions","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-07-15T13:15:31.225992Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2603.07457"},"observation_digest":"sha256:e1c779f51651f2e6b898eda51bd3c7f29d0bc15e82526c0b3c70a55d3ebc3dfe","observation_id":"1c56c68b-b20a-42bc-ac3d-92179512421b","resolution":{"observed_at":"2026-07-15T13:15:31.225992Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2603.09002","last_updated":"2026-04-26T14:13:48Z","snapshot_observed_at":"2026-08-11T02:37:54.478569Z","submitted_at":"2026-03-09T22:46:27Z","title":"Security Considerations for Multi-agent Systems","version":2},"reference_index":88,"source":"pdf_text","source_observed_at":"2026-05-15T14:12:14.160789Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2603.09002"},"observation_digest":"sha256:e161c9ed2b1f38a6786d0122dea2a83606b565808c531f63b6182cf4548e9e20","observation_id":"7e6c1aa8-ba7e-4997-9a73-3ae484825a58","resolution":{"observed_at":"2026-05-15T14:15:55.919512Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2604.04759","last_updated":"2026-04-06T15:27:05Z","snapshot_observed_at":"2026-08-11T04:23:46.286452Z","submitted_at":"2026-04-06T15:27:05Z","title":"Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-10T19:20:52.845052Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2604.04759"},"observation_digest":"sha256:fd6a3f4536e42121f1c62fb966b7c8f631ebbefbd2311b0c697f85465fcdd83c","observation_id":"001b5b4e-cb7a-4a58-90cc-94b4585e9216","resolution":{"observed_at":"2026-05-10T23:05:49.143007Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2604.12616","last_updated":"2026-04-14T11:44:59Z","snapshot_observed_at":"2026-08-11T06:48:51.044512Z","submitted_at":"2026-04-14T11:44:59Z","title":"Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-05-10T15:06:43.140580Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2604.12616"},"observation_digest":"sha256:972c2cbb1d845b9f248e7e3049598dcd44a1930f32221217e2955c20e1c77e3f","observation_id":"22702ab2-e43c-4599-bc3e-d96b2b602d23","resolution":{"observed_at":"2026-05-11T11:11:05.393842Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2604.19657","last_updated":"2026-04-21T16:45:30Z","snapshot_observed_at":"2026-07-06T23:06:16.972438Z","submitted_at":"2026-04-21T16:45:30Z","title":"An AI Agent Execution Environment to Safeguard User Data","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-10T02:14:40.639143Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2604.19657"},"observation_digest":"sha256:ed3e9e80573ab277246a43b36044a11c2dffeddbdd05e07b87b9bc0afcae3a72","observation_id":"08eba912-b742-4998-8cbc-6336b23982be","resolution":{"observed_at":"2026-05-11T13:11:05.899324Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2604.23338","last_updated":"2026-05-06T17:17:02Z","snapshot_observed_at":"2026-08-06T19:46:39.219000Z","submitted_at":"2026-04-25T14:57:15Z","title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","version":2},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-05-08T07:53:13.746141Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2604.23338"},"observation_digest":"sha256:565fe101ad6014ca19736a6d5445d21d3d31134c50aaf91b232f6a38240ccd9d","observation_id":"d5f87eb4-697c-4701-b6f8-ea700a2e9fcf","resolution":{"observed_at":"2026-05-11T20:51:09.036744Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.01970","last_updated":"2026-05-15T06:42:15Z","snapshot_observed_at":"2026-07-06T23:15:07.159340Z","submitted_at":"2026-05-03T17:07:20Z","title":"Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-05-09T17:13:47.722098Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.01970"},"observation_digest":"sha256:ab6535db3871180586e57ac400bdb33154c581ec09b3aa850a2367d662b954c8","observation_id":"82b6be5e-6ddc-4568-9fde-11b86519cff7","resolution":{"observed_at":"2026-05-09T21:38:30.740427Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.03242","last_updated":"2026-05-05T00:21:00Z","snapshot_observed_at":"2026-08-05T09:06:36.339904Z","submitted_at":"2026-05-05T00:21:00Z","title":"Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios","version":1},"reference_index":31,"source":"arxiv_source","source_observed_at":"2026-05-07T16:57:28.155229Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.03242"},"observation_digest":"sha256:92eb27e35a7d40ef003fe0465abadb31e3e20765d2c2e3f6c9bb3c1a7d83e45d","observation_id":"f596f878-f217-4937-87ad-021b972e0335","resolution":{"observed_at":"2026-05-11T23:31:13.050357Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.03482","last_updated":"2026-05-07T11:41:14Z","snapshot_observed_at":"2026-07-30T12:28:00.209964Z","submitted_at":"2026-05-05T08:15:41Z","title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-07T15:57:39.809778Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.03482"},"observation_digest":"sha256:4ae9d01732cae4fd38c988cffe93a2af2d0815f5f7008a6c76ec64da3e58d358","observation_id":"1eb65ed0-2dcb-4a39-933c-3a0b924afd96","resolution":{"observed_at":"2026-05-12T00:01:14.267439Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.03482","last_updated":"2026-05-07T11:41:14Z","snapshot_observed_at":"2026-07-30T12:28:00.209964Z","submitted_at":"2026-05-05T08:15:41Z","title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-08T18:50:41.401393Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.03482"},"observation_digest":"sha256:82763d117f413ac5bf08a6cbd818dd816e0fa47561ce9957d5e0fbca6130cf6f","observation_id":"66696e20-0b76-4694-893d-c150e2d4b973","resolution":{"observed_at":"2026-05-09T06:10:41.460813Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.06393","last_updated":"2026-05-07T15:08:40Z","snapshot_observed_at":"2026-08-08T07:31:47.750419Z","submitted_at":"2026-05-07T15:08:40Z","title":"Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-05-08T09:08:30.102711Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.06393"},"observation_digest":"sha256:59cf1a055233a816302e7ae9283e602dbd99db02d108fa23337bb50441ca1858","observation_id":"feca86c2-699d-439c-862d-c539df9af9d4","resolution":{"observed_at":"2026-05-11T20:26:11.087888Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.09033","last_updated":"2026-05-15T08:27:09Z","snapshot_observed_at":"2026-08-11T10:45:20.232826Z","submitted_at":"2026-05-09T16:16:41Z","title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-05-12T02:27:03.154390Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.09033"},"observation_digest":"sha256:fdae5fbadf32b4990f2580781e0e523d4e4855d3efe6e5b7d909630f72441f1c","observation_id":"056d4b75-b4cb-4f89-969d-40572e6b79d8","resolution":{"observed_at":"2026-05-12T07:37:04.869744Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.09033","last_updated":"2026-05-15T08:27:09Z","snapshot_observed_at":"2026-08-11T10:45:20.232826Z","submitted_at":"2026-05-09T16:16:41Z","title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-05-15T06:09:36.338641Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.09033"},"observation_digest":"sha256:023a58f1744161ecf654427ce3b74613dfd4a3d1336771faccc4f2b575ecf6ed","observation_id":"d89984f9-e28a-47cf-9fae-31ded5417a31","resolution":{"observed_at":"2026-05-15T06:09:49.147914Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.09033","last_updated":"2026-05-15T08:27:09Z","snapshot_observed_at":"2026-08-11T10:45:20.232826Z","submitted_at":"2026-05-09T16:16:41Z","title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","version":3},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-05-19T17:38:45.919637Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.09033"},"observation_digest":"sha256:1eec09b5ff07153af53e01498fc72b2a4a33836b475c0e45c9fd9e40499dbf91","observation_id":"0744b8cf-b3f2-44a3-9332-671e32c74815","resolution":{"observed_at":"2026-05-19T17:42:42.343448Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.14421","last_updated":"2026-05-14T06:07:54Z","snapshot_observed_at":"2026-08-05T21:42:41.952480Z","submitted_at":"2026-05-14T06:07:54Z","title":"MemLineage: Lineage-Guided Enforcement for LLM Agent Memory","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-05-15T02:21:32.356516Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.14421"},"observation_digest":"sha256:1679fe32c2bc6070819dc91a1974f99a12458f05e7db22e07de2c56e047b92aa","observation_id":"6f24d99b-ca39-4adc-9aad-f81134e994c3","resolution":{"observed_at":"2026-05-15T02:23:31.637232Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":6,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f1ba2533ba5a9ecda7157ec136304faeaab4aa3a2fee9ace683061c4e1adb3e0","observation_id":"4b9fdf3f-7778-40d7-9dd2-9f12810ad2a9","resolution":{"observed_at":"2026-05-21T01:43:57.001946Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.18133","last_updated":"2026-05-18T09:38:18Z","snapshot_observed_at":"2026-07-06T23:29:04.241654Z","submitted_at":"2026-05-18T09:38:18Z","title":"An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-05-20T09:58:05.349147Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.18133"},"observation_digest":"sha256:4aed2fd1cafde0e81ec2efbd111f38c0c9ea414fb0a30a252537db75f2ac473a","observation_id":"d0944feb-5abe-49be-8a9d-ff46edd4414d","resolution":{"observed_at":"2026-05-20T09:58:10.927620Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.22643","last_updated":"2026-05-22T14:53:30Z","snapshot_observed_at":"2026-07-06T23:32:59.663926Z","submitted_at":"2026-05-21T15:50:18Z","title":"Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-05-22T05:50:28.114140Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.22643"},"observation_digest":"sha256:4ce5bdd47e08ef1c8425e31b215beff6a74d1982d209f3c041249c4876380359","observation_id":"885b460a-9981-4218-8503-be554bbee6e0","resolution":{"observed_at":"2026-05-22T05:51:08.079203Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.22643","last_updated":"2026-05-22T14:53:30Z","snapshot_observed_at":"2026-07-06T23:32:59.663926Z","submitted_at":"2026-05-21T15:50:18Z","title":"Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-05-25T06:05:27.736494Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.22643"},"observation_digest":"sha256:3a5ac9ea94ac33a3c6b5674a7e4b19f6635123c5534440107fc66bf7891028de","observation_id":"5dbe1982-4951-4ba8-8a69-6af267fa387d","resolution":{"observed_at":"2026-05-25T06:06:43.041641Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.23951","last_updated":"2026-05-09T19:27:38Z","snapshot_observed_at":"2026-08-08T14:59:57.090341Z","submitted_at":"2026-05-09T19:27:38Z","title":"Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-30T22:57:58.989954Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.23951"},"observation_digest":"sha256:eae5905d51bae839a019594f7926c9bc36243563964cef3eb93f07f9864cf8fc","observation_id":"dd122455-abff-4fbf-afc3-00c38deb1e40","resolution":{"observed_at":"2026-07-01T13:35:46.625765Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.27825","last_updated":"2026-05-27T01:31:40Z","snapshot_observed_at":"2026-08-02T19:56:32.199762Z","submitted_at":"2026-05-27T01:31:40Z","title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-06-29T12:04:53.511344Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.27825"},"observation_digest":"sha256:c1c8d128bd4b318a8548bcbd96d6136b68a18bba2033a97fc5e1b33696134b38","observation_id":"0e5802d9-c1f3-4928-af7f-89335483ebbc","resolution":{"observed_at":"2026-06-29T12:13:27.069505Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.31042","last_updated":"2026-05-29T09:19:07Z","snapshot_observed_at":"2026-07-06T23:40:17.605034Z","submitted_at":"2026-05-29T09:19:07Z","title":"From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors","version":1},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-06-28T22:06:41.245543Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.31042"},"observation_digest":"sha256:fa4ac07420a0c988291781c20a82a1ed858d69868046502a4e4f6c493c79df8f","observation_id":"52671b79-e699-4221-8cdc-6a0ccfbf57f2","resolution":{"observed_at":"2026-06-28T22:12:41.452735Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.07805","last_updated":"2026-06-05T19:33:58Z","snapshot_observed_at":"2026-08-03T01:44:22.181409Z","submitted_at":"2026-06-05T19:33:58Z","title":"Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-06-27T21:53:37.616447Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.07805"},"observation_digest":"sha256:54aef0d40c3acf124e76192b644d6d6bf75b81a4962634422838bb22e10527d8","observation_id":"b1cdde4e-44b8-4f45-9784-86217c2dbc46","resolution":{"observed_at":"2026-07-02T17:47:17.779501Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.09038","last_updated":"2026-06-08T05:10:05Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-06-08T05:10:05Z","title":"Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-06-27T16:49:14.243931Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.09038"},"observation_digest":"sha256:08c3a6dddbf32a08b7607868060a90b4145e453ef589d35516a69e8a82afabee","observation_id":"068d0dd2-5733-4988-809f-2d6de2f4c3a0","resolution":{"observed_at":"2026-07-03T01:07:30.147675Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.12290","last_updated":"2026-06-10T16:26:46Z","snapshot_observed_at":"2026-08-02T00:16:37.704294Z","submitted_at":"2026-06-10T16:26:46Z","title":"Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-06-27T09:13:58.485088Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.12290"},"observation_digest":"sha256:7ae9e44adc9904bd359fab87d5035d4bfec22c2cba379d928a68fdca1cceed55","observation_id":"b7652133-b240-4baf-939b-c5405616b075","resolution":{"observed_at":"2026-07-03T11:58:06.290527Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.12703","last_updated":"2026-06-10T21:45:52Z","snapshot_observed_at":"2026-08-08T01:42:51.865638Z","submitted_at":"2026-06-10T21:45:52Z","title":"SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-06-27T08:58:09.574794Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.12703"},"observation_digest":"sha256:e122fea59b2d9b5ed733e5f5d2eb23a1cf15e1b723d9018c18a86401bdf37ea4","observation_id":"8b842b60-a1e6-4660-969d-f34e9af75f3e","resolution":{"observed_at":"2026-07-03T12:28:07.763218Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.24322","last_updated":"2026-06-23T08:57:50Z","snapshot_observed_at":"2026-08-11T06:27:13.828770Z","submitted_at":"2026-06-23T08:57:50Z","title":"Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-25T23:40:36.181525Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.24322"},"observation_digest":"sha256:24d75b8cc212e82cb8c6e6f2dfdada064fbc6d93907dbd41bf7cf1917855f93a","observation_id":"357d372b-9030-4144-9dda-57e14ebd6aeb","resolution":{"observed_at":"2026-07-04T17:30:00.237657Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.26627","last_updated":"2026-06-25T05:44:18Z","snapshot_observed_at":"2026-08-02T09:36:56.612724Z","submitted_at":"2026-06-25T05:44:18Z","title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-06-26T04:29:16.386339Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.26627"},"observation_digest":"sha256:65409f7d40ab82284e1bd1b6c3ea55dd27873830f511c7800a778a0435b4a438","observation_id":"6ac276be-fc7c-4255-b230-231d93a7cedf","resolution":{"observed_at":"2026-07-04T14:09:53.328653Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.30306","last_updated":"2026-06-29T13:47:42Z","snapshot_observed_at":"2026-08-03T21:13:43.609810Z","submitted_at":"2026-06-29T13:47:42Z","title":"Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-06-30T03:44:51.320606Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.30306"},"observation_digest":"sha256:cbd6fc14abc54bc6cca9e3d36134eb72ec2fee80da3600c9293cf0eee78cd151","observation_id":"ce9ab948-19ab-4aca-b71c-b318eb9f7c67","resolution":{"observed_at":"2026-07-01T15:15:48.387224Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2606.30602","last_updated":"2026-06-29T17:40:45Z","snapshot_observed_at":"2026-08-03T17:51:38.702679Z","submitted_at":"2026-06-29T17:40:45Z","title":"MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-06-30T04:48:51.748711Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2606.30602"},"observation_digest":"sha256:d23a3e33d4f23b1e661a8601a02679e064adcb5f4a2f296f0ab55e390bfa4d58","observation_id":"d9ee5e00-aedb-4094-a6e2-83ecff6c5b12","resolution":{"observed_at":"2026-06-30T16:14:53.962560Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2607.08032","last_updated":"2026-07-09T01:15:03Z","snapshot_observed_at":"2026-08-02T16:38:21.894642Z","submitted_at":"2026-07-09T01:15:03Z","title":"What to Keep, What to Forget: A Rate--Distortion View of Memory Compaction in LLMs and Agents","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-07-10T01:26:59.421158Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2607.08032"},"observation_digest":"sha256:45a6f44c0c49b9f58796808d15ac0ebdbe882265facac48ac7161f91267fc105","observation_id":"56a97f66-a1d2-4f9a-9b58-4713293a3685","resolution":{"observed_at":"2026-07-10T01:36:44.254321Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-01T15:05:18.672207Z","title":"AgentPoison: Red-teaming LLM agents via poisoning memory or knowledge bases,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.19433","last_updated":"2026-07-20T22:50:33Z","snapshot_observed_at":"2026-08-11T11:48:43.530345Z","submitted_at":"2026-07-20T22:50:33Z","title":"The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-01T15:05:18.672207Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2607.19433"},"observation_digest":"sha256:846b639c29b48fd6b16895b3583c665b716d8ab18911d453293e059f4eb1c8b1","observation_id":"f539b97a-aa33-4733-be60-33718a89f0bb","resolution":{"observed_at":"2026-08-01T15:05:18.672207Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-01T06:17:59.762921Z","title":"AgentPoison : Red-teaming LLM agents via poisoning memory or knowledge bases","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.21962","last_updated":"2026-07-24T04:19:45Z","snapshot_observed_at":"2026-08-07T16:22:09.041290Z","submitted_at":"2026-07-24T04:19:45Z","title":"Ground Truth First: A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover in Memory-Architecture Rankings","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-01T06:17:59.762921Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2607.21962"},"observation_digest":"sha256:b4cd66fb4e878913e0ff425cb2deeb864f31d879f3b7b915703e209636be848f","observation_id":"dc9aa206-7414-431b-99a6-114554ae6539","resolution":{"observed_at":"2026-08-01T06:17:59.762921Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-01T01:42:11.391147Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.27773","last_updated":"2026-08-05T04:27:17Z","snapshot_observed_at":"2026-08-08T23:10:42.065504Z","submitted_at":"2026-07-30T07:07:39Z","title":"ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-01T01:42:11.391147Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2607.27773"},"observation_digest":"sha256:721674e44de7ba7c6607a6595b078347626ca137fc667316f10a3bba87ec2468","observation_id":"6b54c425-948d-4c8b-9c5d-9d039f9d9878","resolution":{"observed_at":"2026-08-01T01:42:11.391147Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-06T04:16:42.011864Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.27773","last_updated":"2026-08-05T04:27:17Z","snapshot_observed_at":"2026-08-08T23:10:42.065504Z","submitted_at":"2026-07-30T07:07:39Z","title":"ChronoMem: Version Control and Semantic Rollback for Large Language Model Agent Memory","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-06T04:16:42.011864Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2607.27773"},"observation_digest":"sha256:fdd7996848810147863d7d85ae787907ff14a2edc853c2d0219c8d36b8ca01a2","observation_id":"a99f3443-9331-4b8c-b203-2baa877823e5","resolution":{"observed_at":"2026-08-06T04:16:42.011864Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-07T00:12:23.283898Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2608.01558","last_updated":"2026-08-03T00:28:49Z","snapshot_observed_at":"2026-08-11T11:45:44.957877Z","submitted_at":"2026-08-03T00:28:49Z","title":"Securing Agentic AI: From Per-Action Checks to Trajectory Assurance","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T00:12:23.283898Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2608.01558"},"observation_digest":"sha256:85033375e3729d6f84279109551365272dec1cca5c069cdb46512d1f29673056","observation_id":"f332cb43-44ed-47b3-bb15-2d598316e784","resolution":{"observed_at":"2026-08-07T00:12:23.283898Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2407.12784/citation-record","integrity":"/paper/2407.12784/integrity","json":"/paper/2407.12784/citation-record.json","paper":"/paper/2407.12784"},"outbound":[],"paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","latest_version":1,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-09T05:58:40.075515Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"thesis":"As of 11 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 51 inbound Pith citation observations for arXiv:2407.12784."}