Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 3 inbound Pith citation observations for arXiv:2507.13169.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-05-22T12:46:44.819224Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-05-22T12:51:33.393440Z
29 of 29 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation e22e7f76-32cd-4cb3-869f-3183830e0afa · outbound
Prompt Injection 2.0: Hybrid AI Threats Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 28fbf030-816c-41ff-903c-2df09f0a7f9c · outbound
Prompt Injection 2.0: Hybrid AI Threats C., & Heichman, R
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4ba24e3f-f487-4b02-a626-63b6ad009055 · outbound
Prompt Injection 2.0: Hybrid AI Threats Prompt Injection attack against LLM-integrated Applications
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · outbound
Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2c8e481a-6979-4c1e-91d7-eb514330e081 · outbound
Prompt Injection 2.0: Hybrid AI Threats From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 81b7056d-e92d-4262-a83a-cfadff70051b · outbound
Prompt Injection 2.0: Hybrid AI Threats AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 74108fff-12a9-4135-8e67-a6a18bca8085 · outbound
Prompt Injection 2.0: Hybrid AI Threats Design Patterns for Securing LLM Agents against Prompt Injections
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9ffcd4e8-6f3c-4856-9cce-4421416681fa · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 67a374ee-c085-4de3-abb1-fb82d9c1fefe · outbound
Prompt Injection 2.0: Hybrid AI Threats Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f4cdc41-655f-434b-9be2-a74bc3172ba9 · outbound
Prompt Injection 2.0: Hybrid AI Threats Defeating Prompt Injections by Design
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1c073cff-1405-48a5-91aa-b7a78fc582b7 · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 43d9d6d4-67cb-4608-89d9-d5c6532faf25 · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0c024737-d7c3-4a78-9b2f-f2c999750230 · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · outbound
Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 932b69ab-e882-49e0-a697-a9bbcf822bb9 · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation e379a488-61be-486e-b10a-30e052f70bbd · outbound
Prompt Injection 2.0: Hybrid AI Threats XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 97ca63c5-25a5-4980-94cb-1c29107c98e0 · outbound
Prompt Injection 2.0: Hybrid AI Threats The Hidden Dangers of Browsing AI Agents
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 48ce344e-7e62-45bd-8d86-18374023e328 · outbound
Prompt Injection 2.0: Hybrid AI Threats Learning to Poison Large Language Models for Downstream Manipulation
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fb31b710-e5d8-497a-9bb8-b335be88601d · outbound
Prompt Injection 2.0: Hybrid AI Threats Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8a60a853-a16d-4b30-beb5-e095804b0e30 · outbound
Prompt Injection 2.0: Hybrid AI Threats Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fbe5eca5-fc2b-4390-98d2-c32b7d9b82ac · outbound
Prompt Injection 2.0: Hybrid AI Threats Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2a247095-3659-4852-b88a-22fed94a42b8 · outbound
Prompt Injection 2.0: Hybrid AI Threats Manipulating Multimodal Agents via Cross-Modal Prompt Injection
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6514fbca-975f-4253-a587-05efbc389ff9 · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 80107157-42c9-4510-a17b-5ec0990ce669 · outbound
Prompt Injection 2.0: Hybrid AI Threats Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 711b04e6-a84a-4b06-8648-54f847ee47d8 · outbound
Prompt Injection 2.0: Hybrid AI Threats Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 901f6257-6605-4160-b812-d5c36cc18a4a · outbound
Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 53d2c546-ea9f-4636-bf87-72f6c0317db7 · outbound
Prompt Injection 2.0: Hybrid AI Threats LLM Agents can Autonomously Hack Websites
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4a6efbb7-8971-44ae-aabf-67ad24ecb2ae · outbound
Prompt Injection 2.0: Hybrid AI Threats Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8a6b4405-be54-4aaf-bad0-de88deabf587 · outbound
Prompt Injection 2.0: Hybrid AI Threats Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e5e416d9-e605-440c-b626-69eb3f50bd19 · inbound
Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Prompt Injection 2.0: Hybrid AI Threats
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 406e2f80-5836-4e26-8605-0a1161a23245 · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Prompt Injection 2.0: Hybrid AI Threats
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 621df737-31d9-4a80-9d4e-e92f691c623e · inbound
Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Prompt Injection 2.0: Hybrid AI Threats
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.