Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-10T00:02:35.167281Z
Paper Citation Record · LEDGER
As of 5 August 2026, this Paper Citation Record lists 30 of 30 outbound references and 2 inbound Pith citation observations for arXiv:2604.20994.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-10T00:02:35.167281Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-07-13T17:08:58.831798Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-07-02T21:07:23.686230Z
30 of 30 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation e4be9763-e351-48c1-bb75-2a9280a79105 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Granite-Function Calling Model: Introducing Function Calling Abilities via Multi-task Learning of Granular Tasks
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4b5adb7b-2248-4cc5-a054-bf2d1a76f191 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6c886954-712d-4542-ac42-c766f3e6cdc6 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Small Language Models are the Future of Agentic AI
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 942fe2a4-f747-4c9d-aa45-a1df055c4578 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f9ba968a-dc4f-4755-a7b2-b42164db25e1 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Chawla, Olaf Wiest, and Xiangliang Zhang
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 156d8fa3-11f2-42e5-a6fe-24e5a888c145 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Query-Based Adversarial Prompt Generation
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d7f29649-64cd-4a86-b9f0-7bcdde9c91f9 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models The emerged security and privacy of llm agent: A survey with case studies
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 227a1749-99fb-4149-bae1-a53b15c84a7c · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d56d398c-4e71-4cd6-91c9-fa5700afdec0 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Mistral 7B
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 95b25623-fede-414c-b7de-4d378bd9519f · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Small Models, Big Tasks: An Exploratory Empirical Study on Small Language Models for Function Calling
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a40a26bd-59da-47bb-b83b-997e5a0930c4 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models doi: 10.1007/978-1-4020-5614-7_2569
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e999f22a-0af0-43b5-95af-3016b0ce9367 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 452cc3db-cb36-4c5e-b5e8-bcd4e90e7e7e · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Improving Small-Scale Large Language Models Function Calling for Reasoning Tasks
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6f45da65-d33e-4a4d-87f4-1d2a979c383c · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models GPT-4 Technical Report
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2d04e746-dd57-4d8e-866e-52c4fcad3630 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Gorilla: Large Language Model Connected with Massive APIs
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7982d7b7-2af6-4a08-a5b1-15d8a876b20f · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Qwen3 Technical Report
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c6035f76-126d-426f-8739-e91c2e80ec34 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Attack Atlas: A Practitioner's Perspective on Challenges and Pitfalls in Red Teaming GenAI
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e23a0ec1-bcb9-40b5-b5d6-74cb965e43f5 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Toolformer: Language Models Can Teach Themselves to Use Tools
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9c946c59-4198-4ad6-be0a-9ff4891064c5 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models LLaMA: Open and Efficient Foundation Language Models
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bb5daf56-e290-461f-a095-2bd4174dd0e7 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Frontiers Comput
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2314d07c-6aad-44e6-8562-809e02a38862 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Mpma: Preference manipulation attack against model context protocol
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0b3a85a4-9a7b-4349-aa8a-f0e25ef55c1f · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Chain-of-Tools: Utilizing Massive Unseen Tools in the CoT Reasoning of Frozen Language Models
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d694d785-c614-4000-8372-1e35e787a8c8 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models The Dark Side of Function Calling: Pathways to Jailbreaking Large Language Models
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5d83d633-9d93-4bde-bcee-02774333068e · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models ReAct: Synergizing Reasoning and Acting in Language Models
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f11bf409-6bfd-486f-beaf-4fbf122d1bc6 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Jailbreak Attacks and Defenses Against Large Language Models: A Survey
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f64c2241-ab4f-42e4-8de0-401a934a4e77 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 00c339ae-648a-41f4-b060-8eb944fbb130 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 235710f3-2205-4509-96fa-ec57a0c3c973 · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Improving Alignment and Robustness with Circuit Breakers
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 55bc25ac-1d02-482e-befe-76950f5529ff · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Figures (1), (2) and (3) detail the prompts used for the reformulation (1) and argument-variation (2), and multi-intent variation (3) strategies, respectively
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cc40ab87-f257-499d-95f7-f05b57d056ad · outbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Specifically, we observe a peak on lower values for strategy (3), representing the queries containing different intents from the original prompt
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 41f00fa2-d1d9-4298-8c44-af22c0bb7a4b · inbound
Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 963af959-715f-47af-b5c2-8fddfb2a0997 · inbound
VATS: Exploiting Implicit Authority in Error-Path Injection via Systematic Mutation Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.