Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-08T20:06:58.396831Z
Paper Citation Record · LEDGER
As of 18 August 2026, this Paper Citation Record lists 39 of 39 outbound references and 27 inbound Pith citation observations for arXiv:2502.05174.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-08T20:06:58.396831Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-18T06:34:40.430872+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-14T04:23:15.028834Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-05T02:28:24.338817Z
39 of 39 outbound references displayed
External citation measurements
0
pith, observed 2026-08-05T02:28:24.338817Z
Observation bf1d06bc-9a3e-448a-8ba7-829bd0768f4e · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents write newline
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dea9f8ed-8631-4d93-a512-34e00a5d8c8f · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents https://learnprompting.org/docs/prompt_hacking/defensive_measures/sandwich_defense, 2023
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 7b77f22d-bffb-416f-a020-46cc078078a2 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Claude 3.5 models and computer use, 2024
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation b80735f8-ab6a-4cc9-9bf5-ddab069b1e30 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents StruQ: Defending Against Prompt Injection with Structured Queries
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9dae070a-56be-4e5f-b63a-539284747a04 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents SecAlign: Defending Against Prompt Injection with Preference Optimization
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 84b70a05-e67c-4f99-960d-baf286abf793 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 292d00cc-2e23-4846-914f-3dc3ae942497 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Deepseek function calling guide
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 223ee63e-2043-45f2-bff2-5f55c802e61d · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b1dc6c89-9d97-48be-a6eb-b3b54354f6ec · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attention Tracker: Detecting Prompt Injection Attacks in LLMs
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6975a179-af4f-48af-95dc-e328b3791da9 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 81c623e0-dee3-419b-9334-f00aa2f7ef84 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f927fbde-b04d-4b53-8ffb-d1a5ce0c29d2 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Unresolved cited work
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 2958124b-7daa-4ad6-9b3d-69e447113e6f · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Llama3.3 model cards, 2024
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 2300653e-959b-4b9f-81f3-71f10a7ff7dc · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ultimate ChatGPT prompt engineering guide for general users and developers
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 3c8a0ba8-6613-4941-80b3-81b203a0e047 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Testing Language Model Agents Safely in the Wild
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e8786f57-27dc-434f-9fea-c06eba48afa7 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai text embeddings, 2024
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 4d3cfb36-3fbd-498f-a0ef-efef24db98f6 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Openai function calling guide, 2024
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation ed056a33-5c43-4096-9f46-5aad6e97aea0 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents GoEX: Perspectives and Designs Towards a Runtime for Autonomous LLM Applications
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 15640117-b63f-482d-acfd-5ba149c2421a · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents and Ribeiro, I
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation fa310591-321c-4cb8-9946-08b5fb4d3ea7 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Fine-tuned deberta-v3-base for prompt injection detection, 2024
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation b9f42e10-c581-4f3f-9cea-e68f9267f892 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents J., and Hashimoto, T
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation bab47efd-26d4-4e4e-87e7-df91a32a3d55 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Ignore this title and H ack AP rompt: Exposing systemic vulnerabilities of LLM s through a global prompt hacking competition
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f52a6040-3dc9-475a-a901-78344b38a012 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A., Svegliato, J., Bailey, L., Wang, T., Ong, I., Elmaaroufi, K., Abbeel, P., Darrell, T., Ritter, A., and Russell, S
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation ee407b4a-e4f6-47c2-b901-5d6f7b07b83b · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b492243-a40a-46b2-99eb-196c045e6598 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Prompt injection attacks against GPT-3
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation f2a6f917-3765-4e79-9c51-501658165f08 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Delimiters won’t save you from prompt injection
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 6a90feb9-8f8c-46df-9d07-11fed6300970 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Dissecting Adversarial Robustness of Multimodal LM Agents
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 90c09a10-0c7b-4026-acca-d88284c82bed · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3d187030-68c4-41d5-8272-38aaf24193f0 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f395f473-974b-4c1b-90aa-e96b3dcf682c · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Systems
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 51c834a0-bcc7-4ef8-ae66-97d23a97fdcf · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents AdvAgent: Controllable Blackbox Red-teaming on Web Agents
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a54c5ddd-84e9-4792-90b9-959a80102c65 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Assessing Prompt Injection Risks in 200+ Custom GPTs
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9728db56-fcdf-4bc8-9110-f538457876f7 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents R-judge: Benchmarking safety risk awareness for LLM agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation b9ef8ef5-a886-4dba-b054-fc56eaea1a55 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents I njec A gent: Benchmarking indirect prompt injections in tool-integrated large language model agents
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 68c84e93-8235-4f7b-91ac-d9b1d83476b2 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4dbf589f-f2cd-4380-a814-c3ac8c22a68a · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Attacking vision-language computer agents via pop-ups, 2024 b
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 6e8a3080-e8a4-4803-9599-75eaf82c2e79 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Poisoning retrieval corpora by injecting adversarial passages
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2ec90ab3-1ff6-4bcb-9c8a-40b346d24fd5 · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 27efaa9a-50aa-4e30-87aa-399eeb3fc73b · outbound
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bc0da62c-e2b2-4b9e-9729-d62b6bba9bf5 · inbound
Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · inbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f04d6e3a-abbb-4b23-900d-a43dd7764acf · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 83db55d0-db33-4d19-ae2a-643819ab73e1 · inbound
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation eaa09e39-4804-40ab-97b3-d721ad91f20f · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation dc536703-e33e-4e4c-810f-60d43b326d45 · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 27bc2e11-4352-471d-ba9a-ac370452f911 · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation af9bf477-2843-42a9-acb7-81f110a10627 · inbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 27d2da28-7187-47eb-9ce5-535bf8f5b342 · inbound
PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation e4adebc1-6504-4c7c-8f20-a8d6b2fd0806 · inbound
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation b5f50e10-3b71-4af1-8562-22cb40fb556b · inbound
AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation e8a283c1-48e1-42d5-9cd8-fe9247005d92 · inbound
The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 692f3850-3a5e-4ad4-8cad-e516b7b8185c · inbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 91bae419-35f8-4a06-987b-eadb178dd4bf · inbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation dc44d31b-78bd-47b2-8f94-db0762f749a9 · inbound
Reframing LLM Agent Security as an Agent-Human Interaction Problem MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 727f71f4-65f5-463d-aabb-c7f8ff8c006b · inbound
AIRGuard: Guarding Agent Actions with Runtime Authority Control MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 7b8f0d67-b24c-4feb-bfce-0496f8f3e59f · inbound
Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 87627205-3b01-4073-870b-ecf8c197cf77 · inbound
Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation e1954abd-ca21-444a-a120-b1ed758cffee · inbound
Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation d79a76aa-5e44-4487-b491-db217ecb54fc · inbound
When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation fa054f62-2795-4ad7-98c8-6a2a4f9a53cc · inbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8788fdd6-120c-41e7-ba17-e306332bd7e0 · inbound
The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.
Observation 7409786b-0f30-4634-bcd7-e1b343f720f1 · inbound
Agent Security Needs Redefinition through a Holistic Framework MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 206
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f2ebbed9-42ad-4d66-a74d-b17e01676a42 · inbound
Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7de49ffb-9ea8-48b1-bdce-4bda27c3e421 · inbound
AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f4992c41-56f8-4f5f-aa4a-0a8bde72ae61 · inbound
Robust Context-Aware Detection of Malicious Instructions in Text MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 54992195-e40d-41b8-bca5-1cc9f50365a6 · inbound
Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.