{"as_of":"2026-08-08T19:17:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:93ea0ce00c222ec16c88781f4a687b23e48978d6ea6a672fe671bcfa4aad8b81","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":19,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":19,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-08T06:32:00.761636+00:00","state":"measured"},{"denominator":19,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":19,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T10:40:02.046929Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-07-04T15:59:56.705533Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-07T10:40:02.046929Z","title":"Injecguard: Benchmarking and mitigating over-defense in prompt injection guardrail models.arXiv preprint arXiv:2410.22770, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.06384","last_updated":"2025-06-05T06:01:19Z","snapshot_observed_at":"2026-08-07T17:01:39.395444Z","submitted_at":"2025-06-05T06:01:19Z","title":"Detection Method for Prompt Injection by Integrating Pre-trained Model and Heuristic Feature Engineering","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T10:40:02.046929Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2506.06384"},"observation_digest":"sha256:470e220f9fbcff6239f3de599a6f2ffc283293c737a2288d10262f1640a4b538","observation_id":"347b9855-fd2b-4166-9014-f50b5208fba5","resolution":{"observed_at":"2026-08-07T10:40:02.046929Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-07T05:41:25.422926Z","title":"Injecguard: Benchmarking and mitigating over-defense in prompt injection guardrail models, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.07330","last_updated":"2025-06-09T00:11:06Z","snapshot_observed_at":"2026-08-08T01:51:03.511040Z","submitted_at":"2025-06-09T00:11:06Z","title":"JavelinGuard: Low-Cost Transformer Architectures for LLM Security","version":1},"reference_index":28,"source":"arxiv_source","source_observed_at":"2026-08-07T05:41:25.422926Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2506.07330"},"observation_digest":"sha256:83686ece296f01233b713fa95bb5d4bff5e1ab2879c4a6ff3e0f59ed97246dab","observation_id":"2b4a2a08-6a1f-44f4-8243-56230774416b","resolution":{"observed_at":"2026-08-07T05:41:25.422926Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-06T15:32:52.920395Z","title":"Wang et al","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.15613","last_updated":"2025-07-21T13:38:12Z","snapshot_observed_at":"2026-08-07T05:36:18.121460Z","submitted_at":"2025-07-21T13:38:12Z","title":"Multi-Stage Prompt Inference Attacks on Enterprise LLM Systems","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-06T15:32:52.920395Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2507.15613"},"observation_digest":"sha256:65f409fb1fde4d1083d0f85708d03500a90ef0f244544952b2ac5ccff5508616","observation_id":"1d1e9437-1dc1-4d4b-8fbe-b90aeb12b0bd","resolution":{"observed_at":"2026-08-06T15:32:52.920395Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-04T22:01:57.303234Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.07617","last_updated":"2025-09-09T11:42:06Z","snapshot_observed_at":"2026-08-07T08:32:54.938701Z","submitted_at":"2025-09-09T11:42:06Z","title":"Transferable Direct Prompt Injection via Activation-Guided MCMC Sampling","version":1},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-08-04T22:01:57.303234Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2509.07617"},"observation_digest":"sha256:2aa0099882693f3fd7fd4d19123a017ff1fd6b3c253cd7052b25bbbe6416c100","observation_id":"20ed6250-4fe4-49a9-8648-c3bbcd5cfde3","resolution":{"observed_at":"2026-08-04T22:01:57.303234Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-02T17:00:40.793545Z","title":"Injecguard: Benchmarking and mitigating over-defense in prompt injection guardrail models,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2604.01194","last_updated":"2026-07-25T19:27:27Z","snapshot_observed_at":"2026-08-07T18:02:22.537986Z","submitted_at":"2026-04-01T17:40:03Z","title":"AgentWatcher: A Rule-based Prompt Injection Monitor","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-02T17:00:40.793545Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.01194"},"observation_digest":"sha256:6b794cc5aea24b5bf1be2767878e4ebe152ac466abbe73b308ee2b4101efe93a","observation_id":"aacaf011-08ae-443a-bbec-441cec66951d","resolution":{"observed_at":"2026-08-02T17:00:40.793545Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.07536","last_updated":"2026-04-08T19:18:11Z","snapshot_observed_at":"2026-07-06T22:55:46.307881Z","submitted_at":"2026-04-08T19:18:11Z","title":"TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-05-10T17:16:35.875601Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.07536"},"observation_digest":"sha256:430806cf3194227b42afa823e6e6c6649bc41bb2255e07a7055e37e5efa658a6","observation_id":"43a33fbf-7458-4e60-a867-411c51cd5f03","resolution":{"observed_at":"2026-05-11T07:10:59.673004Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.16543","last_updated":"2026-04-17T02:31:09Z","snapshot_observed_at":"2026-07-06T23:03:52.631613Z","submitted_at":"2026-04-17T02:31:09Z","title":"Conjunctive Prompt Attacks in Multi-Agent LLM Systems","version":1},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-05-10T08:13:42.401992Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.16543"},"observation_digest":"sha256:3d5d085b97473caa2b50aedc7cc4b6a8bef1ca31769f7dcd5326ae0bfb91ac40","observation_id":"1717068b-b9ec-47c5-ac04-c9fd8c3040da","resolution":{"observed_at":"2026-05-10T08:17:37.659730Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.17562","last_updated":"2026-04-19T18:02:21Z","snapshot_observed_at":"2026-07-06T23:04:37.370465Z","submitted_at":"2026-04-19T18:02:21Z","title":"SafeAgent: A Runtime Protection Architecture for Agentic Systems","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-10T06:06:49.717091Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.17562"},"observation_digest":"sha256:b8591d0ca35c98fe396e9ee164be2a676b9d62299b70c371bc8bfae1edf0aec8","observation_id":"43a1b4a0-ea53-4e14-9b25-9621e967ac39","resolution":{"observed_at":"2026-05-10T06:11:20.528650Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.21477","last_updated":"2026-07-14T16:11:06Z","snapshot_observed_at":"2026-08-05T05:24:49.455576Z","submitted_at":"2026-04-23T09:39:15Z","title":"MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-05-09T21:37:28.671785Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.21477"},"observation_digest":"sha256:657ece4822845599166eb2c296ff02715ee3772e00548ff67973cde52908626b","observation_id":"8fc45b19-0e07-4aa2-9b30-ebeceda40819","resolution":{"observed_at":"2026-05-11T14:31:07.935293Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.25109","last_updated":"2026-04-28T01:32:27Z","snapshot_observed_at":"2026-07-06T23:11:02.043135Z","submitted_at":"2026-04-28T01:32:27Z","title":"Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-07T16:22:49.737626Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.25109"},"observation_digest":"sha256:fc187aa6d0ed158e3992e8de16e81947c868017fd6be4da475e1fd3cdf4bf513","observation_id":"695da77a-7ffb-48a2-af18-e81677200800","resolution":{"observed_at":"2026-05-11T23:46:16.667903Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2604.25716","last_updated":"2026-04-28T14:43:40Z","snapshot_observed_at":"2026-08-08T08:44:13.990356Z","submitted_at":"2026-04-28T14:43:40Z","title":"Cross-Lingual Jailbreak Detection via Semantic Codebooks","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-07T16:22:33.567085Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2604.25716"},"observation_digest":"sha256:bdea7177c12600d7334e33c69bf679a1506db961c9609d9001efb74e8f4fa97e","observation_id":"091bbcee-5dc8-4ce6-9393-8f9545cfef88","resolution":{"observed_at":"2026-05-11T23:46:20.461805Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2605.03378","last_updated":"2026-07-08T15:04:28Z","snapshot_observed_at":"2026-08-02T02:34:38.609069Z","submitted_at":"2026-05-05T05:37:00Z","title":"ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-05-07T15:59:49.513500Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2605.03378"},"observation_digest":"sha256:f7af6fffb909ae8cb5209fbd44aa4c0d0f24e75060393de4630729a00eb6aa61","observation_id":"e75f430e-e303-4998-855b-cebf83364a4d","resolution":{"observed_at":"2026-05-11T23:56:13.711295Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2605.11268","last_updated":"2026-05-11T21:46:52Z","snapshot_observed_at":"2026-07-06T23:23:06.755816Z","submitted_at":"2026-05-11T21:46:52Z","title":"Context-Aware Spear Phishing: Generative AI-Enabled Attacks Against Individuals via Public Social Media Data","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-05-13T01:48:46.380615Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2605.11268"},"observation_digest":"sha256:fbc3ec17a71b678af8803e52b78247779bc7fcbeef4e17f0211ded64be1a25fd","observation_id":"32b24594-d718-48da-ab1b-50f31a7952a8","resolution":{"observed_at":"2026-05-13T01:52:05.373296Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2605.26999","last_updated":"2026-05-26T13:19:25Z","snapshot_observed_at":"2026-08-08T09:09:26.193483Z","submitted_at":"2026-05-26T13:19:25Z","title":"Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Signals","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-06-29T18:41:03.566306Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2605.26999"},"observation_digest":"sha256:61becfa4143d792380be0e0ee99a59c6d423f6988fb5d0b09cdd68b0cddf3e55","observation_id":"24f60221-b2c9-48f0-9614-841e88f7e1af","resolution":{"observed_at":"2026-06-29T18:43:50.533635Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2606.02959","last_updated":"2026-06-01T23:29:58Z","snapshot_observed_at":"2026-08-05T09:07:58.107278Z","submitted_at":"2026-06-01T23:29:58Z","title":"Gate AI: LLM Security Benchmark Evaluation Methodology and Results","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-06-28T15:05:08.411286Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2606.02959"},"observation_digest":"sha256:51022a3e0373331169f5567b88959f1640d635bde33ceb32449e5d40195551be","observation_id":"a46510d5-4881-484f-888c-80f14d8b7694","resolution":{"observed_at":"2026-07-01T22:46:19.192719Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2606.07808","last_updated":"2026-06-05T19:36:48Z","snapshot_observed_at":"2026-07-06T23:47:24.424525Z","submitted_at":"2026-06-05T19:36:48Z","title":"Where Instruction Hierarchy Breaks: Diagnosing and Repairing Failures in Reasoning Language Models","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-06-27T21:51:34.829877Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2606.07808"},"observation_digest":"sha256:d0b640de0a72822ba46ad95f55a14f3a0a7742dfd327b102ef4949d1c8c4dab6","observation_id":"7d0bc711-6e2f-4db4-9f43-205da7639bc2","resolution":{"observed_at":"2026-07-02T17:47:18.106890Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2606.22659","last_updated":"2026-06-21T20:30:12Z","snapshot_observed_at":"2026-08-06T09:46:08.173818Z","submitted_at":"2026-06-21T20:30:12Z","title":"Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-06-26T09:55:08.178751Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2606.22659"},"observation_digest":"sha256:c9513e11ace7632ae0769c9a6b69ee7b3cd4085165f8b785bd05f8040e9c89ba","observation_id":"adf2fd2b-bb68-4f33-9e0e-78f69e983fd0","resolution":{"observed_at":"2026-07-04T09:29:44.071869Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":"2410.22770","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-07-04T15:59:56.705533Z","title":"arXiv preprint arXiv:2410.22770 , year=","venue":null,"work_id":"45706307-25f6-4864-8703-fd28eaa5af87","year":2024},"citing_paper":{"arxiv_id":"2606.26377","last_updated":"2026-06-24T21:00:39Z","snapshot_observed_at":"2026-08-06T21:22:26.690649Z","submitted_at":"2026-06-24T21:00:39Z","title":"Verifying Intent and Harm: A Unified Defense Against LLM-Generated Threats","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-06-26T01:10:13.093255Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2606.26377"},"observation_digest":"sha256:b747254169b4b1147d8e37d91dc2a5d43781e94001dc546f0fee64128ac738d0","observation_id":"4d75529e-afc7-4c10-a320-8b837f7e7327","resolution":{"observed_at":"2026-07-04T15:59:56.706982Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-01T22:55:50.728137Z","title":"Injecguard: Benchmarking and mitigating over-defense in prompt injection guardrail models,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.15596","last_updated":"2026-07-23T05:16:37Z","snapshot_observed_at":"2026-08-04T19:26:11.022242Z","submitted_at":"2026-07-17T03:44:05Z","title":"From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows","version":2},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-01T22:55:50.728137Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2607.15596"},"observation_digest":"sha256:680cab0cd8dff19034a197b02f2987644dcb85170f10bca7df417e913a81bd94","observation_id":"004175dd-d908-41ac-89ca-ea002c70cc3b","resolution":{"observed_at":"2026-08-01T22:55:50.728137Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2410.22770/citation-record","integrity":"/paper/2410.22770/integrity","json":"/paper/2410.22770/citation-record.json","paper":"/paper/2410.22770"},"outbound":[],"paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","latest_version":3,"primary_category":"cs.CL","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"thesis":"As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 19 inbound Pith citation observations for arXiv:2410.22770."}