Pith. sign in

Paper Citation Record · LEDGER

EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

As of 6 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 19 inbound Pith citation observations for arXiv:2409.11295.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2409.11295 v5

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 19 of 19 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00

measured 19 of 19 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T19:43:28.598263Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

1
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 90382a86-16bd-467a-887a-708a98a35a8b · inbound

ASSURE: Metamorphic Testing for AI-powered Browser Extensions cites this paper.

ASSURE: Metamorphic Testing for AI-powered Browser Extensions EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T19:43:28.598263Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:43:28.598263Z digest=sha256:a1039b2229167c1480296b04194a9bc36311f216eeb580ca5a228473a604bdfd

Observation abae9612-218d-498a-8634-014caef4db11 · inbound

WebGuard: Building a Generalizable Guardrail for Web Agents cites this paper.

WebGuard: Building a Generalizable Guardrail for Web Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T16:12:49.478511Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:12:49.478511Z digest=sha256:1eabfd3cdfa05da45fca576d5bab4f4bd2a253bfc29760f968de73e75a48de6f

Observation 2664bd85-e1dd-4f04-a5c9-efe47d3de940 · inbound

PromptArmor: Simple yet Effective Prompt Injection Defenses cites this paper.

PromptArmor: Simple yet Effective Prompt Injection Defenses EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T15:42:00.957739Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T15:42:00.957739Z digest=sha256:f1beaae5c6b06335943897339d87d0b52b332e39dcc183653f2594c50c2e9595

Observation 68e1cf73-2136-49ad-b530-750830af3ca5 · inbound

OS Agents: A Survey on MLLM-based Agents for General Computing Devices Use cites this paper.

OS Agents: A Survey on MLLM-based Agents for General Computing Devices Use EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T00:00:31.317537Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:00:31.317537Z digest=sha256:919b4b2bc42c73c81488aa6fb5059d912413e7dc5f055cf29dde1112fd1f1c28

Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · inbound

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment cites this paper.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.868193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.868193Z digest=sha256:c42fbce09ee7fe2ed791cfb157fdf3b698b40c8617ce4a55038929f37d27d570

Observation 728d166f-39eb-40ab-b682-20de8a213f92 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:11.805883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:11.805883Z digest=sha256:f6d260ca477196ea26476ed01ef76f5f6dabc20614158a51a1351e8306210e35

Observation 7d8311eb-de4a-4d8e-84f4-712762ab9bed · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 69

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.087412Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:8bc1cc934df3d8f9488aa226f9a0b04430d7eaf9ac413f080d2509764f5ee884

Observation 6c061f65-f33d-4717-992c-7a16f85f5a6a · inbound

Agents at Risk: How Users Unwittingly Undermine LLM Safety cites this paper.

Agents at Risk: How Users Unwittingly Undermine LLM Safety EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:18.184723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:18.184723Z digest=sha256:366ff66ad3d40cc710ef780b941eb5cba1f9869052f025d47ff2dbcd3938963c

Observation 1dca5052-1c53-465f-835c-927dc08e41e1 · inbound

Mind the Gap: Action Rebinding Attacks against Android GUI Agents cites this paper.

Mind the Gap: Action Rebinding Attacks against Android GUI Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-03T09:54:57.641440Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T09:54:57.641440Z digest=sha256:092ae882c708aa708980b08478fe1c22ecdd0279f462031340bd6e8afa407a91

Observation 5d242861-3a0f-417c-9a58-a7df5824c3ab · inbound

Modeling Distinct Human Interaction in Web Agents cites this paper.

Modeling Distinct Human Interaction in Web Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T22:17:05.132343Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T22:17:05.132343Z digest=sha256:70ab8441e7d940de2352f4b38340dc3df0cb54c614334754a462121ff07554fc

Observation 6ccfe973-97ea-404d-a1d6-460e3f42b1b4 · inbound

ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying cites this paper.

ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-11T05:45:57.598580Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-10T17:57:59.918483Z digest=sha256:6592316fbc1ebacabd93acb9b2bac903febd462a3b7ceaafd3bb5f2967544cbb

Observation 0044b1e3-e3fe-4233-ba00-bd340309f7d4 · inbound

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization cites this paper.

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 8

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T17:11:15.332922Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T17:49:39.533090Z digest=sha256:f9f028f6954ffebc9ade1957b54c9186f8572e5e8fa510a57b3bc34acbb0ea77

Observation 3c26c6f5-cf9a-4671-bd85-3923726c167d · inbound

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection cites this paper.

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 141

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:56:13.822914Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=arxiv_source observed=2026-05-07T15:59:49.513500Z digest=sha256:84e25a3a435a3db47e0dc521c640b028dd440392069b9f7846ce70da42463a5d

Observation 0e40d037-6bd5-41b2-a18b-f9557d0f2603 · inbound

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections cites this paper.

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-07-01T14:45:49.587500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-06-30T20:16:13.413064Z digest=sha256:2e4730840a591b8a1d77186b896a5849246b8b25cfc57827e51ff2689c751cec

Observation 55e884d8-c66c-42c2-b55f-62923f4267d7 · inbound

HLL: Can Agents Cross Humanity's Last Line of Verification? cites this paper.

HLL: Can Agents Cross Humanity's Last Line of Verification? EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-07-01T22:56:19.587012Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-06-28T14:57:57.218669Z digest=sha256:ed7d025fcf08d7a8ae28b58885ce4dee14e1af6af99d64cb222d90d2d340e7c7

Observation ec0e7e28-1c72-4aeb-a31f-e010dede3038 · inbound

Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming cites this paper.

Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-07-02T08:06:48.258146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-06-28T06:22:03.848058Z digest=sha256:cea16611b1422dbf4d572c0a5eb8af92ce43bc274e1b8a57aed26569cc9a1333

Observation 0cf6bf26-8ebf-4f9f-82a5-5c6d0eb040fa · inbound

Same-Origin Policy for Agentic Browsers cites this paper.

Same-Origin Policy for Agentic Browsers EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-07-01T07:35:29.038091Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-07-01T07:29:08.355105Z digest=sha256:ab847c51a86d4022323cbed90512c70b01d1218b64a1016261e69b4f79d4cbdc

Observation 09232739-3b47-4587-adea-ada3ad50082f · inbound

Prismata: Confining Cross-Site Prompt Injection in Web Agents cites this paper.

Prismata: Confining Cross-Site Prompt Injection in Web Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 47

Resolution
verified exact
local_arxiv, observed 2026-07-10T12:27:04.061309Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-07-10T12:20:03.672480Z digest=sha256:64ed122ddbcea573722bc2aae151250ad97041b69b73a10abc726522a11c2f28

Observation d4519caf-597f-4eb7-9887-0f80966b45a6 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 282

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.669935Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.669935Z digest=sha256:d16760e50fe01ff3ec24d6acdba4ee4941e5482f0756092449dfdba64cc90126