Pith. sign in

Paper Citation Record · LEDGER

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

As of 4 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 2 inbound Pith citation observations for arXiv:2604.24118.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2604.24118 v1

Coverage vector

measured 20 of 20 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-08T03:07:21.524834Z

measured 22 of 22 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00

measured 2 of 2 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-01T06:40:05.033819Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

20 of 20 outbound references displayed

  • verified exact1
  • verified fuzzy6
  • unresolved1
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch12

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 38648840-d053-4eb0-be8d-b05dcf8a8c4b · outbound

This paper cites Defending Against Prompt Injection With a Few DefensiveTokens.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Prompt Injection With a Few DefensiveTokens

Reference 1

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:31.049398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:366dfee123989dc4d6fdfa37a242882c7dcb3a29b000cb16e0489c69ae1e8876

Observation 6f7c90b8-2c6b-441a-8fe3-e71e38211f9d · outbound

This paper cites https://docs.cloud.google.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization https://docs.cloud.google

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.359110Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:dfc79667d434ece71808c11b89ace88ff7505d33bd91274418dc5f20d4acb702

Observation a98aa8a6-22a5-46c6-9d90-c4fbcc500f1f · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-05-14T22:28:55.556742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:705b841a7d583001460e3b919387195fa2b0f3cd9f0f98f8a928be17bd23cfbd

Observation e46d2afd-0c0a-4d35-9f59-2d5818011af4 · outbound

This paper cites GPT-4o System Card.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GPT-4o System Card

Reference 4

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.475909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:ce276ceb1801425f8fe792505b0bc65fe59e1e1854792c0eb1a501c57df01415

Observation 5acdecc0-a3ec-40b9-9e28-78be41ea06be · outbound

This paper cites Promptlocate: Localizing prompt injection attacks.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Promptlocate: Localizing prompt injection attacks

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.056074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:2c882ba2b236494cb51d39aed1c150faaf53c5a9e2df810493b7951f18b3f66b

Observation 62cb19c6-20ab-4dd7-b231-467f86a45c7c · outbound

This paper cites InProceedings of the 2024 conference on empirical methods in natural language processing: industry track, pages 371–385.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 conference on empirical methods in natural language processing: industry track, pages 371–385

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.353350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:deda8709af5f57e7497c304b5a72414aa89031987685219487e038ebc62bee10

Observation 0758cb4a-9c1a-4ce4-84da-61f3390ff217 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 7

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.268382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:09c0fd1d5059804495ceb720a33e68433c6ca8c7b85435dfdca350f135f38e42

Observation f6f6a1bc-9684-4b1f-b6a5-71b586ac4d02 · outbound

This paper cites In 2025 IEEE Symposium on Security and Privacy (SP), pages 2190–2208.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In 2025 IEEE Symposium on Security and Privacy (SP), pages 2190–2208

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.350682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:5e8f84ade5376a34a303425604b1d7416983acbc28bdba53a4127e6d41863e8f

Observation 0488dda1-cd25-4591-854a-0876e3cecff1 · outbound

This paper cites The Llama 3 Herd of Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization The Llama 3 Herd of Models

Reference 9

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:30.755496Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:2645cf4b9cf5e74256f512d972367a46dfa5204bd9a45230cbd0aef59fe34831

Observation f4c90596-ae9a-4b7c-b243-ae36149a6b88 · outbound

This paper cites cellmate: Sandboxing browser ai agents.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cellmate: Sandboxing browser ai agents

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:32.359050Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:e5a3e58a57aa1a79273ab875875cac09cf73a4820ccf0fb0dd51c8a1398633e4

Observation 37cbf9f3-494f-449a-a4fe-5cfa6f0b6dd7 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Ignore Previous Prompt: Attack Techniques For Language Models

Reference 11

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:32.209358Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:2f23994d48a75ecd2607695690b76d00657cb82ea2bec150cda10f4dd555cb03

Observation 27d3cb5b-29fd-4acd-80eb-021290cad666 · outbound

This paper cites 9 Gerald J Popek and Robert P Goldberg.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization 9 Gerald J Popek and Robert P Goldberg

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-11T22:16:29.937787Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:e38c91e2263d657472048a63a985221b955e8f6a2c5b3a8256d208ab47d5f87b

Observation dbf93f3b-29a0-4f42-9167-ca6ac4953537 · outbound

This paper cites InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, pages 660–674.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, pages 660–674

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.356257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:1a993338677c03d819d34c6a5309fa8e4ed89af3f0c5eaa33c4d34fa6a439b2d

Observation 0d540643-035f-498a-b251-c718ced57266 · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:31.942505Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:601b84392397ec8bea499f8dc3071b840eed85bb5245a51a9319331eb9cae861

Observation 14c31d71-a508-46a2-988d-8d6d77f1f85a · outbound

This paper cites InProceed- ings of the 2009 ACM SIGPLAN/SIGOPS interna- tional conference on Virtual execution environments, pages 121–130.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceed- ings of the 2009 ACM SIGPLAN/SIGOPS interna- tional conference on Virtual execution environments, pages 121–130

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.362088Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:98076277622d39a5bcd16b160408736679445d15244809429e959471b22c2897

Observation e50554d4-97a1-45c3-a630-a85f144002b1 · outbound

This paper cites GLM-4.5: Agentic, Reasoning, and Coding (ARC) Foundation Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GLM-4.5: Agentic, Reasoning, and Coding (ARC) Foundation Models

Reference 16

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.245875Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:97bdb5a7270149a3ba9d65bf2854358ce6a920df98781605851d31dff4d5fbde

Observation a6b9a0e8-0b36-4952-a915-54285597f024 · outbound

This paper cites In Proceedings of the 33rd ACM International Confer- ence on Multimedia, pages 10955–10964.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In Proceedings of the 33rd ACM International Confer- ence on Multimedia, pages 10955–10964

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.348268Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:d25eb97d690df0535dcfcd2b7aba30105d2e5f814315b1c8f152f61a6d814128

Observation 51ca2548-2ad7-4fb1-8191-5594169a9fb9 · outbound

This paper cites an unresolved cited work.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-05-26T22:23:09.345363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:f21b05b6fca2d4f2d1661e92836c8508a78911f6d85725d1a6299d78222ed51e

Observation af9bf477-2843-42a9-acb7-81f110a10627 · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.500382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:cb1e930ac726a25c4bdef948ab130b33177dc182ec9260de2043bc0577de862f

Observation 6ce32323-bb7a-402c-a512-5d461697239a · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 20

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.675479Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:45445a35f6ae3858b3b243089b3b03fc126f5749f807b1ac977eb4a7af9a2c6a

Pith citing papers

Observation 14d6e910-31d5-4ba8-be7a-354f80c8d7c1 · inbound

Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense cites this paper.

Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T06:40:05.033819Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T06:40:05.033819Z digest=sha256:31d190b95fb1b4e3f2d881962e592cf92ca0cf2735f76a2c14d48b4658a35b5d

Observation e14d8970-0c9e-4951-a1ca-0975bdcf0c74 · inbound

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls cites this paper.

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 40

Resolution
unresolved
no resolver link, observed 2026-07-31T17:44:15.652372Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-31T17:44:15.652372Z digest=sha256:e3eebc569d9f4500d5dd819064e0050e0b292c22da95b3903f131c03a5cda59c