{"as_of":"2026-08-12T03:27:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:2f2994c323e2a1e32db4bbe44cd6b336c0a2c0f21f117e98d288494d7ece6f8c","coverage":[{"denominator":43,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":43,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-10T14:38:10.831214Z","state":"measured"},{"denominator":46,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":46,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-11T06:34:44.6726+00:00","state":"measured"},{"denominator":3,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":3,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-06T15:42:00.944376Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-05T22:51:28.498764Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-06T15:42:00.944376Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.15219","last_updated":"2025-07-21T03:41:44Z","snapshot_observed_at":"2026-08-06T15:35:31.690602Z","submitted_at":"2025-07-21T03:41:44Z","title":"PromptArmor: Simple yet Effective Prompt Injection Defenses","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-06T15:42:00.944376Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2507.15219"},"observation_digest":"sha256:8afd77ba6664f595843e862bd1686c1b6d6556f34ac58b0b69c32e3eadf3c091","observation_id":"6fb7aee4-2f44-4257-8920-b8e04a98c701","resolution":{"observed_at":"2026-08-06T15:42:00.944376Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2501.15145","doi":null,"metadata_source":"pith","pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-05T22:51:28.498764Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","venue":"cs.CR","work_id":"3405c5e0-49c7-4576-ac78-69fc6b486a1c","year":2025},"citing_paper":{"arxiv_id":"2508.06418","last_updated":"2025-08-08T16:05:27Z","snapshot_observed_at":"2026-08-08T12:59:56.859606Z","submitted_at":"2025-08-08T16:05:27Z","title":"Quantifying Conversation Drift in MCP via Latent Polytope","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-05T22:51:28.105339Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2508.06418"},"observation_digest":"sha256:e4fa7f89424953c722330ccef19f6e8fd110d644031c9ecb49f0eada66580540","observation_id":"dda0473a-f068-48a5-b58b-73328a2d860b","resolution":{"observed_at":"2026-08-05T22:51:28.507399Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-01T14:11:22.404653Z","title":"Promptshield: Deployable detection for prompt injection attacks,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.18847","last_updated":"2026-07-21T08:35:22Z","snapshot_observed_at":"2026-08-08T16:25:54.761610Z","submitted_at":"2026-07-21T08:35:22Z","title":"Data Leakage Prevention in Agentic Applications via Preemptive Hardening","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-01T14:11:22.404653Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2607.18847"},"observation_digest":"sha256:82463b58fbff115aa422bbdad0f0738a4175d71256dfbcbb00eca799f79855b4","observation_id":"c5cea3cc-776f-49a5-ad13-96b85ee5c4f6","resolution":{"observed_at":"2026-08-01T14:11:22.404653Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2501.15145/citation-record","integrity":"/paper/2501.15145/integrity","json":"/paper/2501.15145/citation-record.json","paper":"/paper/2501.15145"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.418900Z","title":"Synthetic Python Problems(SPP) Dataset","venue":null,"work_id":"d7842b83-3610-4a7e-82c9-7f82dc3259c6","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.655185Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:15598bf41f8436023a4cafd14d17e1a4f20f89d1866c95da4595b72f6624dadc","observation_id":"a9b0e2eb-903f-4636-8665-20e675895086","resolution":{"observed_at":"2026-08-10T14:38:11.422630Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.407722Z","title":null,"venue":null,"work_id":"d38a3e26-5151-48a4-a62b-cd16a818387a","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.659639Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:6587a59f7a8a77e4d5618d86e3dc91ac56b98c90cd6b76cff05e196251c66293","observation_id":"36789142-a7ab-4226-9758-8c02a1c5878e","resolution":{"observed_at":"2026-08-10T14:38:11.411292Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2107.03374","last_updated":"2021-07-14T17:16:02Z","snapshot_observed_at":"2026-08-08T11:58:24.516369Z","submitted_at":"2021-07-07T17:41:24Z","title":"Evaluating Large Language Models Trained on Code","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2107.03374","snapshot_observed_at":"2026-08-10T14:38:10.663848Z","title":null,"venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.663848Z"},"links":{"cited_paper":"/paper/2107.03374","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:31f085927ce3c5423d58719df6f49cf1cd33b21ec16252178a7dc587e469dfd1","observation_id":"b4123771-61eb-4ed3-a78a-1c1f87e2bb74","resolution":{"observed_at":"2026-08-10T14:38:10.663848Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.396402Z","title":null,"venue":null,"work_id":"104f08db-d3ce-4df1-891c-a3dfdfff704d","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.668580Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:07e5bd8c58c2c2a5549a4e1bf96276d44e3fef8289e0ebd6621c131c3a04c223","observation_id":"0a101140-b35d-40a9-8e31-31de44155a63","resolution":{"observed_at":"2026-08-10T14:38:11.400205Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.385656Z","title":null,"venue":null,"work_id":"00d43e87-a9a6-4f2c-928c-534b439cbde2","year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.676549Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:80a7ef6b17927f7ca6fc11ab9cee9080364783f7153d78eaa7238c674c3cbfc4","observation_id":"c1a4e108-e2e6-4b2e-9b53-f1cb3e6f091b","resolution":{"observed_at":"2026-08-10T14:38:11.389301Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14233","last_updated":"2023-05-23T16:49:14Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-05-23T16:49:14Z","title":"Enhancing Chat Language Models by Scaling High-quality Instructional Conversations","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14233","snapshot_observed_at":"2026-08-10T14:38:10.684491Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.684491Z"},"links":{"cited_paper":"/paper/2305.14233","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:b9edc06098c72eb69da13c6a84a0002d9f49ebc0a122729de76ebdf23b75837a","observation_id":"0bea6be7-c00d-4a10-b2ce-9485abc9f5e0","resolution":{"observed_at":"2026-08-10T14:38:10.684491Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.21783","last_updated":"2024-11-23T23:27:33Z","snapshot_observed_at":"2026-08-10T16:40:37.411115Z","submitted_at":"2024-07-31T17:54:27Z","title":"The Llama 3 Herd of Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.21783","snapshot_observed_at":"2026-08-10T14:38:10.689007Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.689007Z"},"links":{"cited_paper":"/paper/2407.21783","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:414af3952f73850837e8abb8cd8d6a5305629ecb3730289c53ef925f945e33a6","observation_id":"f758adff-8c80-43eb-b06f-7ef53093eb12","resolution":{"observed_at":"2026-08-10T14:38:10.689007Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.12173","last_updated":"2023-05-05T14:26:17Z","snapshot_observed_at":"2026-07-06T14:55:08.682906Z","submitted_at":"2023-02-23T17:14:38Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.12173","snapshot_observed_at":"2026-08-10T14:38:10.694084Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.694084Z"},"links":{"cited_paper":"/paper/2302.12173","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:7550c7da561b74bdbab753f1a141975d1ba547c9ab91c4ecec3f00e41fd50755","observation_id":"fbc2aa10-db96-429b-aaa1-a98bad8c4ef6","resolution":{"observed_at":"2026-08-10T14:38:10.694084Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2111.09543","last_updated":"2023-03-24T09:17:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2021-11-18T06:48:00Z","title":"DeBERTaV3: Improving DeBERTa using ELECTRA-Style Pre-Training with Gradient-Disentangled Embedding Sharing","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2111.09543","snapshot_observed_at":"2026-08-10T14:38:10.698026Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.698026Z"},"links":{"cited_paper":"/paper/2111.09543","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:4b3f3ef4d6ccc2cd0b2732178a71e4dda90325a68452c75609158a202fccfe07","observation_id":"430734d5-0bb4-45a0-a7b5-c64c1fbfdc8b","resolution":{"observed_at":"2026-08-10T14:38:10.698026Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2106.09685","last_updated":"2021-10-16T18:40:34Z","snapshot_observed_at":"2026-08-11T08:20:29.798517Z","submitted_at":"2021-06-17T17:37:18Z","title":"LoRA: Low-Rank Adaptation of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2106.09685","snapshot_observed_at":"2026-08-10T14:38:10.702531Z","title":"Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.702531Z"},"links":{"cited_paper":"/paper/2106.09685","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:ef7cb8458b71583318eae77dddff1b45a5e301e8602f0f41501d3d4d720f1bf7","observation_id":"4e929d92-b2ea-4cdd-9efd-3a711c335683","resolution":{"observed_at":"2026-08-10T14:38:10.702531Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.00348","last_updated":"2025-04-23T01:35:19Z","snapshot_observed_at":"2026-08-11T01:59:50.770534Z","submitted_at":"2024-11-01T04:05:59Z","title":"Attention Tracker: Detecting Prompt Injection Attacks in LLMs","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.00348","snapshot_observed_at":"2026-08-10T14:38:10.707493Z","title":"Hsu, and Pin-Yu Chen","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.707493Z"},"links":{"cited_paper":"/paper/2411.00348","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:b2730d5f370a835950934e27b873b5ecf5442d2cbdbb615cd1d40c97abbd7cdf","observation_id":"fa8ae770-decd-434f-9019-873469b9d942","resolution":{"observed_at":"2026-08-10T14:38:10.707493Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.10169","last_updated":"2023-07-19T17:55:13Z","snapshot_observed_at":"2026-08-10T14:34:24.189939Z","submitted_at":"2023-07-19T17:55:13Z","title":"Challenges and Applications of Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.10169","snapshot_observed_at":"2026-08-10T14:38:10.711675Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.711675Z"},"links":{"cited_paper":"/paper/2307.10169","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:0c836026cf671b28be46c0a90ac920a05d81144d1ee449bb8d5dd5103a4d6c38","observation_id":"cdc94ba1-f4e0-4a7b-90e8-0d987d8a083d","resolution":{"observed_at":"2026-08-10T14:38:10.711675Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-10T14:38:10.715889Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.715889Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:ce88d8673f25c3afed8d7a0b9445f2234a3e3068296cf9f707984e644b417867","observation_id":"eb4b1d80-ee42-47ef-97bb-5c0b891f7f69","resolution":{"observed_at":"2026-08-10T14:38:10.715889Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.720746Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.720746Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:319ad6de51aa23faec4e938002982e71be8b2db993202c116439c8d2d8296491","observation_id":"3a570b69-e696-44b6-95e1-7fe185baa0b3","resolution":{"observed_at":"2026-08-10T14:38:10.720746Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.355227Z","title":null,"venue":null,"work_id":"9da1fcbc-47b0-468e-81bf-a0b35c8431f6","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.730931Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:3cd98661a7de8d5299c2687c6ec0513694389ee089323f4916c6faef7fbbae56","observation_id":"7ec546d2-09b4-454d-8931-417970feef7e","resolution":{"observed_at":"2026-08-10T14:38:11.358799Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.343242Z","title":null,"venue":null,"work_id":"26ddd964-e362-4fb4-8eb9-e2e5f2bb9719","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.734732Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:040fb72ac54977c25b15da29b0fbe0c5af205304caeb922cda69958fc88240f8","observation_id":"ae868522-a959-4baa-b726-6accbe7b7d78","resolution":{"observed_at":"2026-08-10T14:38:11.347571Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2303.08774","last_updated":"2024-03-04T06:01:33Z","snapshot_observed_at":"2026-08-07T07:30:12.213965Z","submitted_at":"2023-03-15T17:15:04Z","title":"GPT-4 Technical Report","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2303.08774","snapshot_observed_at":"2026-08-10T14:38:10.738851Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.738851Z"},"links":{"cited_paper":"/paper/2303.08774","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:942b63ac64b87cc660304c01d97629a8d12b4cbfc82f3b0e52297ec03c9da9da","observation_id":"a449f3a9-6ad2-4080-8ef6-29338e173cee","resolution":{"observed_at":"2026-08-10T14:38:10.738851Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.743167Z","title":"Wainwright, Pamela Mishkin, Chong Zhang, Sandhini Agarwal, Katarina Slama, Alex Ray, et al","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.743167Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:bb41dfe056957017e198a088a781f9ab34357dc745d3b47f5fdafd5ccc15c263","observation_id":"1cada18d-5cce-4dc4-933c-4c10486c5a70","resolution":{"observed_at":"2026-08-10T14:38:10.743167Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2211.09527","last_updated":"2022-11-17T13:43:20Z","snapshot_observed_at":"2026-07-06T14:19:47.424778Z","submitted_at":"2022-11-17T13:43:20Z","title":"Ignore Previous Prompt: Attack Techniques For Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2211.09527","snapshot_observed_at":"2026-08-10T14:38:10.752114Z","title":null,"venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.752114Z"},"links":{"cited_paper":"/paper/2211.09527","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:1352b39a11b6b14b7376e5e2b597fa09722eb6f6b17ac632082487c4fe462892","observation_id":"ed18f4c6-1517-4f7b-a14f-541740e2ccbe","resolution":{"observed_at":"2026-08-10T14:38:10.752114Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.17673","last_updated":"2024-01-08T19:11:26Z","snapshot_observed_at":"2026-08-11T18:53:57.726869Z","submitted_at":"2023-12-29T16:37:53Z","title":"Jatmo: Prompt Injection Defense by Task-Specific Finetuning","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.17673","snapshot_observed_at":"2026-08-10T14:38:10.756911Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.756911Z"},"links":{"cited_paper":"/paper/2312.17673","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:0e4773e56bb53fb09dfdc18e32bdaa54cf6a3d0bc5d799d513e908b2e651e4e1","observation_id":"cd390d15-0022-45d2-88a3-f93878cbf92f","resolution":{"observed_at":"2026-08-10T14:38:10.756911Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.323236Z","title":null,"venue":null,"work_id":"930d212e-0410-4edb-b10d-d3ece3f43d48","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.760989Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:5e9f723d661ad7da7f85f6c82c542ad869007f410c87b9e26996773cc41a8597","observation_id":"d306e8c6-4453-470b-87f5-bc4c825e1ff2","resolution":{"observed_at":"2026-08-10T14:38:11.327290Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.310829Z","title":null,"venue":null,"work_id":"9542f6e7-0571-4d26-bd64-1d8ad0ef11b7","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.764678Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:36a9f02ee8f60bef30ed82f50ba0e03da849bd2a8a2b3452977d47c3153c051d","observation_id":"a4944b51-6881-4a3f-98cc-bc88dbeaae2b","resolution":{"observed_at":"2026-08-10T14:38:11.314722Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14965","last_updated":"2024-03-27T04:38:44Z","snapshot_observed_at":"2026-08-07T01:32:47.981682Z","submitted_at":"2023-05-24T09:57:37Z","title":"Tricking LLMs into Disobedience: Formalizing, Analyzing, and Detecting Jailbreaks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14965","snapshot_observed_at":"2026-08-10T14:38:10.768234Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.768234Z"},"links":{"cited_paper":"/paper/2305.14965","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:ccc0554f7eef4badec2dc3d7db25b9c59b31a58fe68698f6571b894efd2bfc97","observation_id":"ea31d402-a21e-4380-a1cb-175ead1a2da6","resolution":{"observed_at":"2026-08-10T14:38:10.768234Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.16119","last_updated":"2024-03-03T00:12:16Z","snapshot_observed_at":"2026-07-06T16:53:18.275859Z","submitted_at":"2023-10-24T18:18:11Z","title":"Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.16119","snapshot_observed_at":"2026-08-10T14:38:10.772475Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.772475Z"},"links":{"cited_paper":"/paper/2311.16119","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:794ac8722122a9cbbd341bdbc08022533487c70c00481a6c1d2eb8f4fc837b18","observation_id":"8a3c8de3-e72f-42e5-9b9b-750ed42eba3e","resolution":{"observed_at":"2026-08-10T14:38:10.772475Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.03825","last_updated":"2024-05-15T12:06:31Z","snapshot_observed_at":"2026-07-06T16:03:34.432602Z","submitted_at":"2023-08-07T16:55:20Z","title":"\"Do Anything Now\": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.03825","snapshot_observed_at":"2026-08-10T14:38:10.776605Z","title":"Do Anything Now","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.776605Z"},"links":{"cited_paper":"/paper/2308.03825","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:61af82311d2d432309b89785f12a4ec61c5b35bd1ce0160d6074accc42311a1f","observation_id":"6d4a26dc-8e4d-407d-98e8-7b3ce237e84d","resolution":{"observed_at":"2026-08-10T14:38:10.776605Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.298716Z","title":null,"venue":null,"work_id":"f1998651-1650-4151-bc27-95a989089a5a","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.780646Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:1f5ad12889331e9f4bdfa700b8197a1ebb07f1dacc86aefef5815a77fb2547be","observation_id":"e954736d-74ad-432f-bd8f-3297b2cc3764","resolution":{"observed_at":"2026-08-10T14:38:11.303077Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.11805","last_updated":"2025-05-09T21:04:06Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-12-19T02:39:27Z","title":"Gemini: A Family of Highly Capable Multimodal Models","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.11805","snapshot_observed_at":"2026-08-10T14:38:10.784378Z","title":"Dai, Anja Hauth, Katie Millican, et al","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.784378Z"},"links":{"cited_paper":"/paper/2312.11805","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:a2a760b8949de50d507129f740da44a8f237b700961aa791dad158ff50b33a43","observation_id":"6daeda31-1370-4c4c-b7da-e9c02c435b21","resolution":{"observed_at":"2026-08-10T14:38:10.784378Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.13971","last_updated":"2023-02-27T17:11:15Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-02-27T17:11:15Z","title":"LLaMA: Open and Efficient Foundation Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.13971","snapshot_observed_at":"2026-08-10T14:38:10.788382Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.788382Z"},"links":{"cited_paper":"/paper/2302.13971","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:aabe781b4e6704d1b44213664419111dd88c7f5122a02048d5b3a2a1566f8145","observation_id":"9031ac05-1c26-46a1-b7ab-8a8391e3d086","resolution":{"observed_at":"2026-08-10T14:38:10.788382Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-11T23:45:02.178667Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.13208","snapshot_observed_at":"2026-08-10T14:38:10.792153Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.792153Z"},"links":{"cited_paper":"/paper/2404.13208","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:3dc5e7a4886809789bf8bb597f9f36b0084ad230dd9044fe7375858a87d968ff","observation_id":"49c8ba2b-bfea-4f87-aeb7-6f2aa4cd2269","resolution":{"observed_at":"2026-08-10T14:38:10.792153Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2408.01605","last_updated":"2024-09-06T18:17:07Z","snapshot_observed_at":"2026-08-09T15:49:58.734883Z","submitted_at":"2024-08-02T23:47:27Z","title":"CYBERSECEVAL 3: Advancing the Evaluation of Cybersecurity Risks and Capabilities in Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2408.01605","snapshot_observed_at":"2026-08-10T14:38:10.796063Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.796063Z"},"links":{"cited_paper":"/paper/2408.01605","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:afc68c6fb4023dcbef2d4e6df7a7de5e974989b2b16765f008213b3d0abf6240","observation_id":"0d80e17d-1ac1-4b7c-befd-95140e1ca5c4","resolution":{"observed_at":"2026-08-10T14:38:10.796063Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2212.10560","last_updated":"2023-05-25T23:50:07Z","snapshot_observed_at":"2026-07-06T14:33:11.945106Z","submitted_at":"2022-12-20T18:59:19Z","title":"Self-Instruct: Aligning Language Models with Self-Generated Instructions","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2212.10560","snapshot_observed_at":"2026-08-10T14:38:10.800055Z","title":"Smith, Daniel Khashabi, and Hannaneh Hajishirzi","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.800055Z"},"links":{"cited_paper":"/paper/2212.10560","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:a565fdb2587b5a3696cdec116af04098ea11bbf247a6ac5778d13670aa458587","observation_id":"6e641870-270d-4651-ae70-77cf1ce74a13","resolution":{"observed_at":"2026-08-10T14:38:10.800055Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2204.07705","last_updated":"2022-10-24T07:00:15Z","snapshot_observed_at":"2026-07-06T13:00:53.618234Z","submitted_at":"2022-04-16T03:12:30Z","title":"Super-NaturalInstructions: Generalization via Declarative Instructions on 1600+ NLP Tasks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2204.07705","snapshot_observed_at":"2026-08-10T14:38:10.804159Z","title":null,"venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.804159Z"},"links":{"cited_paper":"/paper/2204.07705","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:2f96b6e75a0e553d589c5a6df19779843ee66f73862534879af9095a249b06d4","observation_id":"ccf65128-c3b4-44fe-8758-92a5eace32ac","resolution":{"observed_at":"2026-08-10T14:38:10.804159Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2109.01652","last_updated":"2022-02-08T20:26:45Z","snapshot_observed_at":"2026-08-10T07:52:08.606999Z","submitted_at":"2021-09-03T17:55:52Z","title":"Finetuned Language Models Are Zero-Shot Learners","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2109.01652","snapshot_observed_at":"2026-08-10T14:38:10.808151Z","title":"Zhao, Kelvin Guu, Adams Wei Yu, Brian Lester, Nan Du, Andrew M","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.808151Z"},"links":{"cited_paper":"/paper/2109.01652","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:d359d7501f2968c506db93cbac91683c0a16fd792e86234f2f5cb6b03d9295c6","observation_id":"28f8851d-78e6-46dc-9232-b2b29d79ece2","resolution":{"observed_at":"2026-08-10T14:38:10.808151Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.06387","last_updated":"2024-05-25T07:01:15Z","snapshot_observed_at":"2026-08-06T13:25:52.403871Z","submitted_at":"2023-10-10T07:50:29Z","title":"Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.06387","snapshot_observed_at":"2026-08-10T14:38:10.811952Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.811952Z"},"links":{"cited_paper":"/paper/2310.06387","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e0d553f2d9a7141b1dfdca42f1e4d3e5266f2739ecb0cb61416c2c70548d8a97","observation_id":"0175743d-88fe-4eb6-9851-69008c436cdf","resolution":{"observed_at":"2026-08-10T14:38:10.811952Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.285999Z","title":null,"venue":null,"work_id":"33f1f081-6a5b-4769-8944-64b6464cf689","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.816173Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:3ce9207829dab7dd9c2b56a2c47c57c673aaf56262c4292885353a2d2e3c1799","observation_id":"5624ae63-1e2e-44db-a517-e2a5e557d6a0","resolution":{"observed_at":"2026-08-10T14:38:11.290763Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-08-11T04:13:43.714152Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-10T14:38:10.819685Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.819685Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:f63b9ca3ce989bca4cf9183a359551d671dd037371c5668241e612a771adef10","observation_id":"cdda15a5-3796-4d18-9e1a-2d542bc05a47","resolution":{"observed_at":"2026-08-10T14:38:10.819685Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2309.11998","last_updated":"2024-03-10T19:34:57Z","snapshot_observed_at":"2026-07-06T16:21:45.588487Z","submitted_at":"2023-09-21T12:13:55Z","title":"LMSYS-Chat-1M: A Large-Scale Real-World LLM Conversation Dataset","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.11998","snapshot_observed_at":"2026-08-10T14:38:10.823352Z","title":"Xing, et al","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.823352Z"},"links":{"cited_paper":"/paper/2309.11998","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:b6059c18dfdb593bb1b88c8c04877233ca9670397995267ee73c55b66a9ae1c5","observation_id":"defdacfd-8992-4a0f-83f2-a13ab9707d1d","resolution":{"observed_at":"2026-08-10T14:38:10.823352Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.07911","last_updated":"2023-11-14T05:13:55Z","snapshot_observed_at":"2026-07-06T16:47:08.877195Z","submitted_at":"2023-11-14T05:13:55Z","title":"Instruction-Following Evaluation for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.07911","snapshot_observed_at":"2026-08-10T14:38:10.827282Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.827282Z"},"links":{"cited_paper":"/paper/2311.07911","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:846dc9dbd859fcfcfafc0769ea6951ce5aed9a8eb81a28fc96cda37e4271f824","observation_id":"596a5622-8e09-4e7a-9b5e-185a8ea05ab8","resolution":{"observed_at":"2026-08-10T14:38:10.827282Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-07-06T15:59:23.019044Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-10T14:38:10.831214Z","title":"hello!” are classified as an injection). Communications with the model developers revealed that the “jailbreak","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.831214Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:d6f4406debc753573d64f1de6f789006fcad14629b4baa31479496ac36dbeab6","observation_id":"6738e3dd-4006-41f4-b406-2220d1abe217","resolution":{"observed_at":"2026-08-10T14:38:10.831214Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2203.02155","last_updated":"2022-03-04T07:04:42Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-03-04T07:04:42Z","title":"Training language models to follow instructions with human feedback","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2203.02155","snapshot_observed_at":"2026-08-10T14:38:10.747784Z","title":"doi:10.48550/arXiv.2203.02155 arXiv:2203.02155 [cs]","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.747784Z"},"links":{"cited_paper":"/paper/2203.02155","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:62aee1eb6f4937e5c5e30b769e0ac6dcb574d8bc1f60da500ea379a332f0b3f6","observation_id":"c1460b56-bd4c-464d-b07b-71b262190cb2","resolution":{"observed_at":"2026-08-10T14:38:10.747784Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.373294Z","title":"https://www.databricks.com/blog/2023/04/12/dolly-first-open- commercially-viable-instruction-tuned-llm","venue":null,"work_id":"2fbb6085-5096-4b8d-93ae-1cf5277496c4","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.680476Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:0fff7c9ab86b4f89574fbe0ee908c7a0bca71e28bb77320eb6073e058f2365d6","observation_id":"b6211f10-57d6-4d7d-a37a-1691415c0ff9","resolution":{"observed_at":"2026-08-10T14:38:11.377794Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.727112Z","title":"In USENIX Security 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.727112Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:d022ba8965a19026c9db52af3b58fbfe37e33beae416c01196707cf31409d620","observation_id":"dd7110e7-c90d-42a0-9c3c-d11d2a2c5e90","resolution":{"observed_at":"2026-08-10T14:38:10.727112Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.06363","last_updated":"2024-09-25T19:48:39Z","snapshot_observed_at":"2026-08-11T03:37:22.279261Z","submitted_at":"2024-02-09T12:15:51Z","title":"StruQ: Defending Against Prompt Injection with Structured Queries","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.06363","snapshot_observed_at":"2026-08-10T14:38:10.672411Z","title":"doi:10.48550/arXiv.2402.06363 arXiv:2402.06363 [cs]","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2025,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.672411Z"},"links":{"cited_paper":"/paper/2402.06363","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e2209cac5c9d74d394f28a928b1d494055758defb5683a807b0ed51a88c85a0c","observation_id":"56b49855-31aa-49e4-bd2c-99e7ed05df51","resolution":{"observed_at":"2026-08-10T14:38:10.672411Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-11T19:46:34.722732Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks"},"reference_resolution":{"displayed":43,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":41,"verified_exact":0,"verified_fuzzy":2},"total_outbound_references":43},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"thesis":"As of 12 August 2026, this Paper Citation Record lists 43 of 43 outbound references and 3 inbound Pith citation observations for arXiv:2501.15145."}