Pith. sign in

Paper Citation Record · LEDGER

LLM Agents Should Employ Security Principles

As of 8 August 2026, this Paper Citation Record lists 90 of 90 outbound references and 18 inbound Pith citation observations for arXiv:2505.24019.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.24019 v1

Coverage vector

measured 90 of 90 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T12:42:18.393562Z

measured 108 of 108 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 18 of 18 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T04:33:17.074410Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

90 of 90 outbound references displayed

  • verified exact0
  • verified fuzzy23
  • unresolved67
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bd985b7c-b0df-459b-8000-298db5310957 · outbound

This paper cites Firewalls to Secure Dynamic LLM Agentic Networks.

LLM Agents Should Employ Security Principles Firewalls to Secure Dynamic LLM Agentic Networks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.530457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.530457Z digest=sha256:e3c21561c6ca7366df9ac755bd0c8b912ce407f18d56f29cb697fc6a0c095f98

Observation d5d6c0d8-f456-42ec-a9f2-834243d80537 · outbound

This paper cites Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press.

LLM Agents Should Employ Security Principles Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.608335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.608335Z digest=sha256:7e02b29a6e4eee8fc0239807fb39f3cf03cdd0c5760a49157167643fab5ce396

Observation cdec2bb5-bbf7-450e-a9ff-048260c07d27 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

LLM Agents Should Employ Security Principles Detecting Language Model Attacks with Perplexity

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.698195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.698195Z digest=sha256:c16f8864223096028a82d4cf833350c099b6b64990eabf58f0917bf9fe5d2e9a

Observation d05109fa-289d-4952-ad75-ecd264b038e0 · outbound

This paper cites Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/.

LLM Agents Should Employ Security Principles Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.809393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.809393Z digest=sha256:8194fc0344a5aa398d3ec65522a1abe69e90e3dc1e2e5d28f0d818e260709c37

Observation 089e5c0d-478b-43ef-bfa3-b3b54410e83b · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

LLM Agents Should Employ Security Principles AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.942106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.942106Z digest=sha256:ddeb3d368e8e5eaa18298b865834372e7ff0efc3964ca832834a9baf3e890442

Observation dd089303-22eb-46fd-9132-1b9724232760 · outbound

This paper cites Monitoring computer use via hierarchical summarization.

LLM Agents Should Employ Security Principles Monitoring computer use via hierarchical summarization

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.032707Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.032707Z digest=sha256:9f2a7f15552f84193591ebee69a6be628f41f282f8fe01fef3c93b489278d6d5

Observation 9ff1aaba-0123-4546-9680-1d68c64f885f · outbound

This paper cites Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol.

LLM Agents Should Employ Security Principles Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.133502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.133502Z digest=sha256:1d66eb958acf0f787c60d43f2b46b8f5e9e38425f6b151aefb58f9d1c245c974

Observation be791b63-2bd7-4f41-afd4-8331c45673cb · outbound

This paper cites https://github.com/microsoft/autogen/.

LLM Agents Should Employ Security Principles https://github.com/microsoft/autogen/

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.217203Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.217203Z digest=sha256:380534f699bcad0cc4e7630e626fadddc094b9fc0737f554c2875d18f1ce52c2

Observation d65cd2b0-10c3-4be9-bb2e-824e744adbb6 · outbound

This paper cites AirGapAgent: Protecting privacy-conscious conversational agents.

LLM Agents Should Employ Security Principles AirGapAgent: Protecting privacy-conscious conversational agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.321358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.321358Z digest=sha256:afd7017c818781d7914c489444463d4b72a60da34718ba2709e072d74627b891

Observation d64ee457-9957-4055-8516-91b05dfbe8bd · outbound

This paper cites International AI Safety Report.

LLM Agents Should Employ Security Principles International AI Safety Report

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.396694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.396694Z digest=sha256:34b462cd16e36220f387834fd04237bc208ab66def96361d789d7de53e0747a4

Observation dbcb2b21-ad46-4d62-a163-76dcfe37b233 · outbound

This paper cites Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment.

LLM Agents Should Employ Security Principles Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.476447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.476447Z digest=sha256:66e4bbf5e0e77dea6ddfc606c53c64554768677ea5ed9af1d3b36f7f2d498747

Observation bd117973-b3e8-4121-a09d-423378211520 · outbound

This paper cites Computer Security: Art and Science.

LLM Agents Should Employ Security Principles Computer Security: Art and Science

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.571062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.571062Z digest=sha256:f2c6570e7a8f9a806715eba1d180e1beedd9e57c409606df920aede30c02404a

Observation 8d9940fd-8a91-4caa-9895-691e6f6f76d3 · outbound

This paper cites Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020.

LLM Agents Should Employ Security Principles Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.674312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.674312Z digest=sha256:7f0559a494d8a9f05250b9de13a22b2ce9117b7de3baba331b3119e63f3e4324

Observation d347328e-ca07-425f-b855-b3af2492b132 · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

LLM Agents Should Employ Security Principles Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.749191Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.749191Z digest=sha256:ef67c7fc50024b54388e328d60dc7731ae367dc3b8049187f09d0ab659a36222

Observation 867af2a8-de4d-4a33-8869-65aa2047e972 · outbound

This paper cites Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

LLM Agents Should Employ Security Principles Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.823955Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.823955Z digest=sha256:cc6b7f538945d2c6dfc6a82cc8d59e7fc87bcd653d0c8918b8af9b4e32c983ed

Observation 596ee284-0ea0-4129-8f46-0a457afe19d0 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

LLM Agents Should Employ Security Principles LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.956892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.956892Z digest=sha256:2e3a9060487abba759ead9fea974fe63ab4b9505625ba8689872fd24a5df51c4

Observation 2892f98d-6ca6-4c1c-a487-fc9581d063d9 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

LLM Agents Should Employ Security Principles Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.078265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.078265Z digest=sha256:3be774b57124d91c4dcb4275a905fdeed7053ca032c170d8cddd51300ea29d9b

Observation 4fcb89fa-0184-401d-bb07-7ef9b69a6a92 · outbound

This paper cites LLMs for Customer Service and Support.

LLM Agents Should Employ Security Principles LLMs for Customer Service and Support

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.185759Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.185759Z digest=sha256:887aa086e943f1c6a6d940b69a89f3aad88be975eaea8d77406c8d902d1dd85e

Observation ceb442c8-68b9-40a3-8631-22abaefc089f · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

LLM Agents Should Employ Security Principles AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.263611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.263611Z digest=sha256:67c25b3827b99dd806c50cc710c7d9442775fccdf1eab1b33cf591a6dbc8a546

Observation 25525d58-b3c5-4ba9-805e-03c7bf4cf5dc · outbound

This paper cites A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025.

LLM Agents Should Employ Security Principles A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.351103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.351103Z digest=sha256:93075b0e737b5f09d5a7b5c59535f9a7f49544e507816b12a002d7e90d54322c

Observation daed623c-b688-44db-a438-1e84c1d74c33 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

LLM Agents Should Employ Security Principles LLM Agents can Autonomously Hack Websites

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.460789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.460789Z digest=sha256:d23864e11be0b5b40f9c18db097f89ad0f71491b46ff55ba1a2182c82019eda1

Observation b98b3fef-4049-4ffc-ac4c-0154f96d31d3 · outbound

This paper cites Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms.

LLM Agents Should Employ Security Principles Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.991712Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:12.564782Z digest=sha256:ed50ab0c0a71d58587f414f09806dfa4d16da60f0c7d098952dbb29379da9429

Observation 59849ad6-626a-4837-baa2-6e83386a7dcd · outbound

This paper cites Announcing the Agent2Agent Protocol (A2A), 2025.

LLM Agents Should Employ Security Principles Announcing the Agent2Agent Protocol (A2A), 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.889907Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:12.637148Z digest=sha256:a434046cabf1d5e64079f9163b09a646039c9558c052a1f951c0780b6524087d

Observation eef13c70-b45a-442e-ae02-560f42321cae · outbound

This paper cites Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024.

LLM Agents Should Employ Security Principles Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.790524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:12.733210Z digest=sha256:04022e4b161416d014ae7590a96ded3dcfb3ee01eee0dabe6a90d471b4beafe6

Observation 96993d6c-dce1-4cbf-b163-c9a0afd3c2b9 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

LLM Agents Should Employ Security Principles Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.836704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.836704Z digest=sha256:013528343bad6ef2668bbfe324824be853a4a556b1cd96dc299f75ccd56b7918

Observation 83cb01ea-f7e7-4ada-a985-5faed646f991 · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

LLM Agents Should Employ Security Principles TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.942186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.942186Z digest=sha256:1cde8abf73b9ea345b9f5181ba58bd89518006ece633e59031b410ddbb0d96b2

Observation 1c1f3d12-d2ea-4e88-a032-f246d074d031 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

LLM Agents Should Employ Security Principles Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.041837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.041837Z digest=sha256:d58c11b3c1a5bd5f90055420d7d077776bd0c539718c1c1a93a9db402ac99c67

Observation e070e8a2-7038-46cc-8d1e-ec256ef640c2 · outbound

This paper cites DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines.

LLM Agents Should Employ Security Principles DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.159532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.159532Z digest=sha256:a2622e22d39bb3748a11415bf04499764ef8cd6134687286ac556349fee73c5b

Observation 30dc0c33-a749-4094-8680-eaa2a1479476 · outbound

This paper cites https://github.com/langchain-ai/langchain.

LLM Agents Should Employ Security Principles https://github.com/langchain-ai/langchain

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.630328Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:13.243542Z digest=sha256:e03cc0ad4aa7b6e3c10686bfe1d6212522561ede7bd77601c67ae699b2b9643a

Observation 03efd940-4c6a-4584-833c-436b070c380c · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

LLM Agents Should Employ Security Principles Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.333338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.333338Z digest=sha256:380e6271f5d68fc017efe7c39ef6e57c1271c0feeb60b107f6b5e1defe66de46

Observation 9961eabc-da01-4075-8d8c-7ca6e07d3d7a · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

LLM Agents Should Employ Security Principles DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.406934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.406934Z digest=sha256:c2a85967bdfaf90a07b3840a2e074ab9fdb2fe9c04c6e91cc333705e64e8d726

Observation 9efe313b-f1dc-4273-a168-662a114e3017 · outbound

This paper cites RAIN: Your language models can align themselves without finetuning.

LLM Agents Should Employ Security Principles RAIN: Your language models can align themselves without finetuning

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.448589Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:13.445643Z digest=sha256:b41f3d8ec218513b54a595c3246c89b03191e1cf6713deaf9a1ee2f6549b21f5

Observation ef746f30-99ce-46c0-b78d-883f9882a0a9 · outbound

This paper cites Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025.

LLM Agents Should Employ Security Principles Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.310516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:13.503135Z digest=sha256:8ea1211aa4619577bbd242c230e082c96182cf6b1939b4dd503ed327399379a5

Observation c56f5cee-ca82-4ebd-9976-a68fe5bcdde3 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

LLM Agents Should Employ Security Principles AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.581416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.581416Z digest=sha256:0c9bfb5e4a6496685293fc1ff5f8bd8199f20904528ded3494330b405030944f

Observation 4ba3acef-79e5-48ee-86b5-c7196eac569b · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

LLM Agents Should Employ Security Principles Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.656779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.656779Z digest=sha256:0430c6ea1b0e790c5dedb9a3139f2671842ca0434d30fefe2a699c7ee7769106

Observation 94717349-e1fe-4ad4-a098-bb4a1eefcca5 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

LLM Agents Should Employ Security Principles Prompt Injection attack against LLM-integrated Applications

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.736788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.736788Z digest=sha256:aae86b4a5ab6865a583d7debd64f76098f35804298d6c767dfb6a09c92bd6b99

Observation 4076bcf0-2259-46ef-b7b3-4336c42dee73 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

LLM Agents Should Employ Security Principles Formalizing and benchmarking prompt injection attacks and defenses

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.810103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.810103Z digest=sha256:fd74cbad7a2dae855547da91f828f3d77a55f704893f6f97bd5924099282ebe7

Observation 63ce2e3b-8681-4ef4-932a-ae59ee8ac81d · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024.

LLM Agents Should Employ Security Principles Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.058794Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:13.859636Z digest=sha256:f0b0275c66699b5fefaefc31bb8d15691f110b406c287ab0b264cb2fc5c76c52

Observation 58de7286-4c36-43da-907b-85ec38fcfd78 · outbound

This paper cites Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data.

LLM Agents Should Employ Security Principles Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.926146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:13.934623Z digest=sha256:d5e35a842e2a5c261b948754490784c892991b0ffb2c7a941277f4b1ad87487b

Observation 01f8cddd-f5a4-45f6-9135-eaae55082fa6 · outbound

This paper cites GPT-4 technical report, 2023.

LLM Agents Should Employ Security Principles GPT-4 technical report, 2023

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.016657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.016657Z digest=sha256:fdeeac45b22c901e6279b4f82174974b4c93820c07f965c56eab0faf7a2c1b4f

Observation b3203619-4d85-4a8c-ab2a-f8420dd879cf · outbound

This paper cites Optimizing instructions and demonstrations for multi-stage language model programs.

LLM Agents Should Employ Security Principles Optimizing instructions and demonstrations for multi-stage language model programs

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.731074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.102885Z digest=sha256:33f1bdf2e3c0d9e76cf3aa5c1df1784f9c5d731adedeea3cc1814a416e6b930d

Observation b6d67e25-53c6-461b-aa1d-e997e1b703d6 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

LLM Agents Should Employ Security Principles Ignore Previous Prompt: Attack Techniques For Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.183326Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.183326Z digest=sha256:eb573cc13e33f4e07a96416867c1c121cb393d64ebbb905ff701ece8017c570a

Observation 8526a788-4653-4897-8018-f8bda732c331 · outbound

This paper cites The sandwich defense, 2024.

LLM Agents Should Employ Security Principles The sandwich defense, 2024

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.609888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.231663Z digest=sha256:a6ffde8d2f070675224f711b245d08e56df5c8d0a0139ff7d5bec7099154b9fa

Observation 6a19f497-1e9f-4732-8da4-fc51e0ab031d · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

LLM Agents Should Employ Security Principles Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.391206Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.309044Z digest=sha256:d7e5650c86d85d666190c3105052ac9fd1c52e1d663fca41854fe9f29c39260e

Observation 39a7815c-9f5a-4977-b7ee-6fcf06d14461 · outbound

This paper cites Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024.

LLM Agents Should Employ Security Principles Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.349072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.349072Z digest=sha256:8ba6a6b3940d1a9fc0a7f27186f68d344c099e6812d2a55577537e7891a7ae14

Observation cf62a05f-e636-4597-af89-a63000ad4fd1 · outbound

This paper cites Improving language understanding by generative pre-training.

LLM Agents Should Employ Security Principles Improving language understanding by generative pre-training

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.458743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.458743Z digest=sha256:018886bf506fc31d021a6585b342cabfdd90c0fe2f63d435d1212d77f786430b

Observation b095827c-cbd0-499c-9369-795dbcd17625 · outbound

This paper cites Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019.

LLM Agents Should Employ Security Principles Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.067470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.532396Z digest=sha256:8af194a57c0e884fd95b31ab09144be696d2a6695763f6e67f74ec5c6b64cbe6

Observation e92c744a-dbb5-4a26-ab6a-45083317a23a · outbound

This paper cites Identifying the risks of lm agents with an lm-emulated sandbox.

LLM Agents Should Employ Security Principles Identifying the risks of lm agents with an lm-emulated sandbox

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.597041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.597041Z digest=sha256:9d57e739c67d504983e09ffb644d0da93fc4bf990588cbe13b147fe11dd44177

Observation 5ea5a6d0-fd10-4acd-97a8-9e32e13e4d39 · outbound

This paper cites Saltzer and Michael D.

LLM Agents Should Employ Security Principles Saltzer and Michael D

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.926538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.704723Z digest=sha256:a478be1f80bcc5c8be8a531e6a9f01213949210db795648963d17f3e5c98e633

Observation 12f99703-4403-4662-8a8c-f52513336761 · outbound

This paper cites Scalable and transferable black-box jailbreaks for language models via persona modulation.

LLM Agents Should Employ Security Principles Scalable and transferable black-box jailbreaks for language models via persona modulation

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.847173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.809955Z digest=sha256:8d8087b5cfda065362131d75ff588d10a0901e5e3c17ac39f2c45b0b01d9a335

Observation 2c2bde08-6264-4a0e-8f08-47e16c10a20c · outbound

This paper cites PrivacyLens: Evaluating privacy norm awareness of language models in action.

LLM Agents Should Employ Security Principles PrivacyLens: Evaluating privacy norm awareness of language models in action

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.711449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:14.862141Z digest=sha256:2daf5c00b70126fdbcedc35ebbb0ee4b7adc3e37c023272ebe9249a64e1107ea

Observation ed2e0c91-b822-4f97-aeaf-90334fe082a8 · outbound

This paper cites Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024.

LLM Agents Should Employ Security Principles Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.965587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.965587Z digest=sha256:d066d3f2496a1499cc68f5eab3d4df94d7e2195589cf869bbc4c385c6eff1f51

Observation 490b3d32-0aaf-4692-91a5-47f4cf418e97 · outbound

This paper cites "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.

LLM Agents Should Employ Security Principles "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.041346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.041346Z digest=sha256:8d2f34287be8ca8769363a6f033a7c87e38ffdbcc9d23bd7c0680e2ce0bc2ba3

Observation 7913acda-421d-4cda-b47a-e7e91e03b39d · outbound

This paper cites Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn.

LLM Agents Should Employ Security Principles Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.568018Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:15.133715Z digest=sha256:aa770c2c3b9fbda2817f948c2ae6f5344deec11dcc3572dc289812337d159bf8

Observation 62a2d446-309d-4e3a-bdec-858410c0b0e0 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

LLM Agents Should Employ Security Principles Progent: Securing AI Agents with Privilege Control

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.258181Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.258181Z digest=sha256:5cead9ce2d96e218b5b2b2426f4bba693c79293a7231c8ed93bc19ec478d5a46

Observation 66496283-4700-425d-8a6a-d96b84f88a3d · outbound

This paper cites Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles.

LLM Agents Should Employ Security Principles Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.340645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.340645Z digest=sha256:ede49c0279c93676a72b431e5a2670fb20a992d6b18f9f694794b7b6a5794c6c

Observation 7e370c83-7e1d-49cb-bf5a-fd9b142233aa · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

LLM Agents Should Employ Security Principles LLaMA: Open and Efficient Foundation Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.374992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.374992Z digest=sha256:da368b67c92cc8cc5d0d89eb7a90d6d5545b2abad8cd62d67ac334da8030013d

Observation 49bcb3ce-1f1a-4aa2-b8ed-f22c0a351464 · outbound

This paper cites Contextual Agent Security: A Policy for Every Purpose.

LLM Agents Should Employ Security Principles Contextual Agent Security: A Policy for Every Purpose

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.456892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.456892Z digest=sha256:a12e44100d7874f838023776c7c8d36d531c605d23562cc61816032ae03c247b

Observation ccc84b4b-c405-43f6-a854-5b58edeb97bc · outbound

This paper cites Unveiling Privacy Risks in LLM Agent Memory.

LLM Agents Should Employ Security Principles Unveiling Privacy Risks in LLM Agent Memory

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.532647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.532647Z digest=sha256:e6d26f1ac979214068a7336de1260ae1e297bdadfad06f66a65792f7e034686a

Observation b2416549-9e07-4fe0-a7c2-c50da359fe7e · outbound

This paper cites Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models.

LLM Agents Should Employ Security Principles Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.631370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.631370Z digest=sha256:aa323425b519e964d0887a2f28c724b0ffbbfc8866a099ac21513585d3a09d17

Observation 6e96c548-5365-4c4e-a1c9-ae934e9cf4fd · outbound

This paper cites Jailbroken: How does LLM safety training fail? InNeurIPS, 2023.

LLM Agents Should Employ Security Principles Jailbroken: How does LLM safety training fail? InNeurIPS, 2023

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.471413Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:15.706109Z digest=sha256:581d1bdb51a3cbfcec328dfc8193b6a30df98169cf7a971eb9292b211721153a

Observation 002ddea9-086d-45ec-b623-7ae8f92a9849 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

LLM Agents Should Employ Security Principles IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.770833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.770833Z digest=sha256:f0143780f610485e54eaa80df8afa1b7b4256435ca0d5cdfc64622c693529136

Observation 501d3fa2-9165-4f6f-9a3a-612981623685 · outbound

This paper cites Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023.

LLM Agents Should Employ Security Principles Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.297070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:15.848097Z digest=sha256:f5bc9c2ec2b5342a11cdf44230563fc1bb69b779d5721655fbbbf285e3a544c7

Observation 33867e88-cbca-4552-8a3e-9e4b7474d0df · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024.

LLM Agents Should Employ Security Principles Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.919093Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.919093Z digest=sha256:847c5d15e26f1c2182ce986aadef77876613de88053e285c794becacd368bdb6

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:123e05aeec13f18c2afefe71b4d883a6f0986461eec5342acfe58e98b7203fed

Observation ba5b2bdf-6dcb-42ea-9e6d-51a56a1db8fc · outbound

This paper cites GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts.

LLM Agents Should Employ Security Principles GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.057577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.057577Z digest=sha256:9e0b9740f884261885ade7c406cc6942c03e0048dd60e3e2ccac4ce3ec2570d3

Observation a35ad4c9-6bde-41a7-aa1a-c4a918fbf45e · outbound

This paper cites LLM-Fuzzer: Scaling assessment of large language model jailbreaks.

LLM Agents Should Employ Security Principles LLM-Fuzzer: Scaling assessment of large language model jailbreaks

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.038320Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:16.121597Z digest=sha256:b915afdc4af90f313b0a7ad79e03de3cc911864f009887bbe75e7da96f8e22d0

Observation 9ecd6738-1a77-4f90-b57a-10e3daf71070 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 68

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.780421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:16.201346Z digest=sha256:18a0305ce0dadb996f06db59e7f3fdaf734443f121d971582c3f0d763ce4c7c4

Observation 8971b96f-62de-484e-9f31-5cfc8ebf7e08 · outbound

This paper cites R-Judge: Benchmarking Safety Risk Awareness for LLM Agents.

LLM Agents Should Employ Security Principles R-Judge: Benchmarking Safety Risk Awareness for LLM Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.267748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.267748Z digest=sha256:4d7b450d8c79fbae3e8d37137d7acbb36e39f9dd7dfe0e9b5d34aa31636ad0ab

Observation b55ef027-4d4d-46ce-81ce-066aa0603d52 · outbound

This paper cites GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher.

LLM Agents Should Employ Security Principles GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.601536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:16.345626Z digest=sha256:aa9df8c640eecde5525546ce1dd642882ee7a82dfa7ab635f669939d8da4c60b

Observation 5dc51e68-0ae0-474a-82ae-456547c0ebde · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

LLM Agents Should Employ Security Principles InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.461006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.461006Z digest=sha256:56f2de2b0f25d8b602079a8098a2be3c98647ad9ea3ce0c9f3bd54b63c9ec1e9

Observation 8ac99a43-caa9-4b74-a84e-8675f8bc3679 · outbound

This paper cites Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y.

LLM Agents Should Employ Security Principles Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.440904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:16.557915Z digest=sha256:f98d83c976d97a1eceff89410248f859362e39186274375806941609372bdbf7

Observation 4adf505c-776b-47ab-bae3-822d609394ca · outbound

This paper cites Goal-guided Generative Prompt Injection Attack on Large Language Models.

LLM Agents Should Employ Security Principles Goal-guided Generative Prompt Injection Attack on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.635079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.635079Z digest=sha256:ece449a658b514fe1d6e19a4acf884516f44ffb80802b042f7dff8abf01a17c7

Observation b10c2da8-b53b-4941-aedf-cac699e19392 · outbound

This paper cites Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents.

LLM Agents Should Employ Security Principles Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.322556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:16.733672Z digest=sha256:2095d36af585a08097691a4c32c51d8ccc1fd68a5776d92fb939bb32ae5e3955

Observation 6bd88959-2a42-4211-9da3-316e90d52851 · outbound

This paper cites Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction.

LLM Agents Should Employ Security Principles Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.802912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.802912Z digest=sha256:0e508d704e6bcc65b070eca2826af67a512318e51f406de500609e042e2d0cd9

Observation 9c4055af-829d-4ce2-946d-b7ff3dcb3103 · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

LLM Agents Should Employ Security Principles Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.878014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.878014Z digest=sha256:2d274432159c9109befad1d74ac0ef01f3f6dd34f3c575589b11685bb873f4d7

Observation b4aec45b-fb05-4462-b4da-1ef170ba4aa4 · outbound

This paper cites Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025.

LLM Agents Should Employ Security Principles Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.979796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.979796Z digest=sha256:25f72cf08a98447a040ae37c37836ff236b91fe8688f38a2bf31530d7254c771

Observation 4755f0c4-0df9-493b-bc87-041b609ba668 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

LLM Agents Should Employ Security Principles RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.059726Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.059726Z digest=sha256:c18c4f0caa34333095b57108c6b1ba42a549f02395868a133d886bdb87577012

Observation f9c6f5a0-b45e-4e3f-b09c-c24ef5337624 · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

LLM Agents Should Employ Security Principles WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.145765Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.145765Z digest=sha256:34753ee5b795693e866350bb5291e01b65a4af617e0066d28a1e23ab7c3b1d08

Observation 4e6c1294-ed3f-4e98-9bd1-d33b70975e5f · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

LLM Agents Should Employ Security Principles Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.234871Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.234871Z digest=sha256:3ae5a38472e0ba491beb34f58ece9b629da8b2a5aa0c7aa1981c6edf50b67817

Observation af664236-e50d-4876-a479-04426623bb7f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 81

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.222084Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:17.371158Z digest=sha256:3d09cbc180d5e109c00b6bcea756d6dc6ab5c63eaf7fc2de899a0a3b60bab038

Observation d893c327-457a-43bb-a07b-23da90095d20 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 82

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.117728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:17.414088Z digest=sha256:f3e02f29bcee2e4c50764acf40fb754b6997a8297b1b8bf95e3e4489784066be

Observation 6d981ffe-26a1-4e16-a9c6-f9bd07cd4b93 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 83

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.981233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:17.513349Z digest=sha256:19743de5e36a835a8a8c319c52d7e6cef5eec3dfadb5d424567d71f4112d0908

Observation 068bf66b-2211-4c74-a8f3-0b52c326865f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 84

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.877047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:17.692770Z digest=sha256:4a34ab8d710605d24f5f99043f50cd574722b84288095f4612312ef6941183db

Observation d0b69c9e-f71d-4e53-8e62-b9548e2a0acd · outbound

This paper cites Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning.

LLM Agents Should Employ Security Principles Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:21.708644Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:17.877754Z digest=sha256:e89749644af022429bca0b52408225956b19ae9bd1eb0b923640855d0323228b

Observation 3379054e-420d-48f9-b4ee-1498a4230ae7 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 86

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.492939Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:18.044792Z digest=sha256:58bad26bc8ef8f570b346f4ce816afadeb7fab7b087bf6c41ffeb0a47663e5db

Observation fabc4ed9-d310-4eb0-a9bc-e162304cd1c5 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 87

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.276654Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:18.209326Z digest=sha256:fcec135bbe216d1455c9a2d4b8b1850db554953d6582101246ac61562790b97e

Observation a23379ba-d10b-4a84-8488-6a14c06a5562 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 88

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.946610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:18.275656Z digest=sha256:b766ede4a871966cfa710ca28c5b7a73a284b7dbd89af4a610cafc9ad2f3353e

Observation 3bd0b09a-4f36-4946-aad4-d0ec73c114de · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 89

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.646846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:18.334643Z digest=sha256:23d9beceddbf715d6d2fe5e3493abd0939b2fb3b32113969fed1c2eabfc69ca2

Observation 3586a497-e439-41c5-bcb5-2bfc07e1b6ca · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 90

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.381960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T12:42:18.393562Z digest=sha256:01d3921559f567f061f064b6158fae6be278bd3b87ba37463d108ab5077f8b66

Pith citing papers

Observation 16f8fd0f-70db-4624-818d-15468c6f285e · inbound

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks cites this paper.

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks LLM Agents Should Employ Security Principles

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T04:33:17.074410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:33:17.074410Z digest=sha256:9e1f031bcdd524a1d25fbc75cd5ab9de00330716e92958554726ddf20442e3a1

Observation ac2932f3-7626-4f90-8d04-0933120e2807 · inbound

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance cites this paper.

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance LLM Agents Should Employ Security Principles

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T21:22:59.187197Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:22:59.187197Z digest=sha256:c041c126b5cfeb9a09ef917f1db4284db1960f23fb77ad575b9ac1a963bca23e

Observation 7c43d2ea-12ac-4812-93c2-e9bc600e31ab · inbound

Security Considerations for Artificial Intelligence Agents cites this paper.

Security Considerations for Artificial Intelligence Agents LLM Agents Should Employ Security Principles

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-15T12:40:00.295146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-15T12:37:27.153365Z digest=sha256:d84a6cf1b6e62c10ed297176ef29753a6d3f48ec0cb5db6bc947092c7d00cc5f

Observation 10df942f-6b11-48c7-a27b-d46eaacc960b · inbound

Parallax: Why AI Agents That Think Must Never Act cites this paper.

Parallax: Why AI Agents That Think Must Never Act LLM Agents Should Employ Security Principles

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:01:04.817173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-10T15:13:07.178551Z digest=sha256:37c5da0e785cabf593eef4d306e158e8d1bfb648d5296595a3bbe5d8af4f05ba

Observation a4819020-cad8-41ab-9560-085e22e71429 · inbound

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents cites this paper.

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents LLM Agents Should Employ Security Principles

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:01:14.315710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-09T18:56:12.400565Z digest=sha256:894e3a2550c7b0641d276b27b7a4a9b1c515cd58949336c819a5bedb5a694329

Observation e4e679a8-f1a2-420d-a7ab-a670893e7829 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:46:31.792945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-07T02:12:30.086152Z digest=sha256:5712d1873e1ff5b5ea344b19f94d839585e76f43a39edd1dcb3d0dad5b7f4383

Observation cb51a1bf-cc9b-4d9b-b170-fe13e60abd32 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:55:44.451126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-08T17:56:09.884837Z digest=sha256:23f47de73bf5e008e2ad562c81eaeafb265724d5ed7909ad8ef70cc41d1b04d7

Observation e4d2c026-00c6-45b8-b140-e16f5678ab00 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks LLM Agents Should Employ Security Principles

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.084545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:da48b0b1edbccd017c0ed5d6845a754ffdefc2040683b8941df8ae16d0a74cd7

Observation 65f35965-3cb2-4e70-9c1f-4339f87c9b74 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:28:00.169507Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-14T21:23:48.061702Z digest=sha256:ef7e736d309e939fb6c3d80b27377f8d8e712416a8ea2fd20a090702ba126a59

Observation f948f307-afc6-420e-b662-4c12c1ff14cc · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-20T23:29:12.644850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-20T23:28:47.424991Z digest=sha256:f6bc0869f72c30559093f6e2f0707b67494ca61d122546747434adcc4f9d2950

Observation 0d2ef391-5e3f-409c-b30e-6059138001f7 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-03T00:07:27.596565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-07-02T23:59:14.667099Z digest=sha256:7f736d23f1cd4d07b60cfe4b9bc692274561e99a61390e0f0439fa192187b3da

Observation 7c7b7853-fdc2-4fea-8023-43dc2990d156 · inbound

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI cites this paper.

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI LLM Agents Should Employ Security Principles

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-02T03:26:29.052170Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-28T10:04:44.962968Z digest=sha256:7e59917c86d5f54115e3aae8b1d42279edbe431871bb98795cf3c56ee8ebe498

Observation 71e6500c-65af-4abf-8e9d-d28e894d7da6 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation LLM Agents Should Employ Security Principles

Reference 244

Resolution
verified exact
arxiv_id, observed 2026-06-27T13:20:57.050204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:567dbe587be96f1b7a0235a7821076044b43f424bd4930ea5786a6d4e357f3da

Observation 90a16c7c-2cd5-4ae4-86c9-ef72ddf6ee7f · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-07-04T18:00:00.381118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-25T23:17:58.968269Z digest=sha256:965ee619c8d91d4e03a1649bf70e8a1f7a07442e6270a2c93a84a449c5859a4d

Observation 32bf28b6-f117-4c6b-8aa9-951c366ffe89 · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-12T12:34:58.460933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T12:34:58.460933Z digest=sha256:de6ceb1fd140ec3d850d6c894a3035b0f9232e2a82e10911bd72c8c3ea64521a

Observation c8d7d5bb-4367-4626-a82c-7e3f4a68c151 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents LLM Agents Should Employ Security Principles

Reference 44

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T13:39:51.356324Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:f7d838a72bb24a83cac8de401d47099daf146dcfc394ce60d5cd8233c1636fe6

Observation 58d014e1-8893-40b7-9413-4900eec7ff11 · inbound

Safeguarding LLM Agents from Misalignment through Provenance Analysis cites this paper.

Safeguarding LLM Agents from Misalignment through Provenance Analysis LLM Agents Should Employ Security Principles

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-07-04T01:29:22.001648Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-07-04T01:26:25.858521Z digest=sha256:bfe5f627f61886c808b75239b54be3284d56b62c675bf799af17f37b27aabaa9

Observation 2cc1333c-e2fb-42b6-9c5b-f243dd227d9f · inbound

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents cites this paper.

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents LLM Agents Should Employ Security Principles

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T13:11:53.371921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:11:53.371921Z digest=sha256:022327755021938509a4a176f6cc7185af0105b2e733aae3ab470ee823434a87