Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-27T12:47:09.467463Z
Paper Citation Record · LEDGER
As of 4 August 2026, this Paper Citation Record lists 67 of 67 outbound references and 0 inbound Pith citation observations for arXiv:2606.10525.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-27T12:47:09.467463Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
67 of 67 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation e2175545-0e6c-455f-85bb-b4283b9ad0ef · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1ee7f075-e77d-4fbf-8a18-e534f02540bd · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Sampling-aware adversarial attacks against large language models.arXiv preprint arXiv:2507.04446, 2025
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 24b8f3eb-08b9-4573-ba88-a0e705d9f59a · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Jailbreaking Black Box Large Language Models in Twenty Queries
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6b1d030d-ef0b-4e7a-a46d-94163d3bdb38 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 915b0cdd-a67d-4278-92f4-9ef813886252 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments URL https: //doi.org/10.1145/3719027.3744835
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 63691e42-5416-44d0-805b-97a3e15d0d63 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Meta secalign: A secure foundation llm against prompt injection attacks
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 21b6af64-9a94-428c-8ff3-4a3c7e239617 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Learning to Inject: Automated Prompt Injection via Reinforcement Learning
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2e545c43-6a8a-4082-9c79-2cf247cedcb9 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a194b1da-09d8-4316-a2cc-a34a5341fac4 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Securing AI Agents with Information-Flow Control
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c5a085ea-1145-4b70-a35c-4a057d34e657 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Defeating Prompt Injections by Design
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 178ae034-1097-4fcf-b79e-8610f6c32b11 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4c9ed9a3-6450-496c-9aa7-dd3d6f99700f · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 17a697c7-e944-4869-a765-ba8ef2c3ed25 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments & Kolter, Z
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 79b665f1-26d8-4d01-bda8-fcab0f5f660b · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Imprompter: Tricking LLM Agents into Improper Tool Use
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 46d7cb98-b107-493f-9213-0a5be6c2e030 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Gemma 3 Technical Report
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation aeca2500-7405-4bd9-9cb8-ccb3e7ff5648 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments InProceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec @ CCS 2023)
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e3bf848b-5e03-4b33-b18f-6fc0420a2afc · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2742897c-e321-476f-be48-6b5b682c8976 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ba11e2fc-3eb9-46cb-8184-05f6f701777c · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Preventing Prompt Injection with Type-Directed Privilege Separation
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4e80470c-e098-47e9-9ab7-010b726dc5f9 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4cfbbdf1-4b0e-42cf-b063-10f2eab4c9d9 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3fdbf6e5-ccbc-4ddf-b86d-238856fdc238 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments arXiv preprint arXiv:2602.07918 , year=
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 88cc671f-635b-4b63-ae00-9b07b08a847c · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 20b9044d-e263-4c9a-aa21-47d80a5c24ec · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Robertson, Alina Oprea, and Cristina Nita-Rotaru
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation fbf4a131-38e0-44b2-b1e3-7493e7485c40 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 964d2a29-652f-4aaa-96fd-86f779c9a300 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ca83f5c8-0ff8-4968-8413-298cb1059493 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 67a01730-8438-4960-8089-122be29bf809 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 179b5120-023f-49cf-bfe2-b7bf91c6b347 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 85ddeca4-b393-4b24-af65-21ea2c5ddafb · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 103ee248-3490-449f-955e-83b53478bf4a · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Schmidt, and Florian Bernard
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4041e4c6-687d-4594-9def-f976606b0e2a · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f679763-cc3a-4c24-8125-049799287f05 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments OET: Optimization-based prompt injection Evaluation Toolkit
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8c451372-cbde-49be-9b33-d29787b7304e · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Pandya, Andrey Labunets, Sicun Gao, and Earlence Fernandes
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 64bd7d9f-4c8d-4548-8f2e-014e775cf0b1 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3094d42c-5fa7-4ca0-9b85-25eb5f8f8652 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Ignore Previous Prompt: Attack Techniques For Language Models
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e400f000-afd5-4203-bad2-5d11f5110455 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7f19c3da-a3ea-410a-acd0-feb6b13e3a5a · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments 2019.Language Models are Unsupervised Multitask Learners
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f43af389-6a73-46f3-b5d8-ed7cc9bfcd94 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24aadd62-b927-46f1-8f53-9be0fe420317 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Prompt Injection Attack to Tool Selection in LLM Agents
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation adcf6bab-1648-43c3-9144-baaf690bee4b · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Progent: Securing AI Agents with Privilege Control
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4d2b9350-639a-4886-8b75-7ecdc24e3c81 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 56f0bc90-04e7-4d49-8d53-4db78cc3e317 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments https://doi.org/10
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 412cde2d-a5bb-4fc3-bbf5-52bb12fd7d8a · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6bcc2151-383c-4332-8efe-494d9f1e9bc8 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5e8bc831-6b73-4c07-ab03-1962a5f8371b · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cecd6181-85a9-455b-a630-d3d62fb60e05 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Instructional Segment Embedding: Improving LLM Safety with Instruction Hierarchy
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cef3c106-1b6a-4445-abf4-79ecc87dd069 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 781b7d30-9e9f-4625-9836-57e222daef37 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments InNetwork and Distributed System Security (NDSS) Symposium
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 953d2702-ab30-4afe-85d9-b7a1cd92ca12 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments The rise and potential of large language model based agents: a survey.Sci
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5fdb94a6-5a64-4702-b374-2c10410c8a18 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Qwen3 Technical Report
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6b9709cd-e6fb-4490-84c9-7de61a943015 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Align- ment under pressure: The case for informed adver- saries when evaluating llm defenses
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a01fee04-b7c9-4f58-b529-93d3b7eaee0f · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8cd79802-fef0-43b2-bd91-eedd15cb25ce · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1 , pages =
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation eee81a4c-cb9d-4310-b26c-483246ef7e9f · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments scrolling screenshot
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 844c3d3e-c593-4552-8f5f-a6c9ae4b097d · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments In: Zong, C., Xia, F., Li, W., Navigli, R
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6d0b9b79-250c-4f5a-85fe-a20a1e1e19b7 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 23bc665b-1513-4c67-8076-ab33edaecd18 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e6297b21-717f-4ad1-9c61-2696e2fe86ce · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5f931fcc-b6b6-407c-8a16-1428f067818c · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 99f0b189-84c0-408d-80d4-78713be86b05 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments attacker goals
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 459a8f6a-6c32-4349-a37d-3c9af55680c6 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 62
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a9c54ebc-9677-4043-bd78-df150935d3af · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8f66e165-a617-4c3a-9929-c8b0e50c3e06 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments [SYSTEM OVERRIDE]
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9930f064-7082-48ed-bc83-5f9f8db30951 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0b84a063-2a97-4256-b3ad-120945476152 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 66
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4b8baf16-e2ef-47e9-b781-c0a8d4613c76 · outbound
Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.