{"as_of":"2026-08-07T19:48:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:0939e570bea3ed5efaa4bb8aafa8b50ea63d3e50f286e9e10ccae02769771050","coverage":[{"denominator":55,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":55,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T11:18:55.535553Z","state":"measured"},{"denominator":56,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":56,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-01T14:11:22.454449Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.02859","snapshot_observed_at":"2026-08-01T14:11:22.454449Z","title":"Atag: Ai-agent application threat assessment with attack graphs,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.18847","last_updated":"2026-07-21T08:35:22Z","snapshot_observed_at":"2026-08-06T07:02:17.867246Z","submitted_at":"2026-07-21T08:35:22Z","title":"Data Leakage Prevention in Agentic Applications via Preemptive Hardening","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-01T14:11:22.454449Z"},"links":{"cited_paper":"/paper/2506.02859","citing_paper":"/paper/2607.18847"},"observation_digest":"sha256:aaa660574ee7d71062b1d702e592f6779ca493ec1cedfcf9f3870406f7611bd1","observation_id":"fda9f30d-6ad1-4477-93a0-57b9274de9da","resolution":{"observed_at":"2026-08-01T14:11:22.454449Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2506.02859/citation-record","integrity":"/paper/2506.02859/integrity","json":"/paper/2506.02859/citation-record.json","paper":"/paper/2506.02859"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:48.674343Z","title":"Language models are unsupervised multitask learners,","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.674343Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:8d1b582bab23d882e05d983a4fb259182b259c96f47f99050a63ade9947feb6b","observation_id":"c63fffae-d1ed-4030-9e9e-6550ad9bb90f","resolution":{"observed_at":"2026-08-07T11:18:48.674343Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:48.780703Z","title":"Language models are few-shot learners,","venue":null,"work_id":null,"year":1901},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.780703Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:221e1f932edbd2dddbbf9dac6dbd615532791912dad5791ba05a37567fe6a8d1","observation_id":"f0441c7a-9c19-4a8d-9f6f-9c8a6a617130","resolution":{"observed_at":"2026-08-07T11:18:48.780703Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2303.08774","last_updated":"2024-03-04T06:01:33Z","snapshot_observed_at":"2026-08-07T07:30:12.213965Z","submitted_at":"2023-03-15T17:15:04Z","title":"GPT-4 Technical Report","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2303.08774","snapshot_observed_at":"2026-08-07T11:18:48.928939Z","title":"Gpt-4 technical report,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.928939Z"},"links":{"cited_paper":"/paper/2303.08774","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:63c10c6e08578bea1dac61b896b18e53e02c8a64aec373406d08e36761b12073","observation_id":"b8eeb21e-2ff7-4e49-a254-245bc5c580ef","resolution":{"observed_at":"2026-08-07T11:18:48.928939Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.13971","last_updated":"2023-02-27T17:11:15Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-02-27T17:11:15Z","title":"LLaMA: Open and Efficient Foundation Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.13971","snapshot_observed_at":"2026-08-07T11:18:49.085249Z","title":"Llama: Open and efficient foundation language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.085249Z"},"links":{"cited_paper":"/paper/2302.13971","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:d9596a0e76a4b933c2d8203c425b50b73ee014bf4a868cba708566ed064db1c9","observation_id":"52412f7a-03e4-464e-8fbd-6b9f8f81b4df","resolution":{"observed_at":"2026-08-07T11:18:49.085249Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:05.398213Z","title":"Claude 3 Model Card,","venue":null,"work_id":"7dea28cc-7275-4299-8691-d1070007843c","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.210303Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:8adae854547647f12501c1926fde0b0fb0c2c5e50ad40d116c853f54b530f704","observation_id":"8c90f604-8042-4f09-b31c-3127cb595528","resolution":{"observed_at":"2026-08-07T11:19:05.501190Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:49.296587Z","title":"A survey on large language model based autonomous agents,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.296587Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:6d750298de807a9679c6197db3dcfa5fdd99c65b99089a76a7b336321615c7f4","observation_id":"dc832f8b-ee1f-48c9-aad9-289309528233","resolution":{"observed_at":"2026-08-07T11:18:49.296587Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.01680","last_updated":"2024-04-19T01:15:16Z","snapshot_observed_at":"2026-08-06T19:10:15.466826Z","submitted_at":"2024-01-21T23:36:14Z","title":"Large Language Model based Multi-Agents: A Survey of Progress and Challenges","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.01680","snapshot_observed_at":"2026-08-07T11:18:49.400413Z","title":"Large language model based multi-agents: A survey of progress and challenges,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.400413Z"},"links":{"cited_paper":"/paper/2402.01680","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:1c9979a896c5120dae5619644b4f66e4e7a75141b0e5135e195c4867db59813c","observation_id":"0d6977d2-d81f-4744-b681-e7b6340cf7da","resolution":{"observed_at":"2026-08-07T11:18:49.400413Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:05.175283Z","title":"LangChain: Build AI apps with LLMs through composability,","venue":null,"work_id":"e3efbd19-6082-456f-a03a-4542d9f08687","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.505512Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:1c321798bac8ba64db1c25c04cdf006703bb65978921d9c3311245015beea714","observation_id":"58030831-e7eb-46ec-aacb-4950a66418fa","resolution":{"observed_at":"2026-08-07T11:19:05.275361Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.08155","last_updated":"2023-10-03T20:47:10Z","snapshot_observed_at":"2026-07-31T19:03:03.494918Z","submitted_at":"2023-08-16T05:57:52Z","title":"AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.08155","snapshot_observed_at":"2026-08-07T11:18:49.618134Z","title":"Autogen: Enabling next-gen llm applications via multi-agent conversation,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.618134Z"},"links":{"cited_paper":"/paper/2308.08155","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:007ed6cf9ddbb5b894d931b6955387c3d9cc98c05e88f357074de728e7d9396b","observation_id":"bbb90895-17c1-4554-9e9b-1c6347d8abfd","resolution":{"observed_at":"2026-08-07T11:18:49.618134Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.951468Z","title":"Mulval: A logic-based network security analyzer","venue":null,"work_id":"257924d1-4565-461b-9f87-7d7d417051dc","year":2005},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.695176Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:95fe69802f74d8415275af79a88a1edc69e9eea0ebcdc21b36938e60ae7d0b24","observation_id":"75d7ce63-e997-4bb7-88dc-2338a60c56b7","resolution":{"observed_at":"2026-08-07T11:19:05.063110Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:49.820335Z","title":"A scalable approach to attack graph generation,","venue":null,"work_id":null,"year":2006},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.820335Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:20b23a6bfe6487e393f614be84e396d98f70f9acd179cc9563598e10bec1978c","observation_id":"e36a6302-7e41-49a9-bb43-389c808f5390","resolution":{"observed_at":"2026-08-07T11:18:49.820335Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.657089Z","title":"From attack graphs to automated configuration management-an iterative approach,","venue":null,"work_id":"e8c303ba-70fe-4b64-8574-b2bb3831bd0e","year":2008},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.949489Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:c4cf564a84b635a9d449fbca8903e99694986a61db973850b33c55a2abe19aaa","observation_id":"9c1d6ce0-70b9-4c8c-9eb1-ea9be44002b6","resolution":{"observed_at":"2026-08-07T11:19:04.788938Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.398114Z","title":"Ou and A","venue":null,"work_id":"08634202-4f38-47b7-ad11-fc61a28f0e6e","year":2011},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.147494Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e6d4a1782a5b4cbc1b6d929fef3251b48746696db46740829e6d6f7a84afda40","observation_id":"9ca26995-f4bc-497b-ad74-276c25caa19e","resolution":{"observed_at":"2026-08-07T11:19:04.545803Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.223626Z","title":"Securing the supply chain for commodity it devices by automated scenario generation,","venue":null,"work_id":"312dc28f-2ebc-486e-8250-daf713225fa1","year":2015},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.298247Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:d132581ea0c803da14c1cac5bd63f66b6808494fa2916c2ad2528b7485ff6642","observation_id":"ed891b79-6dcf-4fd5-8d3c-ad15154cc1d0","resolution":{"observed_at":"2026-08-07T11:19:04.286718Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.957536Z","title":"Augmenting attack graphs to represent data link and network layer vulnerabilities,","venue":null,"work_id":"a33ee8e6-fc04-411c-af97-ce65f1ca7164","year":2016},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.454148Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:571b44db1bc341889779bd4522d3fd0d9be99e6fc8ba1f69bb7b33646703ceb9","observation_id":"fb3d129d-8a1f-4259-962d-abea7ffe2a90","resolution":{"observed_at":"2026-08-07T11:19:04.067304Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.878767Z","title":"Extending attack graphs to represent cyber-attacks in communication protocols and modern it networks,","venue":null,"work_id":"a2255956-4594-4ee7-982c-8f72e87f505c","year":1936},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.589951Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:54f87675cc02e40aa289edfcd676e2dc3e3237a1c904efa20fb321ff92d17a9e","observation_id":"ca34c6a1-94b4-4738-9df4-2b095c21ac19","resolution":{"observed_at":"2026-08-07T11:19:03.940406Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.647621Z","title":"Inferring the stealthy bridges between enterprise network islands in cloud using cross- layer bayesian networks,","venue":null,"work_id":"c58040ea-6a84-4eb8-8967-0a4e6bde3b0f","year":2014},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.753676Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:0fd51a105537a2371bc3dc1a8d9ecef8e4633c7390470ac4be081ed33354edb1","observation_id":"7052f5ed-fd6b-4c5e-95f2-4c4706160ba2","resolution":{"observed_at":"2026-08-07T11:19:03.766737Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.434681Z","title":"Generation and dynamic update of attack graphs in cloud providers infrastructures,","venue":null,"work_id":"6c893ab0-6dc7-43cf-9a6f-8631457e93a2","year":2019},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.940100Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e638b9bc4c8a0e4c0774938cc6ee3210f1b349134a85346a7b3ab0a6ae896f3e","observation_id":"a680d97c-4469-47f2-87df-c4ed4b50b361","resolution":{"observed_at":"2026-08-07T11:19:03.540924Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.152201Z","title":"Computer-aided human centric cyber situation awareness,","venue":null,"work_id":"3b4d55e8-c686-4017-b058-e874bfa8175d","year":2017},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.089724Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:a3ebe25f32eab66254b261155e8667ff98694f8e9841ee380c59cb557aa457bd","observation_id":"f22a145f-8024-4557-b84e-2ac7afba0836","resolution":{"observed_at":"2026-08-07T11:19:03.320321Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.957045Z","title":"Coral: Container online risk assessment with logical attack graphs,","venue":null,"work_id":"7b66fb72-8111-4410-85bf-c146f9874aa9","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.195328Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:b49e50ffe4b92f2d91c70889ae3a6c30d3d3444d5dc95f9b5262beccd1218f91","observation_id":"17f92936-051d-4945-9947-08347229e2e0","resolution":{"observed_at":"2026-08-07T11:19:03.055511Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.764221Z","title":"Survey of different large language model architectures: Trends, benchmarks, and chal- lenges,","venue":null,"work_id":"0a63925b-5b97-40e3-ae82-830e0c4a214d","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.322376Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:2a54aa4025f02ff5e5f042b9c8261ec0fdeb29c538aba1b28d115dfedc7c6b1b","observation_id":"b049d9b6-b4da-4a18-9e50-d280dd20a4f2","resolution":{"observed_at":"2026-08-07T11:19:02.851632Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.547879Z","title":"LangGraph: Building language agents as graphs,","venue":null,"work_id":"1f9764f6-d470-402f-b2c9-100c93235008","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.464218Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:c01342f60c50a75a530e9905e62a0f08c8d9e5fa663139caee1b7d37ca0623be","observation_id":"744f0259-4a33-4805-9d8f-8ea278418d29","resolution":{"observed_at":"2026-08-07T11:19:02.643299Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.413609Z","title":"crewAI: Cutting-edge framework for orchestrating role-playing, autonomous AI agents,","venue":null,"work_id":"05b88867-3bb9-4e61-ba6d-868ca0557268","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.577998Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:11834cb576e2b88b5927924ba636daf9fbfcee6aefe3fb8c68169cc22ef287d3","observation_id":"e281dc25-700f-413d-b83a-a1f727507a88","resolution":{"observed_at":"2026-08-07T11:19:02.498207Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.155714Z","title":"crewAI Examples,","venue":null,"work_id":"c613d129-52cc-4a75-ab5f-7b9c93ed8381","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.694702Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e1e8d38e37d7b5e06554ed182afcb32c9c987d51d7bfd021fe1082de3868a7d9","observation_id":"737f5dec-e96e-4a1b-8698-3cc5b7f78409","resolution":{"observed_at":"2026-08-07T11:19:02.276450Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.932141Z","title":"Autogen 0.2 Examples,","venue":null,"work_id":"bbf2aec7-a9b8-4037-89e8-50b59d854ddd","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.831061Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:75bac4ebe50b2350e4a07b2364856fbf9edc90decac8f5135e82dd9a85db7790","observation_id":"f36dea29-b774-4d34-b8c7-d848dd70c2b8","resolution":{"observed_at":"2026-08-07T11:19:02.045953Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.665739Z","title":"LangGraph Examples,","venue":null,"work_id":"cf1aa33f-da79-4237-ad67-d8083cce5bed","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.952409Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:09fbb7c934466a90025b404e74bec9c9543b73140935cd28515677ca1f77f822","observation_id":"973a10ca-a6af-4bb4-ba20-703716346497","resolution":{"observed_at":"2026-08-07T11:19:01.797617Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"8394.37083","doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:56.595793Z","title":"Llm security alignment framework design based on personal preference,","venue":null,"work_id":"8a524519-4d48-40ae-832a-aa54b1aa9634","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.053705Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e46de5c33e2bd0ec271696448ee9ab14ab1264d05ada59c281de127db3e7d306","observation_id":"f97c28d9-ba4a-41a4-9f3c-cafe4325eb48","resolution":{"observed_at":"2026-08-07T11:18:56.674641Z","resolver_source":"raw_fallback","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.05374","last_updated":"2024-03-21T00:21:14Z","snapshot_observed_at":"2026-08-02T17:09:20.540788Z","submitted_at":"2023-08-10T06:43:44Z","title":"Trustworthy LLMs: a Survey and Guideline for Evaluating Large Language Models' Alignment","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.05374","snapshot_observed_at":"2026-08-07T11:18:52.176666Z","title":"Trustworthy llms: A survey and guideline for evaluating large language models’ alignment,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.176666Z"},"links":{"cited_paper":"/paper/2308.05374","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:4674eb9fb36aca3cf471566ce090a54b904f3ddfc9047782d846d4e0a17a45c1","observation_id":"5026185b-a223-470a-bde8-d2f84acca9a0","resolution":{"observed_at":"2026-08-07T11:18:52.176666Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.423983Z","title":"Jailbroken: How does llm safety training fail?","venue":null,"work_id":"07c927b0-ef1e-4502-8026-de909774ca46","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.289961Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:70055b8d9ee7fed40012fb9bc5bb77f4664f4e2d1fb76486dd89a91c9043531c","observation_id":"ab045007-7e8b-439b-9cac-ca931c546b99","resolution":{"observed_at":"2026-08-07T11:19:01.520593Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05499","last_updated":"2025-12-29T02:25:27Z","snapshot_observed_at":"2026-07-06T15:40:27.639368Z","submitted_at":"2023-06-08T18:43:11Z","title":"Prompt Injection attack against LLM-integrated Applications","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.05499","snapshot_observed_at":"2026-08-07T11:18:52.408113Z","title":"Prompt injection attack against llm-integrated applications,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.408113Z"},"links":{"cited_paper":"/paper/2306.05499","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:da3d2a5454377655137a735365f3bb8aea69731788aa05e9491797f46f933075","observation_id":"cd262355-7ecb-434e-b300-facc1e862685","resolution":{"observed_at":"2026-08-07T11:18:52.408113Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.179855Z","title":"Universal and transferable adversarial attacks on aligned language models, 2023,","venue":null,"work_id":"f80d4d75-2923-44c2-80b7-5fa814b2bd82","year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.543147Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:918285d76a951e620f3c76bead03a180f94e021c46062cc9d7bb8ac34f7b2058","observation_id":"394989b3-4609-4313-93d3-dbd905f88339","resolution":{"observed_at":"2026-08-07T11:19:01.274640Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.04769","last_updated":"2024-03-11T01:21:32Z","snapshot_observed_at":"2026-07-06T17:41:10.677334Z","submitted_at":"2024-02-16T17:02:53Z","title":"Using Hallucinations to Bypass GPT4's Filter","version":2},"cited_work":{"arxiv_id":"2403.04769","doi":null,"metadata_source":"pith","pith_arxiv_id":"2403.04769","snapshot_observed_at":"2026-08-07T11:18:56.242164Z","title":"Using Hallucinations to Bypass GPT4's Filter","venue":"cs.CR","work_id":"f617f7bd-7a00-4a17-b930-7de74e801ab3","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.685303Z"},"links":{"cited_paper":"/paper/2403.04769","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:b950fe00f190017ffb25b7fe258eb41b27135b0f1a59288aba9f4f56baee4636","observation_id":"f2f97a6d-e7a4-4b73-8754-fdce16afb0ef","resolution":{"observed_at":"2026-08-07T11:18:56.369783Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:52.842202Z","title":"Why are web ai agents more vulnerable than standalone llms? a security analysis,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.842202Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e5396764743185fa0b73462db7e815c8ab35f80745b9235b7d4797929aef1694","observation_id":"d3d5875b-538e-4ed5-9955-c2dd2783a3b0","resolution":{"observed_at":"2026-08-07T11:18:52.842202Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.947283Z","title":"Causal knowledge analysis for detecting and modeling multi-step attacks,","venue":null,"work_id":"916580e1-7a5d-495e-984d-0fd95d50c580","year":2016},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.943526Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:9d1360e006b4bcedf0789da1e0ddd89fd244da4a41c4463e4829997f40c74dda","observation_id":"26c41731-6142-4277-a271-023708ecbe4b","resolution":{"observed_at":"2026-08-07T11:19:01.055292Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.737877Z","title":"A survey on the usability and practical applications of graphical security models,","venue":null,"work_id":"2f3678e6-5025-4fad-ad15-0b1d5caaa10b","year":2017},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.076098Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ee1e772fb03c03e8771c97b08cd7ade8a642dc51141a3187b0a3d0ecfd974885","observation_id":"b72fb89b-26e4-45a5-8c75-d37c8c5f91c2","resolution":{"observed_at":"2026-08-07T11:19:00.836113Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.508798Z","title":"Ou and A","venue":null,"work_id":"627d03de-e0ed-4a92-b1b8-d4783cb19d8a","year":2005},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.200626Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:fc47a8ec734253d8726aafad9d57fc54cbabbad267fda9e07119b611abc9d3a0","observation_id":"107e4ee6-1d28-406b-8ceb-2957d8356f20","resolution":{"observed_at":"2026-08-07T11:19:00.596910Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.261161Z","title":"Automated vul- nerability testing via executable attack graphs,","venue":null,"work_id":"b58b06d4-aede-468e-a2e9-d37d329ee718","year":2020},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.336873Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:f40095e527f63c61af2f96f65ed3f42d73d20d78141e4fbba9398735ef6d3f00","observation_id":"0340ff0e-8e21-4ea0-9853-0eaca49fa59c","resolution":{"observed_at":"2026-08-07T11:19:00.389908Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.018745Z","title":"Cvss-based multi-factor dynamic risk assessment model for network system,","venue":null,"work_id":"115b600e-deec-44e7-816c-0eaffcda217b","year":2020},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.439201Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:8465ac000d6a150cd06daa728d50d4605bc1ed25c93ff809a335013be1645bb7","observation_id":"6f5ef271-20c2-48a4-a4a1-bb8344c9138e","resolution":{"observed_at":"2026-08-07T11:19:00.118295Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.785806Z","title":"Overview on attack graph generation and visualization tech- nology,","venue":null,"work_id":"2958d992-0fd4-4043-96d0-bdd7136f8b5c","year":2013},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.565165Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:f99631bc89979ead51366f7c64f046a9c3af7b53034a2153b184349f53967b23","observation_id":"8e023437-6ee7-4f2b-a3a3-9aa68bcc67ef","resolution":{"observed_at":"2026-08-07T11:18:59.919064Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.579207Z","title":"A systematic study for understanding the security risks in 5g core network,","venue":null,"work_id":"b0cf8590-42e6-4d25-afbd-72da95fd656d","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.677352Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:cbfdfcfe2bd40f975a11ea66f337b1c788038071c3454ba30b479435800aa317","observation_id":"3ff6e752-ae18-4c06-869b-921f484d4299","resolution":{"observed_at":"2026-08-07T11:18:59.658367Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.286286Z","title":"Enhanc- ing cloud security: harnessing bayesian game theory for a dynamic defense mechanism,","venue":null,"work_id":"9c69631a-19d8-4fbf-a709-4bf45c2460c6","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.815590Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:84fd476b60d996120b77244276b6d6d8f340ce9eba4647f3c36e62530548281b","observation_id":"135c28a2-c368-4f18-94c5-4658954f7861","resolution":{"observed_at":"2026-08-07T11:18:59.418218Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.963459Z","title":"Atag github","venue":null,"work_id":"4902238b-ff8b-4a04-a533-eb5783d398ab","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.949879Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e7385a3ec4b51f543ac3b39a8c208e0799f7c5e036402c91eedf6d23bdeec32e","observation_id":"c29b7d07-9891-428b-9c74-e6ad86fd1174","resolution":{"observed_at":"2026-08-07T11:18:59.116565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.697068Z","title":"2025 Top 10 Risk & Mitigations for LLMs and Gen AI Apps,","venue":null,"work_id":"47bc776e-fe01-430c-b3d3-b4a11adb9ab0","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.086895Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ae4cfc0e5750f3dbcfd580e12da4d32271aec5857971094cbe73cbabee0f6a65","observation_id":"6a595c34-9ec0-4150-8066-00df3113ebb0","resolution":{"observed_at":"2026-08-07T11:18:58.832636Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.411935Z","title":"Mitreatlas,","venue":null,"work_id":"1972cdf4-e48c-4517-b5b1-3343ad752da1","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.185800Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:5d57cccda1c9721eb11c9c6ba530f3a8fb806dcb93ad0e5fb8d214195d1e6e2d","observation_id":"7fe77ffd-87e1-48b1-8153-7dda9c42c55c","resolution":{"observed_at":"2026-08-07T11:18:58.542050Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:54.317343Z","title":"Phantom: General trigger attacks on retrieval augmented language generation,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.317343Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:dfe1cd983f6e283ea0b539840a88fb316e3c74e412612b0d8710e73d026c7436","observation_id":"cb7c81c9-2456-42f3-812a-6013554acc27","resolution":{"observed_at":"2026-08-07T11:18:54.317343Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.185163Z","title":"Common vulnerability scoring system","venue":null,"work_id":"afe1145a-d12f-40f5-94ab-e3bc1f99245e","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.424936Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:4096bf0996c7e351a5257847e9d75d4a91f6413dc6fe39f52e4e582166cd8946","observation_id":"1b1aa1d1-a073-4bb0-b593-ebfd6dd7ba3e","resolution":{"observed_at":"2026-08-07T11:18:58.280792Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.02151","last_updated":"2025-04-17T18:55:45Z","snapshot_observed_at":"2026-07-06T17:54:43.685212Z","submitted_at":"2024-04-02T17:58:27Z","title":"Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.02151","snapshot_observed_at":"2026-08-07T11:18:54.543727Z","title":"Jailbreaking lead- ing safety-aligned llms with simple adaptive attacks,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.543727Z"},"links":{"cited_paper":"/paper/2404.02151","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:35a7e256b39551e76c1577f43b6630bf037db5b4fd8bd1bd69e1079320cff072","observation_id":"080c9ed6-9cea-443b-bd00-606e4f4b2f51","resolution":{"observed_at":"2026-08-07T11:18:54.543727Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.911689Z","title":"AI Risk Management Framework — nist.gov,","venue":null,"work_id":"48044aee-1a2a-40bb-a018-f9b638346d00","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.705115Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:0a6e387342b4ba90c78734e5b289843149cdfc794c38b8cf9d1f173a194dace7","observation_id":"75c3a190-74af-4973-acfd-1220aa554ed0","resolution":{"observed_at":"2026-08-07T11:18:58.034126Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.664544Z","title":"Agentic AI Threat Modeling Framework: MAESTRO — CSA — cloudsecurityalliance.org,","venue":null,"work_id":"e80eca4e-3110-4fe9-9f51-53e9181513c3","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.857644Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:f9238d1f1b1629e938e0b8fc370315259e2c3d091bb104e1fd17b4a4c2353dfe","observation_id":"26232291-d5ce-4c88-add4-95eb535d2d64","resolution":{"observed_at":"2026-08-07T11:18:57.780054Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.406188Z","title":"OWASP Foundation, “Announcing the OWASP LLM and Gen AI security project initiative for securing agentic applications,","venue":null,"work_id":"22b2f219-dc1a-45e2-b799-826ce0776aa3","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.966005Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:1ec663089b0bb8abb326da22fd57dff1850c43c41b03ff8eb7df178c8a9a29d1","observation_id":"f4d9ccbd-ee4c-4137-b36f-c2ecaddcf7d7","resolution":{"observed_at":"2026-08-07T11:18:57.508429Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.124299Z","title":"OWASP Foundation, “Multi-Agentic system Threat Modeling","venue":null,"work_id":"4cb91113-74bd-4f9c-8ccd-c15e5bdbb6b8","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.076607Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:4c3c41af360e96433d9a10b8bfecb983ef1c8a51267e7c9dc1f1782047f34441","observation_id":"695d0d10-e310-4e95-8fda-47e227773647","resolution":{"observed_at":"2026-08-07T11:18:57.283991Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:56.889850Z","title":"Securing agentic ai: A comprehensive threat model and mitigation framework for generative ai agents,","venue":null,"work_id":"74c78a80-af21-4221-9e54-1dcb4a515b91","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.201783Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e483d3624050bb3191fda17b4098e55c5a757bd408865d282b0dc474d0b3191e","observation_id":"21677672-78a3-4468-b639-9b31e9097eb0","resolution":{"observed_at":"2026-08-07T11:18:56.992001Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:55.402038Z","title":"Doomarena: A framework for testing ai agents against evolving security threats,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.402038Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:601df0514ad981e6693d5d1f95e08e5ec02ae1cf5bff3f95df2a23dccae1d03a","observation_id":"184e8ec7-0c5a-4199-9d12-ad870582ed6c","resolution":{"observed_at":"2026-08-07T11:18:55.402038Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2208.05750","last_updated":"2022-08-11T11:00:40Z","snapshot_observed_at":"2026-08-05T00:52:20.337545Z","submitted_at":"2022-08-11T11:00:40Z","title":"A Survey of MulVAL Extensions and Their Attack Scenarios Coverage","version":1},"cited_work":{"arxiv_id":"2208.05750","doi":null,"metadata_source":"pith","pith_arxiv_id":"2208.05750","snapshot_observed_at":"2026-08-07T11:18:55.740028Z","title":"A Survey of MulVAL Extensions and Their Attack Scenarios Coverage","venue":"cs.CR","work_id":"de6fd7bd-e959-4566-aebc-e19ad2085c28","year":2022},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.535553Z"},"links":{"cited_paper":"/paper/2208.05750","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:a92f2078781e14396929afa82b72a44132ee915180a06463888ca3306396fd15","observation_id":"a5dbbb8a-78af-4542-801c-9905d3d87043","resolution":{"observed_at":"2026-08-07T11:18:55.845485Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.19956","last_updated":"2025-05-02T18:42:42Z","snapshot_observed_at":"2026-08-07T15:58:32.319366Z","submitted_at":"2025-04-28T16:29:24Z","title":"Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.19956","snapshot_observed_at":"2026-08-07T11:18:55.303303Z","title":"Available: https://arxiv.org/abs/2504.19956","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":2025,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.303303Z"},"links":{"cited_paper":"/paper/2504.19956","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:eecf3dc37e0a1b7049afa1f08ca164d8fe850ccbeb9e217dfacb0e41957f625a","observation_id":"bca5b16d-1e19-4cbd-8de6-ca1af8db510a","resolution":{"observed_at":"2026-08-07T11:18:55.303303Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-07T11:11:39.176556Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs"},"reference_resolution":{"displayed":55,"state_counts":{"malformed_identifier":0,"metadata_mismatch":1,"parse_uncertain":0,"unresolved":15,"verified_exact":2,"verified_fuzzy":37},"total_outbound_references":55},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 1 inbound Pith citation observation for arXiv:2506.02859."}