Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-19T06:14:52.902631Z
Paper Citation Record · LEDGER
As of 5 August 2026, this Paper Citation Record lists 36 of 36 outbound references and 17 inbound Pith citation observations for arXiv:2507.06850.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-19T06:14:52.902631Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-02T19:04:10.482234Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-06-30T16:24:55.077325Z
36 of 36 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 923858e0-1e5a-4f01-a2ef-ecd8d1bc8060 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Conversational Health Agents: A Personalized LLM-Powered Agent Framework
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b69c451a-d464-4ef5-889f-629e4baab2b9 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise agno-agi/agno
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4c5758ad-9a8e-4b49-af0b-57196462f7ce · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise CyberRAG: An agentic RAG cyber attack classification and reporting tool
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cfa44b46-f052-416d-a196-2ef12f183c6a · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Langchain, October 2022
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3a057573-a53f-459a-8270-cb80830569e6 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1b3c24b1-295f-48f7-8fcf-09dbf9377ff7 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Trojanrag: Retrieval-augmented generation can be back- door driver in large language models
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1e406a86-9516-42e8-9fcc-e0a2b6baf6de · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise LLM agents can autonomously hack websites.arXiv
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d60d4242-e178-4b37-a7a0-bb20b95ad9f4 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injec- tion
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5235f135-d488-4464-a7b4-9f0313abca6a · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Badnets: Identifying vulnerabilities in the machine learning model supply chain
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d746e0c5-8df9-489f-8e68-8b2139b7ceb2 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Unresolved cited work
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b073a367-ddaa-453a-828c-6636e15452a9 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Introducing warp agent mode
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c8f23d51-a5ec-4afa-8962-8f69e757c85a · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Weight poisoning attacks on pre-trained models
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bd5977d4-e499-4dfc-8736-12bf0039f28a · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise laszukdawid/terminal-agent
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a920d7a5-84c7-4717-baf4-0e12421229b2 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Prompt infection: Llm- to-llm prompt injection within multi-agent systems
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation eff50a72-80ae-40e2-9b34-9af067c30992 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Retrieval-augmented generation for knowledge- intensive nlp tasks.Advances in neural information processing systems
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5883b98e-4660-4b42-98d5-c2f4d9ec9bd3 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Commercial llm agents are already vulnerable to simple yet dangerous attacks
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3ee17d8f-86b6-4b76-9780-12fa645d9a8e · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Backdoor attacks on pre- trained models by layerwise weight poisoning
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 62d2b852-9dc3-4b5b-aa16-a4f6d913f9d9 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Formalizing and benchmarking prompt injection attacks and defenses
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1c0fa3fb-989e-4f66-9af9-1266cd560dde · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise A Language Agent for Autonomous Driving
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 85350ee9-e933-4781-ad20-033c951b12f1 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise vxcontrol/pentagi
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 91f07c7b-c785-4b3c-a308-81cb9009c437 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Lang- Graph
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 367c7b63-178b-4ca4-b0ec-3c0bd2e16df6 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Meterpreter — metasploit documentation
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 79f8eb5d-155a-4132-a567-6a2c661a3fc2 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Trism for agentic ai: A review of trust, risk, and security management in llm-based agen- tic multi-agent systems
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c084a304-a7dd-456e-ad01-a2ece0bed531 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Machine against the rag: Jamming retrieval-augmented generation with blocker documents
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 501e7aa3-da0a-4907-b262-434e2a85e36b · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise On the feasibility of using llms to autonomously execute multi-host network attacks
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 73dfc683-bcad-49ef-a50f-e17c4d54db67 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentic retrieval-augmented generation: A survey on agentic rag
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 33d4deab-44ad-4ee4-8a09-78ea3f3cc409 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Badagent: Inserting and activating back- door attacks in llm agents
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 41618c24-c1a5-4ddd-8a14-7ca08e55f213 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentvigil: Generic black-box red- teaming for indirect prompt injection against llm agents
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7993b626-8a9f-4a4e-bad0-1bb63b5b9b8a · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Wiley, 2nd edition
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bbd187df-f3e1-425b-af9d-3bc30eecba60 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise BloombergGPT: A Large Language Model for Finance
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 83269add-8d46-4587-90d8-7f40c1ba9886 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise The rise and potential of large language model based agents: a survey.Science China Information Sciences, 68
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5151aed2-c0ad-4b75-b584-ce6a6dbb7aa6 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5de5ebce-e28f-42dc-a89f-a8e8a2477c15 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Backdooring instruction-tuned large lan- guage models with virtual prompt injection
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5fe4580d-9f6d-4471-b853-7257e6663011 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Watch out for your agents! investi- gating backdoor threats to llm-based agents
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation af1b0de6-ca41-4fc8-808c-dee89a5f9265 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise React: Synergizing reasoning and acting in language models
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation aec1926c-963a-46b3-a048-9fe6fc8c8844 · outbound
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Poisonedrag: Knowledge corruption attacks to retrieval-augmented generation of large language mod- els
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 06f52ec1-d2a8-4114-9e2c-e057b8fb0289 · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4c7adf36-5681-4b0d-bef7-0b7067dbadc1 · inbound
In-Context Environments Induce Evaluation-Awareness in Language Models The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 2025
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dfefdddc-dbfe-4d1c-a9f0-49f9de60456d · inbound
From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d0d3c263-29be-4e78-919e-c9619a8178ea · inbound
AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c47d3a7f-9340-40b8-b508-ed6195b832d4 · inbound
Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 50097204-7fc3-4e26-b622-a4b80f30e3ee · inbound
Trace: Unmasking AI Attack Agents Through Terminal Behavior Fingerprinting The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d0bce763-1f73-4d17-8b5d-34304f6d1e43 · inbound
When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 197e254e-43ce-45c7-a3e3-c171bf6ec994 · inbound
From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 76
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a8f796f9-ea66-4e15-9303-92903aa201d3 · inbound
Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 577eeaa2-27ca-4173-8c41-697e0d8f93c7 · inbound
Position: A Three-Layer Probabilistic Assume-Guarantee Architecture Is Structurally Required for Safe LLM Agent Deployment The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 96398ede-da4c-4607-a5bf-c06d6d184ef8 · inbound
The Misattribution Gap: When Memory Poisoning Looks Like Model Failure in Agentic AI Systems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 743652cf-9172-45c2-9560-f8877e37346f · inbound
Security, Privacy, and Ethical Risks in OpenClaw The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5996c85c-c62c-411a-99a0-7b1406d78edf · inbound
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 698e63f9-7791-4a65-bcd5-9888e956a7b1 · inbound
Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation baae2f08-e6e1-45d4-a25d-522419ef8c61 · inbound
LLM-Powered Agentic AI for 5G/6G Networks: A Tutorial and Survey on Architectures, Protocols, and Standardization The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 177
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 587919d3-435b-4f41-8ebd-bbfa1a6775ff · inbound
Agent Security Needs Redefinition through a Holistic Framework The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 273
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cb027c41-408f-447f-8fd5-54a79d7df231 · inbound
Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.