Pith. sign in

Paper Citation Record · LEDGER

Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 22 inbound Pith citation observations for arXiv:2407.20859.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2407.20859 v1

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 22 of 22 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 22 of 22 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.833682Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-19T11:32:17.399819Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 70567d79-fc90-402b-9b4a-faed101ddead · inbound

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems cites this paper.

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 92

Resolution
verified exact
arxiv_id, observed 2026-05-15T19:32:19.842883Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-15T19:32:19.405615Z digest=sha256:a27cdbac2b565b80f51d908528d7bc5f7d41341faafaeafa06619d57281c1ee8

Observation 27868dea-37aa-466f-a614-86f0fb11dd28 · inbound

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents cites this paper.

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-14T01:35:51.157627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-14T01:35:50.992477Z digest=sha256:4d3624e1c68d341d8118b0724013ea11444f464ea93b79a28c2326507d56c117

Observation 75e283ae-38ba-4953-92f4-67cd737699ad · inbound

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks cites this paper.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.833682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.833682Z digest=sha256:37fb948f39a617da6f17c765416276c50c7d8e025e70e70577602439e669c1a9

Observation af22e5bb-013d-460b-bc09-2dcc13193c75 · inbound

AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents cites this paper.

AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:24:32.653182Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-14T21:24:32.615129Z digest=sha256:43b41f763b4091333a39fc0967193f67c01eaa343ea7b050a132c0f5e6225147

Observation c50de765-5309-4a6b-8205-e12fb77fb6e4 · inbound

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI cites this paper.

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 180

Resolution
unresolved
no resolver link, observed 2026-08-07T14:15:48.765487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:15:48.765487Z digest=sha256:d1b169bdeb7f1c1821b4b84c7936dfdad087b685511e4f7ffea23e367cfca91b

Observation cc26684a-32d6-4848-8283-16a8a2deb2ae · inbound

Exploring Consciousness in LLMs: A Systematic Survey of Theories, Implementations, and Frontier Risks cites this paper.

Exploring Consciousness in LLMs: A Systematic Survey of Theories, Implementations, and Frontier Risks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T14:09:51.938976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:09:51.938976Z digest=sha256:24f6ea7a7b7bd4bcdbf581479d2b364ededf6543825e079df92827694d056d4f

Observation 739051ed-4776-46f1-ae67-d86a2954aa29 · inbound

MermaidFlow: Redefining Agentic Workflow Generation via Safety-Constrained Evolutionary Programming cites this paper.

MermaidFlow: Redefining Agentic Workflow Generation via Safety-Constrained Evolutionary Programming Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T13:00:09.290039Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:00:09.290039Z digest=sha256:1d65ed90f02e6a7021f2106b26b9edaa35433d82bc50bfe13bad6c8d6493130d

Observation e2be02a1-f2f4-4f0b-9fdf-db486a9d0823 · inbound

When GPT Spills the Tea: Comprehensive Assessment of Knowledge File Leakage in GPTs cites this paper.

When GPT Spills the Tea: Comprehensive Assessment of Knowledge File Leakage in GPTs Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T12:14:28.219807Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:14:28.219807Z digest=sha256:2aa0ee3e61c48d47f060d736baf313308c82d24d4d73b843ed857f91dc5ca87c

Observation 4bc17a46-d09e-42ef-a4c5-2982947c98c6 · inbound

To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems cites this paper.

To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-19T11:32:17.403211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-19T11:30:47.877793Z digest=sha256:8e19a3413c6a07d82ce201299afa3062d54ef144f236464e35a734dc2c1c6479

Observation 5d661501-7bea-4e38-8ac4-eefd7427adba · inbound

Misalignment or misuse? The AGI alignment tradeoff cites this paper.

Misalignment or misuse? The AGI alignment tradeoff Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 104

Resolution
unresolved
no resolver link, observed 2026-08-07T11:00:30.044332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:00:30.044332Z digest=sha256:4f91c7c88a19ad9c20b84129b73a052cf0104d271354e9a8e541229a61096639

Observation 4063b574-a780-46db-9b09-9c93bf741cc7 · inbound

AgentMisalignment: Measuring the Propensity for Misaligned Behaviour in LLM-Based Agents cites this paper.

AgentMisalignment: Measuring the Propensity for Misaligned Behaviour in LLM-Based Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T10:54:58.042421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T10:54:58.042421Z digest=sha256:7ab3fa84b64aea4a1a75d9bf1f5d06c0a9f9d6006c15a256fd3eb5e154985d0b

Observation 618e3f50-7bab-4b7b-b2ce-45a9ff0281b3 · inbound

Oversight Structures for Agentic AI in Public-Sector Organizations cites this paper.

Oversight Structures for Agentic AI in Public-Sector Organizations Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T10:35:52.641114Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T10:35:52.641114Z digest=sha256:772aea6a51445deccb28572de367a13f224398e1a72d9e19bebdcc53886bd042

Observation f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3 · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.737890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.737890Z digest=sha256:8dc7d975cdca75435c824b78c3a3287aa6a9802b35f531eaccb17a0deb8ce2f6

Observation 38da46af-33d6-4c90-9f1c-191963725db3 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:40.846006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:40.846006Z digest=sha256:6aa8ffcf0d1df2eac5589380a14ecccf9608f243571aa2d56ffed407b38048d6

Observation 86350cec-1f15-431b-8e67-fda1be52837f · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 156

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:46.996573Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:46.996573Z digest=sha256:d006276761ffafe2cecb46c2769d59be896abd772e7624a7efe274313282d132

Observation a8258143-3763-4f6f-a648-1c37df5f0ba3 · inbound

Free-MAD: Consensus-Free Multi-Agent Debate cites this paper.

Free-MAD: Consensus-Free Multi-Agent Debate Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T17:15:01.750168Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T17:15:01.750168Z digest=sha256:d67b7e237a25a9873bf8b18634c57391dc15cbc103aa3d8128557d7aa8141fd9

Observation 6235fe9d-4c70-442a-a49b-4f8aac21bf5c · inbound

Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence cites this paper.

Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-04T14:42:51.152563Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T14:42:51.152563Z digest=sha256:24213b033d6380cbfc8e631a0e9356b89affd6c5f0cbb95ae196dcca1c3f8bb1

Observation 5398029e-fde9-42d1-bbc1-d7858ae7264f · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.436204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:4a9790ef6d32b88137e8720424fe2004c1673b16c243b351b743c5b8ee9103bd

Observation 00c339ae-648a-41f4-b060-8eb944fbb130 · inbound

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models cites this paper.

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 27

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T00:29:47.748410Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T00:02:35.167281Z digest=sha256:413186e96d12c3744a894f44f98524e2b72c6518cf251e261356ae317442f036

Observation 042a5f95-437d-4c84-a286-a8309732ced0 · inbound

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework cites this paper.

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 112

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:51:09.070148Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-08T07:53:13.746141Z digest=sha256:0e1d0ce3843e6fc21ac13a752bc6342f4d768a922cd4a8352d315799c44bf9ed

Observation 0c171232-24de-4559-b3d3-322879d57af4 · inbound

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios cites this paper.

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-11T23:31:13.133715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-07T16:57:28.155229Z digest=sha256:fe2a6ce4a8608cdde1c28cad11150a7eda4ad1fedba867d92fe1e9ff317ec4f4

Observation 5c8ccc6b-5e33-40ad-82af-f054abba4f2d · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 271

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.616748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.616748Z digest=sha256:bdb5c13fc2b729b3f08273dff8ddb4d4488cb0da7affaa539cc319575ec89247