Pith. sign in

Paper Citation Record · LEDGER

Prompt Injection 2.0: Hybrid AI Threats

As of 7 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 3 inbound Pith citation observations for arXiv:2507.13169.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.13169 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 3 of 3 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-05-22T12:46:44.819224Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-22T12:51:33.393440Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact2
  • verified fuzzy1
  • unresolved25
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation e22e7f76-32cd-4cb3-869f-3183830e0afa · outbound

This paper cites Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples.

Prompt Injection 2.0: Hybrid AI Threats Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.088522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.088522Z digest=sha256:1651cd9600b4e0d4f78c0edfe913717cc8b7a0ef2f3ee77565705fc59b7d121f

Observation 28fbf030-816c-41ff-903c-2df09f0a7f9c · outbound

This paper cites C., & Heichman, R.

Prompt Injection 2.0: Hybrid AI Threats C., & Heichman, R

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T16:34:08.065627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:03.214886Z digest=sha256:caa4941281aa2b7a2088fe1b93d8c4ae8499c1b0d3ba6f34c567c4708369d18b

Observation 4ba24e3f-f487-4b02-a626-63b6ad009055 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Prompt Injection 2.0: Hybrid AI Threats Prompt Injection attack against LLM-integrated Applications

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.313953Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.313953Z digest=sha256:a5d48a1df5e7ca344749989feeba668518fa95dc01c7cbfa899626261a67661c

Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.407180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.407180Z digest=sha256:bf5d6a1819aa7d52cd513411c7e3606664e5407c5f66e0ed601a797423b687ce

Observation 2c8e481a-6979-4c1e-91d7-eb514330e081 · outbound

This paper cites From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?.

Prompt Injection 2.0: Hybrid AI Threats From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.503194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.503194Z digest=sha256:2ccdf3c95125f804b2853b13df87c266b62e58c4a86cade547dc584d66d2a7c8

Observation 81b7056d-e92d-4262-a83a-cfadff70051b · outbound

This paper cites AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development.

Prompt Injection 2.0: Hybrid AI Threats AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.402350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:03.624743Z digest=sha256:11dd7358363015d4f98f183d99839ba44e597a474c45982822f573ea243350a1

Observation 74108fff-12a9-4135-8e67-a6a18bca8085 · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

Prompt Injection 2.0: Hybrid AI Threats Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.695223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.695223Z digest=sha256:d76a5f9b9476621f4c6639d98e4d67d2ad5f0bc033fb87c75bf0566d8852d52a

Observation 9ffcd4e8-6f3c-4856-9cce-4421416681fa · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 8

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.818080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:03.778176Z digest=sha256:85ba3e693b22cdbc1e80753d77a85d58fcff0bd808a346477fa553af38af5508

Observation 67a374ee-c085-4de3-abb1-fb82d9c1fefe · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Prompt Injection 2.0: Hybrid AI Threats Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.842222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.842222Z digest=sha256:95383b8cd564a5214eb196f4be6e6ad845e1de38ba595200288c5fd75b8cde9e

Observation 7f4cdc41-655f-434b-9be2-a74bc3172ba9 · outbound

This paper cites Defeating Prompt Injections by Design.

Prompt Injection 2.0: Hybrid AI Threats Defeating Prompt Injections by Design

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.919189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.919189Z digest=sha256:8eb03a548815592f8d2780e02080885d08373853d8764fc84b2bb05bfdbe031f

Observation 1c073cff-1405-48a5-91aa-b7a78fc582b7 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 11

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.505229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:04.001119Z digest=sha256:d1b30e5db08aec8b70c441e809e15d48a150c3d680c6e7bd8de140e44a57f3cd

Observation 43d9d6d4-67cb-4608-89d9-d5c6532faf25 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.307622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:04.096370Z digest=sha256:02c1b3d8b1a2caeb51c9a62445340daf1662ea879845037831312227990b6c7d

Observation 0c024737-d7c3-4a78-9b2f-f2c999750230 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 13

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.022398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:04.192243Z digest=sha256:31c738d683ff11da79b5918a3d54497c95549c097296023d23c8b8ca3525a993

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:c8c7a0a93d351735090db6ae2361236a86ce3ae0bdbce4dfe19e6929cba2cf6d

Observation 932b69ab-e882-49e0-a697-a9bbcf822bb9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.877652Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:04.375475Z digest=sha256:e7d1d1080c118ff82ac9a3976034a4dc23262588f6e023eb7d6729cbdd5d3337

Observation e379a488-61be-486e-b10a-30e052f70bbd · outbound

This paper cites XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants.

Prompt Injection 2.0: Hybrid AI Threats XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.094966Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:04.450450Z digest=sha256:241221f24af3e9be8f60b68f9be7f037def93368f789d1536cb0e5a1152f8461

Observation 97ca63c5-25a5-4980-94cb-1c29107c98e0 · outbound

This paper cites The Hidden Dangers of Browsing AI Agents.

Prompt Injection 2.0: Hybrid AI Threats The Hidden Dangers of Browsing AI Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.510763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.510763Z digest=sha256:e4b02894c41e8731e4a437f195fe87f617efe4737288d4caba84336c04c36bf2

Observation 48ce344e-7e62-45bd-8d86-18374023e328 · outbound

This paper cites Learning to Poison Large Language Models for Downstream Manipulation.

Prompt Injection 2.0: Hybrid AI Threats Learning to Poison Large Language Models for Downstream Manipulation

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.598552Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.598552Z digest=sha256:dcab1ddf51e9911fa6027f042c676bc2e0108175d51a190ec18e732114759bef

Observation fb31b710-e5d8-497a-9bb8-b335be88601d · outbound

This paper cites Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.667309Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.667309Z digest=sha256:279061eea0032ff33572dc19ffdd77fe0bcd7e69e58b2947caca7ad38617ddd8

Observation 8a60a853-a16d-4b30-beb5-e095804b0e30 · outbound

This paper cites Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.754226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.754226Z digest=sha256:5f2af4bc8135cf53729a6cf80638b32f298f5f061a37b263f475cd348f134d83

Observation fbe5eca5-fc2b-4390-98d2-c32b7d9b82ac · outbound

This paper cites Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.853306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.853306Z digest=sha256:647fa48addb482226e46c439f2d843ec8b6d8642451883f861ce41921abe952a

Observation 2a247095-3659-4852-b88a-22fed94a42b8 · outbound

This paper cites Manipulating Multimodal Agents via Cross-Modal Prompt Injection.

Prompt Injection 2.0: Hybrid AI Threats Manipulating Multimodal Agents via Cross-Modal Prompt Injection

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.952025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.952025Z digest=sha256:912698bed19cec07ef665dc9c15048d640a6319008381a08701a265450b0af8c

Observation 6514fbca-975f-4253-a587-05efbc389ff9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.771915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:05.011939Z digest=sha256:e4bf3e621c7cbfd87af7fe2bcfba420d5763ce214393f15041da878db6f6ba39

Observation 80107157-42c9-4510-a17b-5ec0990ce669 · outbound

This paper cites Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs.

Prompt Injection 2.0: Hybrid AI Threats Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.101373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.101373Z digest=sha256:4e46219623d42a174e0b5418a8e95b2bba0e8060e731d0a85c9b7fa36cb48c9c

Observation 711b04e6-a84a-4b06-8648-54f847ee47d8 · outbound

This paper cites Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition.

Prompt Injection 2.0: Hybrid AI Threats Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.169846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.169846Z digest=sha256:d20a514bf474080515b89b9f082728247e1fb29685f8c95666b4b2e5c0af9e2a

Observation 901f6257-6605-4160-b812-d5c36cc18a4a · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 26

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T16:34:06.657603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T16:34:05.255867Z digest=sha256:7472cfdb93540e7ffbc7bd6782f79de226603d55ce1ca67c5dbe3141cf58764e

Observation 53d2c546-ea9f-4636-bf87-72f6c0317db7 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

Prompt Injection 2.0: Hybrid AI Threats LLM Agents can Autonomously Hack Websites

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.325342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.325342Z digest=sha256:5ec1c38df9744e8ffdf3d8d1aea4242aa25cd871a4c65500b65a3e29efbd1d77

Observation 4a6efbb7-8971-44ae-aabf-67ad24ecb2ae · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.379319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.379319Z digest=sha256:c20090c9e5657863653202cab96decdb304cea314acc749ef2019970026e4754

Observation 8a6b4405-be54-4aaf-bad0-de88deabf587 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Prompt Injection 2.0: Hybrid AI Threats Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.446734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.446734Z digest=sha256:4297ae72a46259e41755f886ed554e3db6b03f71ea6fb9bfeeb949601eab2020

Pith citing papers

Observation e5e416d9-e605-440c-b626-69eb3f50bd19 · inbound

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities cites this paper.

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Prompt Injection 2.0: Hybrid AI Threats

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-18T18:06:43.025006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-18T18:04:09.528381Z digest=sha256:75c9fc59a8d3b5e642d3cafeb7011ac679d5464e8f202e2a31b4d34e4e434041

Observation 406e2f80-5836-4e26-8605-0a1161a23245 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Prompt Injection 2.0: Hybrid AI Threats

Reference 61

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.431852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:64f6b30369e810f794206181118bae1d47cabd680792e591c26b66881c106a66

Observation 621df737-31d9-4a80-9d4e-e92f691c623e · inbound

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation cites this paper.

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Prompt Injection 2.0: Hybrid AI Threats

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:51:33.396810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-22T12:46:44.819224Z digest=sha256:bd57c4d023f73c3c9bce4de67bb9ba6dfb826330216f163d1669370f156c8498