Pith. sign in

Paper Citation Record · LEDGER

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

As of 5 August 2026, this Paper Citation Record lists 36 of 36 outbound references and 17 inbound Pith citation observations for arXiv:2507.06850.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.06850 v6

Coverage vector

measured 36 of 36 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-19T06:14:52.902631Z

measured 53 of 53 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00

measured 17 of 17 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-02T19:04:10.482234Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-06-30T16:24:55.077325Z

Reference resolution

36 of 36 outbound references displayed

  • verified exact2
  • verified fuzzy32
  • unresolved1
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 923858e0-1e5a-4f01-a2ef-ecd8d1bc8060 · outbound

This paper cites Conversational Health Agents: A Personalized LLM-Powered Agent Framework.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Conversational Health Agents: A Personalized LLM-Powered Agent Framework

Reference 1

Resolution
metadata mismatch
arxiv_id, observed 2026-05-19T06:17:07.709778Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:85f61510cb0f53cf183834c72224378300b96126c6f78a93667c66300ac36da9

Observation b69c451a-d464-4ef5-889f-629e4baab2b9 · outbound

This paper cites agno-agi/agno.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise agno-agi/agno

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.232429Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:ec61b7e68c0dee6469969e49eb0987f6c3d052fe9254c97c97b00c4c25592832

Observation 4c5758ad-9a8e-4b49-af0b-57196462f7ce · outbound

This paper cites CyberRAG: An agentic RAG cyber attack classification and reporting tool.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise CyberRAG: An agentic RAG cyber attack classification and reporting tool

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.213726Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:312f48ca0e02d7a6fcfefed8aeb4b041a2743d7024f4d4ff830f95f20cb43ae6

Observation cfa44b46-f052-416d-a196-2ef12f183c6a · outbound

This paper cites Langchain, October 2022.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Langchain, October 2022

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.217942Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:e6d6470939c51f724e1f5d4cfda596074fff4f97cae993abd4acd119bb6a3172

Observation 3a057573-a53f-459a-8270-cb80830569e6 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.209306Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:e42016c5b1b1f20648f785f76d8560e593ea8fd4b617b16a81e211d332ca3307

Observation 1b3c24b1-295f-48f7-8fcf-09dbf9377ff7 · outbound

This paper cites Trojanrag: Retrieval-augmented generation can be back- door driver in large language models.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Trojanrag: Retrieval-augmented generation can be back- door driver in large language models

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.222142Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:0227342dd5d73424df931d982a80917ddb7c43849257c3795cd0a6ff71d77a47

Observation 1e406a86-9516-42e8-9fcc-e0a2b6baf6de · outbound

This paper cites LLM agents can autonomously hack websites.arXiv.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise LLM agents can autonomously hack websites.arXiv

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.226524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:802317ae4ea53cdc27b672f9a0b4a3b79360982960d22eec1813a99a5a8459ea

Observation d60d4242-e178-4b37-a7a0-bb20b95ad9f4 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injec- tion.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injec- tion

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.189274Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:59f681aa97c059f2d53bddc2c915c8f248b4ac0e65de5b42313580eb2ebdde09

Observation 5235f135-d488-4464-a7b4-9f0313abca6a · outbound

This paper cites Badnets: Identifying vulnerabilities in the machine learning model supply chain.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Badnets: Identifying vulnerabilities in the machine learning model supply chain

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.251237Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:c1a470e475dab137942abb2b838b17081f4edaeeb75cec1d7105b47a05ada675

Observation d746e0c5-8df9-489f-8e68-8b2139b7ceb2 · outbound

This paper cites an unresolved cited work.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Unresolved cited work

Reference 10

Resolution
unresolved
raw_fallback, observed 2026-05-19T06:17:08.204353Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:b2550ac12814c8fa8609f7806972bb50de4030be9a7b309ca716337b8d81f4b7

Observation b073a367-ddaa-453a-828c-6636e15452a9 · outbound

This paper cites Introducing warp agent mode.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Introducing warp agent mode

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.199097Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:f37f79dbde9e2cd5228d39c2be8222d3594728f784b78aa321622c1480585445

Observation c8f23d51-a5ec-4afa-8962-8f69e757c85a · outbound

This paper cites Weight poisoning attacks on pre-trained models.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Weight poisoning attacks on pre-trained models

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.237172Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:7d54f7fc7171717a8797fd1c59ee6c34a1c17b54ed3a05ed194d3b116b69aac6

Observation bd5977d4-e499-4dfc-8736-12bf0039f28a · outbound

This paper cites laszukdawid/terminal-agent.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise laszukdawid/terminal-agent

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.093098Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:98f6d4ad8098062564159c65233c8a9c2105cd256d9d3797c8472f8deb5dd2f3

Observation a920d7a5-84c7-4717-baf4-0e12421229b2 · outbound

This paper cites Prompt infection: Llm- to-llm prompt injection within multi-agent systems.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Prompt infection: Llm- to-llm prompt injection within multi-agent systems

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.096678Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:cbeb1ffa44f7fd899ae253aa175c1b33175082f9ed7426684eddf2fa661360db

Observation eff50a72-80ae-40e2-9b34-9af067c30992 · outbound

This paper cites Retrieval-augmented generation for knowledge- intensive nlp tasks.Advances in neural information processing systems.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Retrieval-augmented generation for knowledge- intensive nlp tasks.Advances in neural information processing systems

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.103568Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:0da410ec4e9284eac00c2150269f19ccf7233b210424aa7edba989fcf5d89a77

Observation 5883b98e-4660-4b42-98d5-c2f4d9ec9bd3 · outbound

This paper cites Commercial llm agents are already vulnerable to simple yet dangerous attacks.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Commercial llm agents are already vulnerable to simple yet dangerous attacks

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.183619Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:7afb2e04e3d4d7c12d3aef2af18a2daf1fb57a8933627f67d1bd6d2beeb9157d

Observation 3ee17d8f-86b6-4b76-9780-12fa645d9a8e · outbound

This paper cites Backdoor attacks on pre- trained models by layerwise weight poisoning.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Backdoor attacks on pre- trained models by layerwise weight poisoning

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.193661Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:3848e5b2d64e583b9f8e1d98fdda738017e0b29757581171752af3604c209751

Observation 62d2b852-9dc3-4b5b-aa16-a4f6d913f9d9 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Formalizing and benchmarking prompt injection attacks and defenses

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.176552Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:68ea1a8c2509dd2adaa76e553c101e02b7c710862f28c1ff14b5ef2bc19cfa3a

Observation 1c0fa3fb-989e-4f66-9af9-1266cd560dde · outbound

This paper cites A Language Agent for Autonomous Driving.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise A Language Agent for Autonomous Driving

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-19T06:17:07.696033Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:d0da2f528b043bc6f6c51669c3ae0fc892ed5cedf2367eebbd7fd17109bf52d1

Observation 85350ee9-e933-4781-ad20-033c951b12f1 · outbound

This paper cites vxcontrol/pentagi.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise vxcontrol/pentagi

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.089624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:2bd75c6b20c3d14d23d2d0c5ff5cf2b6ce43f41fa4b858658ede354f5b1e5c81

Observation 91f07c7b-c785-4b3c-a308-81cb9009c437 · outbound

This paper cites Lang- Graph.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Lang- Graph

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.150829Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:43d3520cda42f049c1c09777dff64f27f800b86f0f95eb138310a11eadc1dc24

Observation 367c7b63-178b-4ca4-b0ec-3c0bd2e16df6 · outbound

This paper cites Meterpreter — metasploit documentation.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Meterpreter — metasploit documentation

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.256993Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:b71b630c26720d0cbc740dea06c20025bb2ce6c232d0bace38029253145869ff

Observation 79f8eb5d-155a-4132-a567-6a2c661a3fc2 · outbound

This paper cites Trism for agentic ai: A review of trust, risk, and security management in llm-based agen- tic multi-agent systems.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Trism for agentic ai: A review of trust, risk, and security management in llm-based agen- tic multi-agent systems

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.155882Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:573f5669d8bcfecc71ed02c1debdee7aa8533347eb21069ccf5ba27b59dc5135

Observation c084a304-a7dd-456e-ad01-a2ece0bed531 · outbound

This paper cites Machine against the rag: Jamming retrieval-augmented generation with blocker documents.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Machine against the rag: Jamming retrieval-augmented generation with blocker documents

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.160047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:e0c33550a703be6ad0933aa433f94a685ce7edfeae6090be5aabb65b4039d918

Observation 501e7aa3-da0a-4907-b262-434e2a85e36b · outbound

This paper cites On the feasibility of using llms to autonomously execute multi-host network attacks.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise On the feasibility of using llms to autonomously execute multi-host network attacks

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.172227Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:a59bbf0d80153e8973d52f93c16598571771f18dfa945a7baa1d8e936c64e4ff

Observation 73dfc683-bcad-49ef-a50f-e17c4d54db67 · outbound

This paper cites Agentic retrieval-augmented generation: A survey on agentic rag.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentic retrieval-augmented generation: A survey on agentic rag

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.246896Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:1ca664c375182b943d977205527908ff2f23d47641e5da62e17e5573887ad593

Observation 33d4deab-44ad-4ee4-8a09-78ea3f3cc409 · outbound

This paper cites Badagent: Inserting and activating back- door attacks in llm agents.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Badagent: Inserting and activating back- door attacks in llm agents

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.241225Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:f215d8d8bb297a5e298f78a336a10292650791731f16f2dfdc8e7cbe6cec854b

Observation 41618c24-c1a5-4ddd-8a14-7ca08e55f213 · outbound

This paper cites Agentvigil: Generic black-box red- teaming for indirect prompt injection against llm agents.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Agentvigil: Generic black-box red- teaming for indirect prompt injection against llm agents

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.107694Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:1707c255bc56b151a9f83b2cf82436312f14f9d391a3d062914522afba84c9ce

Observation 7993b626-8a9f-4a4e-bad0-1bb63b5b9b8a · outbound

This paper cites Wiley, 2nd edition.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Wiley, 2nd edition

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.136947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:8092dd4655573105eb657d48dd580239b19ef036d648eea65ca9ca77f09bfdac

Observation bbd187df-f3e1-425b-af9d-3bc30eecba60 · outbound

This paper cites BloombergGPT: A Large Language Model for Finance.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise BloombergGPT: A Large Language Model for Finance

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-05-19T06:17:07.703169Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:7a7eb688a0ca110fd96cd68a3b1d5d8c301656279c2aa18f9365db8416b69427

Observation 83269add-8d46-4587-90d8-7f40c1ba9886 · outbound

This paper cites The rise and potential of large language model based agents: a survey.Science China Information Sciences, 68.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise The rise and potential of large language model based agents: a survey.Science China Information Sciences, 68

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.123970Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:5b9299bd931577db04bfcf78bd68c33ac139a4490741c1ca9eb8c288ad020869

Observation 5151aed2-c0ad-4b75-b584-ce6a6dbb7aa6 · outbound

This paper cites Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.167702Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:d4b57bf2efd5941c7e7ecbd22793f98be4b6a4067a3d307781de8076db746a1b

Observation 5de5ebce-e28f-42dc-a89f-a8e8a2477c15 · outbound

This paper cites Backdooring instruction-tuned large lan- guage models with virtual prompt injection.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Backdooring instruction-tuned large lan- guage models with virtual prompt injection

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.143089Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:0460206f6f4c2aa68d872f32ae9adfd0922ad73e6ec9f5771d459652a6b42cf1

Observation 5fe4580d-9f6d-4471-b853-7257e6663011 · outbound

This paper cites Watch out for your agents! investi- gating backdoor threats to llm-based agents.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Watch out for your agents! investi- gating backdoor threats to llm-based agents

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.263760Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:ffee600342e2a07ea0ce532aae8f0c8644bc687d98c34e1f03e6c1f608b453ff

Observation af1b0de6-ca41-4fc8-808c-dee89a5f9265 · outbound

This paper cites React: Synergizing reasoning and acting in language models.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise React: Synergizing reasoning and acting in language models

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.118343Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:8edc2939603d3f8109582626f081b1bdf4e2ff598ddadb7b38099b108ad27e4a

Observation aec1926c-963a-46b3-a048-9fe6fc8c8844 · outbound

This paper cites Poisonedrag: Knowledge corruption attacks to retrieval-augmented generation of large language mod- els.

The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise Poisonedrag: Knowledge corruption attacks to retrieval-augmented generation of large language mod- els

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T06:17:08.113526Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T06:14:52.902631Z digest=sha256:87f38d9abab2d5ea0caf5e1817d2e2431d15708b9804c4a891ee24b743f6a092

Pith citing papers

Observation 06f52ec1-d2a8-4114-9e2c-e057b8fb0289 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 40

Resolution
verified exact
local_arxiv, observed 2026-05-18T03:42:22.495392Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:5e52f16feeb5db515d57fbbce081577ec192f47a4cb50d387d216d764d5ef004

Observation 4c7adf36-5681-4b0d-bef7-0b7067dbadc1 · inbound

In-Context Environments Induce Evaluation-Awareness in Language Models cites this paper.

In-Context Environments Induce Evaluation-Awareness in Language Models The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-02T19:04:10.482234Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T19:04:10.482234Z digest=sha256:68e4a506b7a1f7815401ea6e659bac3b8a4d6a041dd025cc8b4dedf540403e04

Observation dfefdddc-dbfe-4d1c-a9f0-49f9de60456d · inbound

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration cites this paper.

From Spark to Fire: Modeling and Mitigating Error Cascades in LLM-Based Multi-Agent Collaboration The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 33

Resolution
verified exact
local_arxiv, observed 2026-05-15T16:40:10.570454Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T16:36:43.330447Z digest=sha256:eee5c8350ca6dfa994987a1a97f21284822c986e2f23444f505ade7d7f10f888

Observation d0d3c263-29be-4e78-919e-c9619a8178ea · inbound

AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems cites this paper.

AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T18:10:38.489000Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T18:10:38.489000Z digest=sha256:91e4d52e0e94c7178338887ca28c8d603879aad265c3db662341d1ef9d6b88df

Observation c47d3a7f-9340-40b8-b508-ed6195b832d4 · inbound

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines cites this paper.

Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-12T01:43:44.211476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T17:40:23.128451Z digest=sha256:f074baec7d656b96f6bcd9eba4151700aab8f00d1b7dcfc7c67b59e75ee5f437

Observation 50097204-7fc3-4e26-b622-a4b80f30e3ee · inbound

Trace: Unmasking AI Attack Agents Through Terminal Behavior Fingerprinting cites this paper.

Trace: Unmasking AI Attack Agents Through Terminal Behavior Fingerprinting The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-12T01:43:44.211476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-09T15:18:43.426681Z digest=sha256:7768f183ac9a644a013b57bb962f117c26db0381ffc9bb8217edb2ebe8fb8c79

Observation d0bce763-1f73-4d17-8b5d-34304f6d1e43 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 49

Resolution
verified exact
local_arxiv, observed 2026-05-12T08:01:33.056687Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:813c425bbc857c0d3769ed49fa421180670d278f7288c9dc8e0788f51af212ed

Observation 197e254e-43ce-45c7-a3e3-c171bf6ec994 · inbound

From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI cites this paper.

From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 76

Resolution
verified exact
local_arxiv, observed 2026-05-20T18:08:50.492088Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-20T18:08:24.901025Z digest=sha256:60566dd7407c4677d2fcd719b8115e9886b73a81f5ffbee2706c3f978b523dd9

Observation a8f796f9-ea66-4e15-9303-92903aa201d3 · inbound

Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents cites this paper.

Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 17

Resolution
metadata mismatch
local_arxiv, observed 2026-05-20T10:53:13.416419Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=arxiv_source observed=2026-05-20T10:51:19.555985Z digest=sha256:a3d9170966ff0bb0f074675761f53ecbaf0db8df965f5bfe05ef10f086650ab1

Observation 577eeaa2-27ca-4173-8c41-697e0d8f93c7 · inbound

Position: A Three-Layer Probabilistic Assume-Guarantee Architecture Is Structurally Required for Safe LLM Agent Deployment cites this paper.

Position: A Three-Layer Probabilistic Assume-Guarantee Architecture Is Structurally Required for Safe LLM Agent Deployment The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 36

Resolution
verified exact
local_arxiv, observed 2026-05-20T10:23:12.018634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-20T10:21:11.725387Z digest=sha256:d6529be21da2fac5de213459905edd94530f86902cac1d3ccc98e10e8eb5e077

Observation 96398ede-da4c-4607-a5bf-c06d6d184ef8 · inbound

The Misattribution Gap: When Memory Poisoning Looks Like Model Failure in Agentic AI Systems cites this paper.

The Misattribution Gap: When Memory Poisoning Looks Like Model Failure in Agentic AI Systems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 19

Resolution
metadata mismatch
local_arxiv, observed 2026-05-25T00:45:09.327089Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-25T00:43:34.500801Z digest=sha256:da18960958654364e8672c257e45a729fa46ea3fb25ff57011747d7570feb4c4

Observation 743652cf-9172-45c2-9560-f8877e37346f · inbound

Security, Privacy, and Ethical Risks in OpenClaw cites this paper.

Security, Privacy, and Ethical Risks in OpenClaw The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 8

Resolution
verified exact
local_arxiv, observed 2026-05-25T04:26:37.756524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-25T04:25:49.102385Z digest=sha256:fb571b213093d972d85b00895534d7377bbdd2fc1827aab1764e93d7a46ba365

Observation 5996c85c-c62c-411a-99a0-7b1406d78edf · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-06-30T16:24:55.083131Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:6f00c648e047c536c5368e30238276fb5ca03a15b6e4be2500a891bddaf742ae

Observation 698e63f9-7791-4a65-bcd5-9888e956a7b1 · inbound

Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks cites this paper.

Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 3

Resolution
verified exact
local_arxiv, observed 2026-06-29T14:33:31.448440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-29T06:34:52.596684Z digest=sha256:dba03d23ac9d70721cfd1253eae97083a00c4ff7706114ca713bdec3e689a9ef

Observation baae2f08-e6e1-45d4-a25d-522419ef8c61 · inbound

LLM-Powered Agentic AI for 5G/6G Networks: A Tutorial and Survey on Architectures, Protocols, and Standardization cites this paper.

LLM-Powered Agentic AI for 5G/6G Networks: A Tutorial and Survey on Architectures, Protocols, and Standardization The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 177

Resolution
unresolved
no resolver link, observed 2026-08-01T21:29:54.443698Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T21:29:54.443698Z digest=sha256:59e754ea3ad5218b49d8c3d30343fdb310e05bd5e553b57b275b957a94fc9a9c

Observation 587919d3-435b-4f41-8ebd-bbfa1a6775ff · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 273

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.626585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.626585Z digest=sha256:0cf4c90ccef5a9a0b44503d670b04f1e214a764e86986cd675617bc7ca61c44f

Observation cb027c41-408f-447f-8fd5-54a79d7df231 · inbound

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems cites this paper.

Even More Deception: Objective Misalignment in Mixed-Motive LLM Multi-Agent Systems The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-01T00:51:17.248440Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T00:51:17.248440Z digest=sha256:fd4d236e6b9a8eaa05e6ce82bb120b182bddd7a3b1221aaabdb6eef52379cb08