Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-08T03:07:21.524834Z
Paper Citation Record · LEDGER
As of 4 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 2 inbound Pith citation observations for arXiv:2604.24118.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-08T03:07:21.524834Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-01T06:40:05.033819Z
A source-named dated measurement, never combined with another source.
Source: cited_works
20 of 20 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 38648840-d053-4eb0-be8d-b05dcf8a8c4b · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Prompt Injection With a Few DefensiveTokens
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6f7c90b8-2c6b-441a-8fe3-e71e38211f9d · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization https://docs.cloud.google
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a98aa8a6-22a5-46c6-9d90-c4fbcc500f1f · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e46d2afd-0c0a-4d35-9f59-2d5818011af4 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GPT-4o System Card
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5acdecc0-a3ec-40b9-9e28-78be41ea06be · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Promptlocate: Localizing prompt injection attacks
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 62cb19c6-20ab-4dd7-b231-467f86a45c7c · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 conference on empirical methods in natural language processing: industry track, pages 371–385
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0758cb4a-9c1a-4ce4-84da-61f3390ff217 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Automatic and Universal Prompt Injection Attacks against Large Language Models
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f6f6a1bc-9684-4b1f-b6a5-71b586ac4d02 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In 2025 IEEE Symposium on Security and Privacy (SP), pages 2190–2208
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0488dda1-cd25-4591-854a-0876e3cecff1 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization The Llama 3 Herd of Models
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f4c90596-ae9a-4b7c-b243-ae36149a6b88 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cellmate: Sandboxing browser ai agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 37cbf9f3-494f-449a-a4fe-5cfa6f0b6dd7 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Ignore Previous Prompt: Attack Techniques For Language Models
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 27d3cb5b-29fd-4acd-80eb-021290cad666 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization 9 Gerald J Popek and Robert P Goldberg
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dbf93f3b-29a0-4f42-9167-ca6ac4953537 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, pages 660–674
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0d540643-035f-498a-b251-c718ced57266 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization PromptArmor: Simple yet Effective Prompt Injection Defenses
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 14c31d71-a508-46a2-988d-8d6d77f1f85a · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceed- ings of the 2009 ACM SIGPLAN/SIGOPS interna- tional conference on Virtual execution environments, pages 121–130
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e50554d4-97a1-45c3-a630-a85f144002b1 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GLM-4.5: Agentic, Reasoning, and Coding (ARC) Foundation Models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a6b9a0e8-0b36-4952-a915-54285597f024 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In Proceedings of the 33rd ACM International Confer- ence on Multimedia, pages 10955–10964
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 51ca2548-2ad7-4fb1-8191-5594169a9fb9 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Unresolved cited work
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation af9bf477-2843-42a9-acb7-81f110a10627 · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6ce32323-bb7a-402c-a512-5d461697239a · outbound
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 14d6e910-31d5-4ba8-be7a-354f80c8d7c1 · inbound
Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e14d8970-0c9e-4951-a1ca-0975bdcf0c74 · inbound
Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.