{"as_of":"2026-08-06T01:47:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:440d27b2ee6a8238d1b5315162f1e8341a3d1f0b05ed3db10bc333524913a9dd","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":36,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":36,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-05T06:32:48.257954+00:00","state":"measured"},{"denominator":36,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":36,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-05T23:04:08.645670Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":0,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T23:04:08.645670Z","title":"arXiv preprint arXiv:2504.15585","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2508.06087","last_updated":"2025-08-08T07:29:33Z","snapshot_observed_at":"2026-08-05T23:04:04.288151Z","submitted_at":"2025-08-08T07:29:33Z","title":"Adaptive Backtracking for Privacy Protection in Large Language Models","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-05T23:04:08.645670Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2508.06087"},"observation_digest":"sha256:1d10547263a8ad26d073868e6b66eb91cb103a6d875fc2e6988794d12579bd94","observation_id":"f81e63ee-310a-4b40-a780-cc2cec28daae","resolution":{"observed_at":"2026-08-05T23:04:08.645670Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T10:38:58.402887Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.03871","last_updated":"2025-09-04T04:12:31Z","snapshot_observed_at":"2026-08-05T10:38:56.478715Z","submitted_at":"2025-09-04T04:12:31Z","title":"A Comprehensive Survey on Trustworthiness in Reasoning with Large Language Models","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-05T10:38:58.402887Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.03871"},"observation_digest":"sha256:ba981cba6e1cec0ec42bafae4bd297e4bd73ec7c0cfdad4563437fe1a8f1b104","observation_id":"8360dd42-bfa8-4b80-8ac4-5808aa6baa3c","resolution":{"observed_at":"2026-08-05T10:38:58.402887Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T10:21:47.149354Z","title":"Yu, Qingsong Wen, and Yang Liu","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.04191","last_updated":"2025-09-04T13:13:57Z","snapshot_observed_at":"2026-08-05T10:21:45.069661Z","submitted_at":"2025-09-04T13:13:57Z","title":"KubeGuard: LLM-Assisted Kubernetes Hardening via Configuration Files and Runtime Logs Analysis","version":1},"reference_index":95,"source":"pdf_text","source_observed_at":"2026-08-05T10:21:47.149354Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.04191"},"observation_digest":"sha256:a8f3ebed365f69ec182da2c5ed059aa69684c957e594c1433bc4d0b385f477d3","observation_id":"6dcbcab6-57cf-46f6-b4f6-c7ef91578aa5","resolution":{"observed_at":"2026-08-05T10:21:47.149354Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T04:50:32.170105Z","title":"A comprehensive survey in llm (- agent) full stack safety: Data, training and deployment,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.05946","last_updated":"2025-09-07T06:46:03Z","snapshot_observed_at":"2026-08-05T14:52:11.492382Z","submitted_at":"2025-09-07T06:46:03Z","title":"Large Language Models for Next-Generation Wireless Network Management: A Survey and Tutorial","version":1},"reference_index":175,"source":"pdf_text","source_observed_at":"2026-08-05T04:50:32.170105Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.05946"},"observation_digest":"sha256:ce81babacadf9d340ad79e6385dc245a91364756e39939ea95cd8fcd3f3a29ce","observation_id":"627e0278-77d1-45ca-b4ff-497df50cc0d9","resolution":{"observed_at":"2026-08-05T04:50:32.170105Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-04T14:42:50.674982Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment.arXiv preprint arXiv:2504.15585,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2509.23573","last_updated":"2026-05-28T01:14:19Z","snapshot_observed_at":"2026-08-04T22:20:08.925642Z","submitted_at":"2025-09-28T02:08:27Z","title":"Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence","version":5},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-04T14:42:50.674982Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.23573"},"observation_digest":"sha256:65f6c9d45a0aaeae69d9e20bea9bc15c0a63716f20afcc0db5162a37d0a8c56f","observation_id":"5687e63f-1cfc-491f-8ddc-4cba96ebfa15","resolution":{"observed_at":"2026-08-04T14:42:50.674982Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-04T14:41:50.921051Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment.arXiv preprint arXiv:2504.15585, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.24380","last_updated":"2026-07-04T03:50:21Z","snapshot_observed_at":"2026-08-04T14:41:42.802868Z","submitted_at":"2025-09-29T07:29:18Z","title":"Agentic Services Computing","version":3},"reference_index":178,"source":"pdf_text","source_observed_at":"2026-08-04T14:41:50.921051Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.24380"},"observation_digest":"sha256:b67dab5b53c328b6451ba7d6d56df15afc598a013a398790d6a88f8dd63255e7","observation_id":"3004583b-014b-4f1f-a1fb-04940e398556","resolution":{"observed_at":"2026-08-04T14:41:50.921051Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2509.26100","last_updated":"2026-05-14T06:48:52Z","snapshot_observed_at":"2026-08-03T06:15:45.859457Z","submitted_at":"2025-09-30T11:20:41Z","title":"AgenticEval: Toward Agentic and Self-Evolving Safety Evaluation of Large Language Models","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-05-18T12:35:01.443896Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2509.26100"},"observation_digest":"sha256:615360f0ac722b645c1d7c0d1fabb0341781944f07eec4738dafe4e1e4350067","observation_id":"2fa5d3d6-f2b3-4950-8354-f4c2c0d9357f","resolution":{"observed_at":"2026-05-18T12:36:22.463634Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-04T09:15:21.818144Z","title":"Yu, Qingsong Wen, and Yang Liu","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2510.16492","last_updated":"2026-06-26T11:50:13Z","snapshot_observed_at":"2026-08-04T09:15:18.428835Z","submitted_at":"2025-10-18T13:22:19Z","title":"Check Yourself Before You Wreck Yourself: Selectively Quitting Improves LLM Agent Safety","version":4},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-08-04T09:15:21.818144Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2510.16492"},"observation_digest":"sha256:ae0b42ce008459fd82d820f089c3a91972175a25245a1f8f8fcd2fc224282512","observation_id":"0ccd089e-dbac-49e9-896e-a4b7c58c5b3e","resolution":{"observed_at":"2026-08-04T09:15:21.818144Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-04T08:44:56.504049Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment.arXiv preprint arXiv:2504.15585, 2025a","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2510.19420","last_updated":"2026-05-26T15:57:06Z","snapshot_observed_at":"2026-08-04T08:44:55.576191Z","submitted_at":"2025-10-22T09:43:32Z","title":"Securing Multi-Agent Systems Against Corruptions via Node Contribution Backpropagation","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-04T08:44:56.504049Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2510.19420"},"observation_digest":"sha256:fd307370b475a4163bdf620c2a82ec2dcd97e9bf40737d064f0b6a693e5bc2a1","observation_id":"1f81fcd7-473e-4ead-8dca-e4c2f59e4af5","resolution":{"observed_at":"2026-08-04T08:44:56.504049Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2511.12710","last_updated":"2026-05-18T06:50:41Z","snapshot_observed_at":"2026-07-06T22:35:55.936840Z","submitted_at":"2025-11-16T17:52:07Z","title":"Evolve the Method, Not the Prompts: Evolutionary Synthesis of Jailbreak Attacks on LLMs","version":2},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-05-21T18:58:53.183734Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2511.12710"},"observation_digest":"sha256:5a85e854d37fe9d3ac6e61ec4b631df9d38858ecf5caa2073cf476e45880d6ca","observation_id":"8990c204-c015-4c3a-bd3e-0608db533c45","resolution":{"observed_at":"2026-05-21T19:00:30.397180Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-03T06:23:43.757957Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment.arXiv preprint arXiv:2504.15585,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2602.02557","last_updated":"2026-05-29T23:48:47Z","snapshot_observed_at":"2026-08-03T06:23:40.878064Z","submitted_at":"2026-01-30T14:23:50Z","title":"The Alignment Curse: Modality Alignment Supercharges Audio Attacks via Text Transfer","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-03T06:23:43.757957Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2602.02557"},"observation_digest":"sha256:233c0b1ec211940ef897ea849a604ecd0b1559595c6aa5f7ed292e7e04bffb43","observation_id":"432e8ebe-e187-4091-93ad-ae6b1c7facf7","resolution":{"observed_at":"2026-08-03T06:23:43.757957Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-02T23:43:07.687190Z","title":"org/CorpusID:143424870","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2602.12966","last_updated":"2026-06-09T04:02:52Z","snapshot_observed_at":"2026-08-02T23:42:58.142462Z","submitted_at":"2026-02-13T14:33:13Z","title":"ProbeLLM: Automating Principled Diagnosis of LLM Failures","version":2},"reference_index":2019,"source":"pdf_text","source_observed_at":"2026-08-02T23:43:07.687190Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2602.12966"},"observation_digest":"sha256:e2fdb92ae4c5e29ccf8623b7931f738d9c644472a87be4b03504f7a1036bf127","observation_id":"746a367d-6d75-4b97-850f-e419c3b57eb1","resolution":{"observed_at":"2026-08-02T23:43:07.687190Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2604.11309","last_updated":"2026-04-13T11:12:30Z","snapshot_observed_at":"2026-07-30T17:13:57.164751Z","submitted_at":"2026-04-13T11:12:30Z","title":"The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-05-10T16:07:31.602378Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2604.11309"},"observation_digest":"sha256:aa1fc7fd49ee66d008a94ed22b44fa8649e433abef27fe50d7d467b04c4be444","observation_id":"4125b05d-325a-465f-9376-34ee1f85469b","resolution":{"observed_at":"2026-05-11T09:16:04.234442Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2604.11934","last_updated":"2026-04-13T18:22:50Z","snapshot_observed_at":"2026-07-06T23:00:12.978356Z","submitted_at":"2026-04-13T18:22:50Z","title":"BiasIG: Benchmarking Multi-dimensional Social Biases in Text-to-Image Models","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-05-10T15:33:15.025940Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2604.11934"},"observation_digest":"sha256:7245095d15db39c32b8e17228390ff2863deae3ac86d428a148ff4f5660beceb","observation_id":"e74ea2e4-43ec-46d2-ac23-36da4267756b","resolution":{"observed_at":"2026-05-11T10:21:00.645817Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2604.16321","last_updated":"2026-02-25T07:55:49Z","snapshot_observed_at":"2026-08-03T01:31:14.694940Z","submitted_at":"2026-02-25T07:55:49Z","title":"LLM-Based Multi-Agent Systems for Code Generation: A Multi-Vocal Literature Review","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-05-15T19:52:49.324500Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2604.16321"},"observation_digest":"sha256:c1c126f3a7963298f030dde11c3d3a9da8708dc2ae46b21c4317c2749610b811","observation_id":"1e41d869-3c91-4f07-b6bc-d6471d446470","resolution":{"observed_at":"2026-05-15T19:56:33.814418Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2604.19083","last_updated":"2026-04-21T04:52:38Z","snapshot_observed_at":"2026-07-06T23:05:48.885141Z","submitted_at":"2026-04-21T04:52:38Z","title":"ProjLens: Unveiling the Role of Projectors in Multimodal Model Safety","version":1},"reference_index":178,"source":"arxiv_source","source_observed_at":"2026-05-10T03:00:34.862711Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2604.19083"},"observation_digest":"sha256:3f5a0f13172d199382dc8b68d8f93e003622c9e27ae737a84a7a139974e75a97","observation_id":"93e9fd91-8f12-4b4d-acc2-50be6e16a428","resolution":{"observed_at":"2026-05-11T12:46:05.697693Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2604.27861","last_updated":"2026-04-30T13:44:01Z","snapshot_observed_at":"2026-07-30T08:45:44.179299Z","submitted_at":"2026-04-30T13:44:01Z","title":"TwinGate: Stateful Defense against Decompositional Jailbreaks in Untraceable Traffic via Asymmetric Contrastive Learning","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-05-07T06:12:37.845017Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2604.27861"},"observation_digest":"sha256:0e7a171840149950708b5ece14a3e2a6334a717308006aafc03080fbcb367ef6","observation_id":"9297d37a-a513-4dcd-8b8d-0d9f71da619c","resolution":{"observed_at":"2026-05-12T10:26:29.219146Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.01899","last_updated":"2026-05-03T14:28:08Z","snapshot_observed_at":"2026-07-06T23:15:01.968194Z","submitted_at":"2026-05-03T14:28:08Z","title":"Disentangling Intent from Role: Adversarial Self-Play for Persona-Invariant Safety Alignment","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-05-09T17:24:54.796037Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.01899"},"observation_digest":"sha256:dd3bf536a28d882ff541a8d6d01d2273e5ae936079de04f2188f1a453e50edd4","observation_id":"5b14aa25-c446-4733-8b09-f9ad1b3e762e","resolution":{"observed_at":"2026-05-11T16:21:07.319493Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.11679","last_updated":"2026-05-13T09:28:34Z","snapshot_observed_at":"2026-07-06T23:23:30.499023Z","submitted_at":"2026-05-12T07:38:59Z","title":"Explaining and Breaking the Safety-Helpfulness Ceiling via Preference Dimensional Expansion","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-05-13T01:03:10.263663Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.11679"},"observation_digest":"sha256:9662c3db1568a074b6f1d6b5cb54aee3dad90a2175f0f27b216f85cd5b646553","observation_id":"0536dfdb-3e49-4208-97fc-b63d716f6d09","resolution":{"observed_at":"2026-05-13T01:07:00.563071Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.11679","last_updated":"2026-05-13T09:28:34Z","snapshot_observed_at":"2026-07-06T23:23:30.499023Z","submitted_at":"2026-05-12T07:38:59Z","title":"Explaining and Breaking the Safety-Helpfulness Ceiling via Preference Dimensional Expansion","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-05-14T21:12:06.989077Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.11679"},"observation_digest":"sha256:591f2201348b51e567c5fe7f8ee00e2c0668485ea221ec58f2c78932f31b712b","observation_id":"0eb13ae8-32e2-4dc7-8a0b-27627098488d","resolution":{"observed_at":"2026-05-14T21:12:58.976961Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.12529","last_updated":"2026-04-15T10:56:08Z","snapshot_observed_at":"2026-08-01T15:54:04.993991Z","submitted_at":"2026-04-15T10:56:08Z","title":"BackFlush: Knowledge-Free Backdoor Detection and Elimination with Watermark Preservation in Large Language Models","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-14T21:01:10.756844Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.12529"},"observation_digest":"sha256:2f437a42755b9502befcff03baffcdf96e744a5faaf5dd9e2b62b8fc9cda414e","observation_id":"a6dfaaca-478c-4429-bd9a-077cbb8d879f","resolution":{"observed_at":"2026-05-14T21:02:58.891963Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":52,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:9a3bc496591ab02f9c0f8545d89bd1a6533f4c8671869d37fcb573f2fb9b1a06","observation_id":"9a3344e2-5e67-4e03-bc5a-0669f6456152","resolution":{"observed_at":"2026-05-21T01:43:56.850450Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.20266","last_updated":"2026-05-18T20:21:32Z","snapshot_observed_at":"2026-08-03T05:12:45.221230Z","submitted_at":"2026-05-18T20:21:32Z","title":"A Survey of Large Audio Language Models: Generalization, Trustworthiness, and Outlook","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-05-21T07:38:23.099479Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.20266"},"observation_digest":"sha256:116a6e21d64c804929236792018a5954f43ac629da4e4192205c8d6d08fb2d7e","observation_id":"1ebf339c-e46d-4d65-addf-a2d9d2dc71a7","resolution":{"observed_at":"2026-05-21T07:39:49.124688Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.20641","last_updated":"2026-05-20T02:55:56Z","snapshot_observed_at":"2026-07-06T23:31:13.042581Z","submitted_at":"2026-05-20T02:55:56Z","title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-05-21T04:45:35.079192Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.20641"},"observation_digest":"sha256:6b07f33749c9342de6438dada68375a5da018417ef699d76fedde7e669c13369","observation_id":"49e329d1-315d-45f4-a7b7-b335c0985d17","resolution":{"observed_at":"2026-05-21T04:49:35.654769Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.25603","last_updated":"2026-05-25T08:54:55Z","snapshot_observed_at":"2026-08-03T17:47:49.546009Z","submitted_at":"2026-05-25T08:54:55Z","title":"Detecting Unfaithful Chain-of-Thought via Circuit-Guided Internal-External Discrepancy","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-06-29T21:47:17.894881Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.25603"},"observation_digest":"sha256:c52b2f94339dfca1165b1bac1f72d24273049e5535e92404ee094f51dd0c089b","observation_id":"063b7fbf-a09c-4ef6-82f4-5e3ceab79311","resolution":{"observed_at":"2026-06-29T21:53:59.521103Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.29396","last_updated":"2026-05-28T05:46:38Z","snapshot_observed_at":"2026-08-02T05:05:10.834203Z","submitted_at":"2026-05-28T05:46:38Z","title":"Aligned but Fragile: Enhancing LLM Safety Robustness via Zeroth-Order Optimization","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-06-29T07:41:03.219581Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.29396"},"observation_digest":"sha256:9c80249e193a03e3c1295e2e497c70bc349945549292473ff5bb299d6adea056","observation_id":"a1cdd3b8-337d-4c90-95a3-6dd4ab19b69b","resolution":{"observed_at":"2026-06-29T07:43:13.502152Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.02282","last_updated":"2026-06-01T14:05:35Z","snapshot_observed_at":"2026-07-06T23:42:44.661608Z","submitted_at":"2026-06-01T14:05:35Z","title":"POIROT: Interrogating Agents for Failure Detection in Multi-Agent Systems","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-28T14:44:21.487169Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.02282"},"observation_digest":"sha256:48e1eb761e5aaa4fc94dc5c514dc1986160c9a9fa4d551056bd5d6d245cfa621","observation_id":"df30c543-00b4-46cf-9de7-8d4e668bdb15","resolution":{"observed_at":"2026-07-01T23:06:19.985654Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.05660","last_updated":"2026-06-04T03:43:09Z","snapshot_observed_at":"2026-08-03T21:53:08.948703Z","submitted_at":"2026-06-04T03:43:09Z","title":"Safe Embodied AI for Long-horizon Tasks: A Cross-layer Analysis of Robotic Manipulation","version":1},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-06-28T01:46:36.081851Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.05660"},"observation_digest":"sha256:8d0a95f509f4fc64059560c2bf8f1cead0f2970a54351b2d5d80358a5fe1e3d6","observation_id":"aaa70230-6616-4e55-ad12-b59207d03a12","resolution":{"observed_at":"2026-07-02T12:56:56.715862Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.10749","last_updated":"2026-06-09T12:01:07Z","snapshot_observed_at":"2026-07-31T21:35:18.696472Z","submitted_at":"2026-06-09T12:01:07Z","title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","version":1},"reference_index":182,"source":"pdf_text","source_observed_at":"2026-06-27T12:55:22.831264Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.10749"},"observation_digest":"sha256:b6248ca09fd87ef3de6a4a612d611ee43194a3a4e8be9949135c1cce59f0e909","observation_id":"090f64dc-976d-4b53-b52f-a84b53fc51b1","resolution":{"observed_at":"2026-06-27T13:20:56.866720Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.12474","last_updated":"2026-06-10T05:37:58Z","snapshot_observed_at":"2026-08-03T00:29:20.709630Z","submitted_at":"2026-06-10T05:37:58Z","title":"SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems","version":1},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-06-27T08:04:15.004591Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.12474"},"observation_digest":"sha256:f650599eddda3f1437d81df52133e9dc63e3e90282e6b38e020c34172586515c","observation_id":"7b03d879-f0ea-47f2-8cf2-a175c1c308fc","resolution":{"observed_at":"2026-07-03T13:28:18.834488Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.25442","last_updated":"2026-06-24T06:10:33Z","snapshot_observed_at":"2026-07-06T23:59:52.373272Z","submitted_at":"2026-06-24T06:10:33Z","title":"PolicyAlign: Direct Policy-Based Safety Alignment for Large Language Models","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-06-25T21:09:19.727723Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.25442"},"observation_digest":"sha256:5c660cbce47529d5b88b4903647e1180fb5f66a1095a435442358925f8bc8f91","observation_id":"ef2b4891-04f4-4c96-a460-7e69a64d9593","resolution":{"observed_at":"2026-07-04T19:40:06.706686Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.26106","last_updated":"2026-05-01T16:22:46Z","snapshot_observed_at":"2026-08-04T05:29:19.346451Z","submitted_at":"2026-05-01T16:22:46Z","title":"Reducing Conversational Escalation in Large Language Model Dialogue with Nonviolent Communication Constraints","version":1},"reference_index":9,"source":"arxiv_source","source_observed_at":"2026-07-01T07:56:07.948696Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.26106"},"observation_digest":"sha256:27e64fe089af199c860d65df658a1a77b711d3fdefb0a2a8bdfd49c90c26bfe4","observation_id":"b1fc6796-572d-4c6b-b90d-f88057d94645","resolution":{"observed_at":"2026-07-01T08:05:31.326711Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2606.29239","last_updated":"2026-08-03T15:22:02Z","snapshot_observed_at":"2026-08-06T00:33:51.700213Z","submitted_at":"2026-06-28T07:06:46Z","title":"Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-06-30T07:47:18.350953Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.29239"},"observation_digest":"sha256:aab2b14a3033960b8b614931bef8d77b418db1a7a16055cf658386eecfcf167e","observation_id":"44eabc72-7363-4262-a7ca-ec27128cfdb2","resolution":{"observed_at":"2026-06-30T08:04:28.739091Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-04T04:39:06.922277Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2606.29239","last_updated":"2026-08-03T15:22:02Z","snapshot_observed_at":"2026-08-06T00:33:51.700213Z","submitted_at":"2026-06-28T07:06:46Z","title":"Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors","version":2},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-04T04:39:06.922277Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2606.29239"},"observation_digest":"sha256:1f6fef3138fdc6337ae34ad875434f943b19636fa2dc456cfdd7755d28dfc246","observation_id":"baf5f170-7c2e-4782-985c-c1ae06ee600f","resolution":{"observed_at":"2026-08-04T04:39:06.922277Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-07-14T11:21:48.935912Z","title":"A comprehensive survey in LLM(-agent) full stack safety: Data, training and deployment, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.10487","last_updated":"2026-07-11T21:48:53Z","snapshot_observed_at":"2026-07-16T23:18:24.101473Z","submitted_at":"2026-07-11T21:48:53Z","title":"Temporary Authority, Permanent Effects: Commit-Time Authorization for LLM Agents","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-07-14T11:21:48.935912Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2607.10487"},"observation_digest":"sha256:ceccf21985336807820ff6b951bc4f5d3d659dc32ebfffe031e788d1b4f9e78b","observation_id":"6fc0892e-e9c5-4435-a09e-b5039a8bd066","resolution":{"observed_at":"2026-07-14T11:21:48.935912Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-01T19:02:48.799933Z","title":"arXiv preprint arXiv:2504.15585 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.17117","last_updated":"2026-07-19T08:07:32Z","snapshot_observed_at":"2026-08-01T19:02:25.079720Z","submitted_at":"2026-07-19T08:07:32Z","title":"Persistent Sparse Autoencoders: Learning Feature Timescales in Language Models","version":1},"reference_index":185,"source":"arxiv_source","source_observed_at":"2026-08-01T19:02:48.799933Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2607.17117"},"observation_digest":"sha256:ef0ab1724d57909de46da507473f5cf1cf48c589ef34ea0796790f534178f678","observation_id":"9f185a3e-dd8e-4ffa-9144-a44a7613bf20","resolution":{"observed_at":"2026-08-01T19:02:48.799933Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2504.15585/citation-record","integrity":"/paper/2504.15585/integrity","json":"/paper/2504.15585/citation-record.json","paper":"/paper/2504.15585"},"outbound":[],"paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","latest_version":4,"primary_category":"cs.CR","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"thesis":"As of 6 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 36 inbound Pith citation observations for arXiv:2504.15585."}