{"as_of":"2026-08-09T12:27:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:a5c433613160ab4b8ff0cd962235227e45c372992b0d29b5af8a1af4e0898a97","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":9,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":9,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":9,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":9,"source":"paper_references, paper_reference_links","source_observed_at":"2026-06-30T16:22:23.857438Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":0,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2603.28166","last_updated":"2026-04-20T07:37:21Z","snapshot_observed_at":"2026-08-02T07:10:51.130581Z","submitted_at":"2026-03-30T08:35:00Z","title":"Evaluating Privilege Usage of Agents with Real-World Tools","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-05-14T22:16:56.848520Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2603.28166"},"observation_digest":"sha256:8cbc3162ef7649fa1c45f330eadf969e2825603718c6056ec41d38f140791f97","observation_id":"1aab66c6-34ae-4d9e-bdaf-350397be20b1","resolution":{"observed_at":"2026-05-14T22:18:04.361136Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.11053","last_updated":"2026-05-22T06:52:48Z","snapshot_observed_at":"2026-07-06T23:22:57.012338Z","submitted_at":"2026-05-11T14:55:48Z","title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-13T00:56:02.786795Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.11053"},"observation_digest":"sha256:bf693d10efd6f645b571fcefb320a19c41b976efdc29147dcef74c580bc422a6","observation_id":"a5c5f379-665a-44a6-85eb-35b38f957443","resolution":{"observed_at":"2026-05-13T00:57:00.300069Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.11053","last_updated":"2026-05-22T06:52:48Z","snapshot_observed_at":"2026-07-06T23:22:57.012338Z","submitted_at":"2026-05-11T14:55:48Z","title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-14T21:17:10.373607Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.11053"},"observation_digest":"sha256:47e901b4f204fb8642122d6edf4ab73077ae854316e4e292b6218fe88964db46","observation_id":"3e82437a-40d0-4159-895d-391f36553946","resolution":{"observed_at":"2026-05-14T21:17:58.611548Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.11053","last_updated":"2026-05-22T06:52:48Z","snapshot_observed_at":"2026-07-06T23:22:57.012338Z","submitted_at":"2026-05-11T14:55:48Z","title":"Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols","version":3},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-25T05:57:22.726910Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.11053"},"observation_digest":"sha256:18684aef42b8144e1223af9b7bf9af8642f68cfaecab13b5b3183631f4e6bbfe","observation_id":"fb9ca04a-f186-4b68-a354-bc9994f08cd4","resolution":{"observed_at":"2026-05-25T06:00:23.557984Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.14859","last_updated":"2026-05-15T03:53:20Z","snapshot_observed_at":"2026-07-06T23:26:13.644646Z","submitted_at":"2026-05-14T14:05:58Z","title":"Do Coding Agents Understand Least-Privilege Authorization?","version":2},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-05-19T16:34:14.379419Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.14859"},"observation_digest":"sha256:7390a98b73539952635bf4135fb6ad74c70159957bf641578c0d436bb61d33cc","observation_id":"954a84a3-b2a7-46d4-afa0-291657d1ddfb","resolution":{"observed_at":"2026-05-19T16:37:39.984544Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:43ac11cf28f1e66bafbed3a5dc42eaee7dd6541a37a2657a90ee9dff29b2a5dc","observation_id":"85b0d4e7-a8a2-42ee-86d0-03b4d12aa8f5","resolution":{"observed_at":"2026-05-21T01:43:56.870990Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.17380","last_updated":"2026-05-17T10:49:07Z","snapshot_observed_at":"2026-08-02T11:02:18.535581Z","submitted_at":"2026-05-17T10:49:07Z","title":"ADR: An Agentic Detection System for Enterprise Agentic AI Security","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-05-20T13:17:59.293695Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.17380"},"observation_digest":"sha256:5693643b70dad6ba201fcef19f99385cd2c542d3d399c4d52c9153fc7408262a","observation_id":"64a5976c-460d-4834-a76c-5b390b9f4032","resolution":{"observed_at":"2026-05-20T13:18:18.173988Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.24069","last_updated":"2026-05-22T08:34:48Z","snapshot_observed_at":"2026-08-02T10:17:43.608511Z","submitted_at":"2026-05-22T08:34:48Z","title":"When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-06-30T16:22:23.857438Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.24069"},"observation_digest":"sha256:559724cd2ae861eb8d0465fccb858b35f72bdb79d3882c7fa58bbcc4d5742981","observation_id":"bede31b4-ccc2-4cdc-95c2-e57b79c744f8","resolution":{"observed_at":"2026-06-30T16:24:55.111630Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2606.10749","last_updated":"2026-06-09T12:01:07Z","snapshot_observed_at":"2026-07-31T21:35:18.696472Z","submitted_at":"2026-06-09T12:01:07Z","title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-06-27T12:55:22.831264Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2606.10749"},"observation_digest":"sha256:e7d1be94150ac1ab464d77d6e98ac3c040dd5e79d600c849f8f38beccd448078","observation_id":"ecc9f3f8-dc64-4210-8d39-eddc804b5446","resolution":{"observed_at":"2026-06-27T13:20:56.905038Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2506.15253/citation-record","integrity":"/paper/2506.15253/integrity","json":"/paper/2506.15253/citation-record.json","paper":"/paper/2506.15253"},"outbound":[],"paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 9 inbound Pith citation observations for arXiv:2506.15253."}