Pith. sign in

Paper Citation Record · LEDGER

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

As of 18 August 2026, this Paper Citation Record lists 39 of 39 outbound references and 27 inbound Pith citation observations for arXiv:2502.05174.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.05174 v4

Coverage vector

measured 39 of 39 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-08T20:06:58.396831Z

measured 66 of 66 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-18T06:34:40.430872+00:00

measured 27 of 27 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-14T04:23:15.028834Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

39 of 39 outbound references displayed

  • verified exact0
  • verified fuzzy17
  • unresolved22
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bf1d06bc-9a3e-448a-8ba7-829bd0768f4e · outbound

This paper cites write newline.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents write newline

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.210635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.210635Z digest=sha256:9f337c10bbc8857ae40bfc064aa48238eeb1235dd4a89a42fd9fdace8090043c

Observation dea9f8ed-8631-4d93-a512-34e00a5d8c8f · outbound

This paper cites https://learnprompting.org/docs/prompt_hacking/defensive_measures/sandwich_defense, 2023.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents https://learnprompting.org/docs/prompt_hacking/defensive_measures/sandwich_defense, 2023

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.975034Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.216987Z digest=sha256:3a0e0faca1d35630e86a639f227bda3c3baad9a8f26981fbbb0b5d46aeb3d5fe

Observation 7b77f22d-bffb-416f-a020-46cc078078a2 · outbound

This paper cites Claude 3.5 models and computer use, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Claude 3.5 models and computer use, 2024

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.961017Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.222289Z digest=sha256:ae5bcc347a9af817b905c02c42a1f5034d76b012e9e43030d45e769c783657fe

Observation b80735f8-ab6a-4cc9-9bf5-ddab069b1e30 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents StruQ: Defending Against Prompt Injection with Structured Queries

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.227628Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.227628Z digest=sha256:9790676e0e8a564e682c77917fb1f330faf15bcfb5b497dfaf235cc23ad862af

Observation 9dae070a-56be-4e5f-b63a-539284747a04 · outbound

This paper cites SecAlign: Defending Against Prompt Injection with Preference Optimization.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents SecAlign: Defending Against Prompt Injection with Preference Optimization

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.233116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.233116Z digest=sha256:d34808e941f68604044d0747978e9a5555aeed1a11b476956773bcc44b0d2622

Observation 84b70a05-e67c-4f99-960d-baf286abf793 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.946981Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.238658Z digest=sha256:9da3afd47c7894445e1189dee5662e1095fbde51070876c38616e9d6fc084c2d

Observation 292d00cc-2e23-4846-914f-3dc3ae942497 · outbound

This paper cites Deepseek function calling guide.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Deepseek function calling guide

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.932465Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.243672Z digest=sha256:b3f240080264d3d7ee633959ebf511a6f6cbe798bcbda9b671e6a6161dc68fd0

Observation 223ee63e-2043-45f2-bff2-5f55c802e61d · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.248872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.248872Z digest=sha256:9554de46045da78124b47cd8172312d226d758bd90c7d4bcd9d700317130bec1

Observation b1dc6c89-9d97-48be-a6eb-b3b54354f6ec · outbound

This paper cites Attention Tracker: Detecting Prompt Injection Attacks in LLMs.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attention Tracker: Detecting Prompt Injection Attacks in LLMs

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.253925Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.253925Z digest=sha256:e7adba3177297795a4bb812b473e82e42638c7db72bd4c6df1cf29ae7b6c93f3

Observation 6975a179-af4f-48af-95dc-e328b3791da9 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.258918Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.258918Z digest=sha256:d22541d79067c88376adcc0e1e3f9179f290fbb61c8fa9b2047ca644c2148416

Observation 81c623e0-dee3-419b-9334-f00aa2f7ef84 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.263834Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.263834Z digest=sha256:ac6974a3a057aa30523103aeb61bf021101aba62ede51bafeff96d7b27097f72

Observation f927fbde-b04d-4b53-8ffb-d1a5ce0c29d2 · outbound

This paper cites an unresolved cited work.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-08T20:06:58.917814Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.269070Z digest=sha256:d4b10f43bcf1eab3f53532abc73fb13f0e59e30702d8558096cf7ad4c9c2cbe2

Observation 2958124b-7daa-4ad6-9b3d-69e447113e6f · outbound

This paper cites Llama3.3 model cards, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama3.3 model cards, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.902871Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.273661Z digest=sha256:cbff295ed37ef889afd77282887070179df873c448fec91556d75c4736dc5f45

Observation 2300653e-959b-4b9f-81f3-71f10a7ff7dc · outbound

This paper cites Ultimate ChatGPT prompt engineering guide for general users and developers.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ultimate ChatGPT prompt engineering guide for general users and developers

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.888824Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.278368Z digest=sha256:6b699ce8f6f0fd70697f3d8b4f92dcada2ade2ac7886ea418486752d834dac2c

Observation 3c8a0ba8-6613-4941-80b3-81b203a0e047 · outbound

This paper cites Testing Language Model Agents Safely in the Wild.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Testing Language Model Agents Safely in the Wild

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.282814Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.282814Z digest=sha256:da5b5c576d93defa23089ab485f3dc0a2547911ffc10753536d811978a9bb125

Observation e8786f57-27dc-434f-9fea-c06eba48afa7 · outbound

This paper cites Openai text embeddings, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai text embeddings, 2024

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.874469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.287513Z digest=sha256:59d95f2a482f5ad708468e90eebd6ce38447761f9f10875075ee8920c5a2cc42

Observation 4d3cfb36-3fbd-498f-a0ef-efef24db98f6 · outbound

This paper cites Openai function calling guide, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai function calling guide, 2024

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.859955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.292137Z digest=sha256:284a8b61ea452bbf6e40e8952c79bb00421afb045b4d5696b7e097927063c081

Observation ed056a33-5c43-4096-9f46-5aad6e97aea0 · outbound

This paper cites GoEX: Perspectives and Designs Towards a Runtime for Autonomous LLM Applications.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents GoEX: Perspectives and Designs Towards a Runtime for Autonomous LLM Applications

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.296667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.296667Z digest=sha256:5195894c727517fe4f3207b1aae9f50fc6d384dfc1f5a0d8f9d507b4695e8cde

Observation 15640117-b63f-482d-acfd-5ba149c2421a · outbound

This paper cites and Ribeiro, I.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents and Ribeiro, I

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.844863Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.301706Z digest=sha256:c968c07cd8b041e62504867bbd07864b13facf9c37b479d58719dac40adb4983

Observation fa310591-321c-4cb8-9946-08b5fb4d3ea7 · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.829647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.306771Z digest=sha256:316008c43f6a44094c65b983df2a1a09a8ee56566348eeb3a94524ce7b46f0b1

Observation b9f42e10-c581-4f3f-9cea-e68f9267f892 · outbound

This paper cites J., and Hashimoto, T.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents J., and Hashimoto, T

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.813875Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.311563Z digest=sha256:9fbff61190c1d14c7e330d569a6554048a4ecb07f8f604c50f8fd12034bd6d20

Observation bab47efd-26d4-4e4e-87e7-df91a32a3d55 · outbound

This paper cites Ignore this title and H ack AP rompt: Exposing systemic vulnerabilities of LLM s through a global prompt hacking competition.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ignore this title and H ack AP rompt: Exposing systemic vulnerabilities of LLM s through a global prompt hacking competition

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.316068Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.316068Z digest=sha256:45a39d1c93623d7810d6c12071f1d3412f19f85682def77648e815f8629103d5

Observation f52a6040-3dc9-475a-a901-78344b38a012 · outbound

This paper cites A., Svegliato, J., Bailey, L., Wang, T., Ong, I., Elmaaroufi, K., Abbeel, P., Darrell, T., Ritter, A., and Russell, S.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A., Svegliato, J., Bailey, L., Wang, T., Ong, I., Elmaaroufi, K., Abbeel, P., Darrell, T., Ritter, A., and Russell, S

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.798731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.321013Z digest=sha256:6f3eab94fefe95b2621cd429cfd11b12b11cc941962e7fdbc8b5db5a52d262fa

Observation ee407b4a-e4f6-47c2-b901-5d6f7b07b83b · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.325586Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.325586Z digest=sha256:08857eceb8bc8b6882186ea69953743945a4e0059ed9a3c23ab3f952e9deb0f6

Observation 6b492243-a40a-46b2-99eb-196c045e6598 · outbound

This paper cites Prompt injection attacks against GPT-3.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Prompt injection attacks against GPT-3

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.782338Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.330790Z digest=sha256:62fd77ba8ac69b2497b19f19961f082adb1c9013837f006f80779c63bb32b0c9

Observation f2a6f917-3765-4e79-9c51-501658165f08 · outbound

This paper cites Delimiters won’t save you from prompt injection.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Delimiters won’t save you from prompt injection

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.767633Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.335473Z digest=sha256:1ab3ca79532fc3bbbe8c968f2637f4c666d5c2a9180d9602c18b8baa2904b140

Observation 6a90feb9-8f8c-46df-9d07-11fed6300970 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.339855Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.339855Z digest=sha256:9d953167e9e3e0b106f38d558b8ae9780d1538951e85d5b5836506f0c7f742ff

Observation 90c09a10-0c7b-4026-acca-d88284c82bed · outbound

This paper cites System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.344908Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.344908Z digest=sha256:7017433b823c6e5fac09dac5d6d01f69375fc08571870d295a3e4306472f6ba1

Observation 3d187030-68c4-41d5-8272-38aaf24193f0 · outbound

This paper cites A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.349652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.349652Z digest=sha256:3c5569dffe4f9a7c0f70b7e93e76ef3f3f93f0f775a77548c41fce8372c3239d

Observation f395f473-974b-4c1b-90aa-e96b3dcf682c · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.752762Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.354320Z digest=sha256:54134bcce3ead4823c5297a9ef15b49010c074f6192ab10ad9e8253b9538d91d

Observation 51c834a0-bcc7-4ef8-ae66-97d23a97fdcf · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.358737Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.358737Z digest=sha256:4179f787a2efe256c2d4b9ddd64229ca1808c80f38ea2e4ebf40fbd97f1c14b4

Observation a54c5ddd-84e9-4792-90b9-959a80102c65 · outbound

This paper cites Assessing Prompt Injection Risks in 200+ Custom GPTs.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Assessing Prompt Injection Risks in 200+ Custom GPTs

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.363694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.363694Z digest=sha256:7648aad944f5523e49c4af5d9598d8af454ea8c501ea2512b06a01b264e34dab

Observation 9728db56-fcdf-4bc8-9110-f538457876f7 · outbound

This paper cites R-judge: Benchmarking safety risk awareness for LLM agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents R-judge: Benchmarking safety risk awareness for LLM agents

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.737887Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.368510Z digest=sha256:de786709c199eec91a39a7619d27a6850f916186bb3ac661365616b4f2b1aa7d

Observation b9ef8ef5-a886-4dba-b054-fc56eaea1a55 · outbound

This paper cites I njec A gent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents I njec A gent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.372999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.372999Z digest=sha256:feba3ea3f2e0b5f1fac39a7d6c6d2eac706a2c75d3e330d5d2a7b82a90453d5b

Observation 68c84e93-8235-4f7b-91ac-d9b1d83476b2 · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.377603Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.377603Z digest=sha256:610366a2907f18c6def732390d18b786804bbfcf4cb79107b60c0d2c2c097597

Observation 4dbf589f-f2cd-4380-a814-c3ac8c22a68a · outbound

This paper cites Attacking vision-language computer agents via pop-ups, 2024 b.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attacking vision-language computer agents via pop-ups, 2024 b

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T20:06:58.722556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-08-08T20:06:58.382660Z digest=sha256:ca8ec8318052af00359f3555ad0ab5d1bf7925d6a85c5e631d03e06707ef0da8

Observation 6e8a3080-e8a4-4803-9599-75eaf82c2e79 · outbound

This paper cites Poisoning retrieval corpora by injecting adversarial passages.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Poisoning retrieval corpora by injecting adversarial passages

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.387249Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.387249Z digest=sha256:e9fa96eca044802b12d60b8c5bd07d5cf474c92509f58372b7f7adfd6bab075e

Observation 2ec90ab3-1ff6-4bcb-9c8a-40b346d24fd5 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.391995Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.391995Z digest=sha256:995183fd959f68e71414c4cd6275a05d1449587f28af5dd711a9ed60a306c47f

Observation 27efaa9a-50aa-4e30-87aa-399eeb3fc73b · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.396831Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.396831Z digest=sha256:b14fe2f7c73112647b14efd749e458c40533993df795a4dcc4ad602a67fdba79

Pith citing papers

Observation bc0da62c-e2b2-4b9e-9729-d62b6bba9bf5 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.071951Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:49072c91dd03e4420447fce3e337ae310629f5e9afd17c4d7c78c6912a9004ee

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · inbound

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment cites this paper.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:cc94a7a91d327d2dae27737f3c416735053b96cbb2c6fc462aa67be568322725

Observation f04d6e3a-abbb-4b23-900d-a43dd7764acf · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 72

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.076283Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:ecedaafe5fa0d4921e0e2b80f2a69c03d9a0ada44e273ae422c45b9bfe7c9dc6

Observation 83db55d0-db33-4d19-ae2a-643819ab73e1 · inbound

Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection cites this paper.

Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T15:20:17.375618Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-21T15:18:58.274360Z digest=sha256:0f7129c8b961b6a4d716776a816c38e0ada3dfd5a666d703ca71f4ee0a01e23a

Observation eaa09e39-4804-40ab-97b3-d721ad91f20f · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-10T11:55:21.358611Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-10T04:42:33.450658Z digest=sha256:2a53c81a71603122d4fa65a1cb5bac1043ca486b13ff4ad1617931659dcdc87d

Observation dc536703-e33e-4e4c-810f-60d43b326d45 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-21T00:53:53.086682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-21T00:51:22.907932Z digest=sha256:721be80000763147c19fdaf41467d9b4da2b7fb0a31bd636b130789ffa1ebb4c

Observation 27bc2e11-4352-471d-ba9a-ac370452f911 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T15:56:49.153150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:56:49.153150Z digest=sha256:cb54e05c178d112abed5e4f53c56f0601bc212e54dc864bbd93c7800f4ab2ebf

Observation af9bf477-2843-42a9-acb7-81f110a10627 · inbound

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cites this paper.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.500382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:093ef7ce40c08745b9bba316df866193abcaff2661a0767cf7c6eee9413b3410

Observation 27d2da28-7187-47eb-9ce5-535bf8f5b342 · inbound

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization cites this paper.

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-08T17:53:53.269765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-08T17:49:39.533090Z digest=sha256:42faa3c96847a72a7328f8c3cf1cd809908726c26b6a8801cf55b4463953064a

Observation e4adebc1-6504-4c7c-8f20-a8d6b2fd0806 · inbound

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection cites this paper.

ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:56:13.752504Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-05-07T15:59:49.513500Z digest=sha256:0c833145aa4599527a0ece34ecdc4b69d89cc0e6392aecf983bee27be65dc15c

Observation b5f50e10-3b71-4af1-8562-22cb40fb556b · inbound

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents cites this paper.

AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:32:02.602437Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-13T01:31:34.468389Z digest=sha256:aa175277bee9780e335b1eb1383848f273f14448409575c3bab036a58e1d1d00

Observation e8a283c1-48e1-42d5-9cd8-fe9247005d92 · inbound

The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck cites this paper.

The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:32:02.864173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-13T01:31:13.100257Z digest=sha256:6b41e16a789f2112ffdd5f02793155177912fd26eb82706a792fcaebfc4b8a2d

Observation 692f3850-3a5e-4ad4-8cad-e516b7b8185c · inbound

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection cites this paper.

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-20T10:03:14.260886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-20T10:03:05.696380Z digest=sha256:4b5813b75358cb358260cdac30b94756d331a465030a99e65639c002f8c7c9f1

Observation 91bae419-35f8-4a06-987b-eadb178dd4bf · inbound

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection cites this paper.

LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-06-30T18:55:00.614674Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-06-30T18:48:32.929392Z digest=sha256:9659330b69f4b59ff06c51fa2b8e2df2a7cb7ae6a3e71759b16f0f61239f4b81

Observation dc44d31b-78bd-47b2-8f94-db0762f749a9 · inbound

Reframing LLM Agent Security as an Agent-Human Interaction Problem cites this paper.

Reframing LLM Agent Security as an Agent-Human Interaction Problem MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 68

Resolution
verified exact
arxiv_id, observed 2026-06-30T13:54:43.862943Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-06-30T13:52:06.272229Z digest=sha256:0b9d70833d23b770743fa7749cbb48a987d51047174a1ca6b5d80226d9b59bdb

Observation 727f71f4-65f5-463d-aabb-c7f8ff8c006b · inbound

AIRGuard: Guarding Agent Actions with Runtime Authority Control cites this paper.

AIRGuard: Guarding Agent Actions with Runtime Authority Control MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-06-29T12:53:27.162560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-06-29T11:27:11.944532Z digest=sha256:459b74399f4363859ea72312b897d99b7ab85eedbc4477c6518369854c024277

Observation 7b8f0d67-b24c-4feb-bfce-0496f8f3e59f · inbound

Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity cites this paper.

Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-06-28T22:32:43.991088Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-06-28T22:30:14.098291Z digest=sha256:e2c0e48a62e4032ff9e656dc53689f81ed85e996f39af4d51b7465a37b2bf5be

Observation 87627205-3b01-4073-870b-ecf8c197cf77 · inbound

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models cites this paper.

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 17

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T19:22:34.416763Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-06-28T19:19:17.673497Z digest=sha256:604db446d5faf2d25f0fb9ab27bda13b0cb4a09c369570724fd063687f0d8aef

Observation e1954abd-ca21-444a-a120-b1ed758cffee · inbound

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning cites this paper.

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 22

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T04:59:36.379930Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=arxiv_source observed=2026-06-26T16:32:09.625729Z digest=sha256:695522e35486f368d4cac2800bf0c0725032aae9a659a759701062fe891a2478

Observation d79a76aa-5e44-4487-b491-db217ecb54fc · inbound

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents cites this paper.

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:09:45.221940Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-06-26T09:05:22.096955Z digest=sha256:b65be8144a11b1598c9c731ffa26655105be343b605fff00154d04c925d680a8

Observation fa054f62-2795-4ad7-98c8-6a2a4f9a53cc · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 43

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:e5842d9fdd89ea52042ca904504008ab6da0615ba50eb1866c2463f45bea4ddd

Observation 8788fdd6-120c-41e7-ba17-e306332bd7e0 · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 51

Resolution
verified exact
local_arxiv, observed 2026-07-11T02:47:50.246193Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:350db1a3711c108e09226d384431900363bc6f1845c1cf827c539eea4d1a8656

Observation 7409786b-0f30-4634-bcd7-e1b343f720f1 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 206

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.304739Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.304739Z digest=sha256:706da796e4eb95d7daab2327e5fb26419dedb777db821aa43609b9827b9133d1

Observation f2ebbed9-42ad-4d66-a74d-b17e01676a42 · inbound

Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions cites this paper.

Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-04T22:27:22.453591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T22:27:22.453591Z digest=sha256:70e47c1e4669a2fe446e3eb67e83658620497305b44b7da5f0e34969065bae55

Observation 7de49ffb-9ea8-48b1-bdce-4bda27c3e421 · inbound

AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection cites this paper.

AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-08T00:51:38.030612Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T00:51:38.030612Z digest=sha256:3c4c19ecd749754c928dd7903165ddc9a1c041cbd4cda89a0b363d5a461b5bf6

Observation f4992c41-56f8-4f5f-aa4a-0a8bde72ae61 · inbound

Robust Context-Aware Detection of Malicious Instructions in Text cites this paper.

Robust Context-Aware Detection of Malicious Instructions in Text MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-08T13:19:01.988614Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T13:19:01.988614Z digest=sha256:72e50639c22d7925c65de96b71215d4cfb691c60f22d325390f8ece0cb275fc1

Observation 54992195-e40d-41b8-bca5-1cc9f50365a6 · inbound

Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection cites this paper.

Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-14T04:23:15.028834Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-14T04:23:15.028834Z digest=sha256:34bcaf5542b54408306b23741ce3424b227f4afacfa188fee76a9fe95654a2e0