Pith. sign in

Paper Citation Record · LEDGER

Assessing Automated Prompt Injection Attacks in Agentic Environments

As of 4 August 2026, this Paper Citation Record lists 67 of 67 outbound references and 0 inbound Pith citation observations for arXiv:2606.10525.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.10525 v1

Coverage vector

measured 67 of 67 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-06-27T12:47:09.467463Z

measured 67 of 67 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

67 of 67 outbound references displayed

  • verified exact33
  • verified fuzzy0
  • unresolved25
  • parse uncertain0
  • malformed identifier2
  • metadata mismatch7

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation e2175545-0e6c-455f-85bb-b4283b9ad0ef · outbound

This paper cites Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks.

Assessing Automated Prompt Injection Attacks in Agentic Environments Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.960012Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:34a6fca9343262c72d311a176ad076fa67085f3a33c630ac3b5d344541d9e322

Observation 1ee7f075-e77d-4fbf-8a18-e534f02540bd · outbound

This paper cites Sampling-aware adversarial attacks against large language models.arXiv preprint arXiv:2507.04446, 2025.

Assessing Automated Prompt Injection Attacks in Agentic Environments Sampling-aware adversarial attacks against large language models.arXiv preprint arXiv:2507.04446, 2025

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.943108Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:73d374e70c79a798af48d133dc257de2991139d648ccc7eddb05a8c4b3d27f46

Observation 24b8f3eb-08b9-4573-ba88-a0e705d9f59a · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Assessing Automated Prompt Injection Attacks in Agentic Environments Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 3

Resolution
metadata mismatch
local_arxiv, observed 2026-07-03T06:17:41.965090Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:02a653c476c95affb7deacd6f2688ca9316bcdef27de328d125cb502b3427465

Observation 6b1d030d-ef0b-4e7a-a46d-94163d3bdb38 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 4

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:c6f955e19e7a79056dda31d01d3d7610001ef6b7b5fdbea3e89ab06fce72c28c

Observation 915b0cdd-a67d-4278-92f4-9ef813886252 · outbound

This paper cites URL https: //doi.org/10.1145/3719027.3744835.

Assessing Automated Prompt Injection Attacks in Agentic Environments URL https: //doi.org/10.1145/3719027.3744835

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-06-27T12:50:55.669003Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:afc19b7f90e5921e34ac2429255db897f2b4f740cf5177898f9c7b5a31813be7

Observation 63691e42-5416-44d0-805b-97a3e15d0d63 · outbound

This paper cites Meta secalign: A secure foundation llm against prompt injection attacks.

Assessing Automated Prompt Injection Attacks in Agentic Environments Meta secalign: A secure foundation llm against prompt injection attacks

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.963869Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:c9ecc375c084442c41c9df1b21b3ac8972af6047c1f160147ce5bfffd230db91

Observation 21b6af64-9a94-428c-8ff3-4a3c7e239617 · outbound

This paper cites Learning to Inject: Automated Prompt Injection via Reinforcement Learning.

Assessing Automated Prompt Injection Attacks in Agentic Environments Learning to Inject: Automated Prompt Injection via Reinforcement Learning

Reference 7

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.929906Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:f41341436ebebe34e7a1f5f18b813f554221963dc0732e0a81eecf23dfa246fb

Observation 2e545c43-6a8a-4082-9c79-2cf247cedcb9 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 8

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:60e7f4065b78a27e12bbddec1ec4124a87c25790e9a9bbabb32cfd00c50d46c7

Observation a194b1da-09d8-4316-a2cc-a34a5341fac4 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Assessing Automated Prompt Injection Attacks in Agentic Environments Securing AI Agents with Information-Flow Control

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.855000Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:9e4959d0aa8ead9d4811eea8f181f0945ae4ccfd1cc198f5c4eadcb1757cccf9

Observation c5a085ea-1145-4b70-a35c-4a057d34e657 · outbound

This paper cites Defeating Prompt Injections by Design.

Assessing Automated Prompt Injection Attacks in Agentic Environments Defeating Prompt Injections by Design

Reference 10

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.846662Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:df0a5491d8169a9df704bc7230f901fedd004ce8e1ba86f59e4564566b2ae2f0

Observation 178ae034-1097-4fcf-b79e-8610f6c32b11 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.857461Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:709aaef57e6d9140a950ed094d324d1971cbe720c6f09be3be1879dd5219056e

Observation 4c9ed9a3-6450-496c-9aa7-dd3d6f99700f · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 12

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:ccbe9e42fea4c8e2e9daa04c6333743e2e8f0473d40d00486f0b08ab099ced66

Observation 17a697c7-e944-4869-a765-ba8ef2c3ed25 · outbound

This paper cites & Kolter, Z.

Assessing Automated Prompt Injection Attacks in Agentic Environments & Kolter, Z

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.863770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:223ce3f489eee7cc5416a492ffa55b840094073ea818c94aa6fd858e2d5dd654

Observation 79b665f1-26d8-4d01-bda8-fcab0f5f660b · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

Assessing Automated Prompt Injection Attacks in Agentic Environments Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.981522Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:1b961daf8402558ebd5b7b1f4755cb0502064b4331120cd82e6ce397d8591226

Observation 46d7cb98-b107-493f-9213-0a5be6c2e030 · outbound

This paper cites Gemma 3 Technical Report.

Assessing Automated Prompt Injection Attacks in Agentic Environments Gemma 3 Technical Report

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.990836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:a02e82bc200fa5e8a71bfa81a92d39d59a02727404b2679bd5441ead554d320a

Observation aeca2500-7405-4bd9-9cb8-ccb3e7ff5648 · outbound

This paper cites InProceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec @ CCS 2023).

Assessing Automated Prompt Injection Attacks in Agentic Environments InProceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec @ CCS 2023)

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-06-27T12:50:55.655383Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:1a05b1b4933b8b2ec087d5d0834b2e64f867ceb7559298aa921453b4768a92c3

Observation e3bf848b-5e03-4b33-b18f-6fc0420a2afc · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Assessing Automated Prompt Injection Attacks in Agentic Environments Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 17

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.975379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:27b2ec93c22ae585814dcc998dd03f031946dae265349d579e43d80e1f6a8905

Observation 2742897c-e321-476f-be48-6b5b682c8976 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 18

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:eff9b69fcbd2271eb536e7528551512f92f31d01ccd7e711fdfa08a5bcdc8c6a

Observation ba11e2fc-3eb9-46cb-8184-05f6f701777c · outbound

This paper cites Preventing Prompt Injection with Type-Directed Privilege Separation.

Assessing Automated Prompt Injection Attacks in Agentic Environments Preventing Prompt Injection with Type-Directed Privilege Separation

Reference 19

Resolution
metadata mismatch
local_arxiv, observed 2026-07-03T06:17:41.954467Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:8106d5557034436ff218f5144bed52031a8b08227f3a158289bf985a870eec36

Observation 4e80470c-e098-47e9-9ab7-010b726dc5f9 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 20

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:ef354875c54126a49799aad9ff155e7be1ba2ec07611625c893c9cb0e8db083f

Observation 4cfbbdf1-4b0e-42cf-b063-10f2eab4c9d9 · outbound

This paper cites Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents.

Assessing Automated Prompt Injection Attacks in Agentic Environments Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.955388Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:b3947296e4185d1ef7f29759cff314e13a0b474cb93fc280edabca7d17b14405

Observation 3fdbf6e5-ccbc-4ddf-b86d-238856fdc238 · outbound

This paper cites arXiv preprint arXiv:2602.07918 , year=.

Assessing Automated Prompt Injection Attacks in Agentic Environments arXiv preprint arXiv:2602.07918 , year=

Reference 22

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T06:17:41.966712Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:a3608a537243eec5f72b6bb6aa626b8216ea47af0d00923037d369455876e0de

Observation 88cc671f-635b-4b63-ae00-9b07b08a847c · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 23

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2e340281fcab3891cc7f957bd5e232820bc71face2e05a2afdacd2ee41dfe3c1

Observation 20b9044d-e263-4c9a-aa21-47d80a5c24ec · outbound

This paper cites Robertson, Alina Oprea, and Cristina Nita-Rotaru.

Assessing Automated Prompt Injection Attacks in Agentic Environments Robertson, Alina Oprea, and Cristina Nita-Rotaru

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-06-27T12:50:55.666607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:0a4adbe7206ceed05d2eb7d585d788f5121eeb4d81465ad48715c6ba8c464c56

Observation fbf4a131-38e0-44b2-b1e3-7493e7485c40 · outbound

This paper cites AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?

Reference 25

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.969697Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:4e332b35649bdad6a6ed644ffd7cdb96db81258c25dfb1f437977b39b48004bf

Observation 964d2a29-652f-4aaa-96fd-86f779c9a300 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2bab908b683e4413e44582339cb4a82def2992069e6f15ee5115acc6e2ac125d

Observation ca83f5c8-0ff8-4968-8413-298cb1059493 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 27

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:7ec8aa925f517986691dbb826b02493fd1b5e32f6e01efe692405f308a290099

Observation 67a01730-8438-4960-8089-122be29bf809 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 28

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:b1b222e242f4b322b9a5bfe886e55470b490c08d91f672810a1ac1cb76e10d35

Observation 179b5120-023f-49cf-bfe2-b7bf91c6b347 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 29

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:74adf1ef62391e6a2fa95022efc17df928f0443cb679e4f0a81a90fd187b6b3b

Observation 85ddeca4-b393-4b24-af65-21ea2c5ddafb · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Assessing Automated Prompt Injection Attacks in Agentic Environments The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.986826Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:bfe2ef863dd9706efc6775b85190327e311ec82453fe98a7b2b4d279fdbbc11d

Observation 103ee248-3490-449f-955e-83b53478bf4a · outbound

This paper cites Schmidt, and Florian Bernard.

Assessing Automated Prompt Injection Attacks in Agentic Environments Schmidt, and Florian Bernard

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.940417Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:c4810d46b62bd49cfaf300458c8c3c753b55b18b51e853227f60cf84901d11e5

Observation 4041e4c6-687d-4594-9def-f976606b0e2a · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 32

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:3ec43244d04e178df56014f9ba99b93a3da3aca172c70e30cd8d881806abdcb3

Observation 7f679763-cc3a-4c24-8125-049799287f05 · outbound

This paper cites OET: Optimization-based prompt injection Evaluation Toolkit.

Assessing Automated Prompt Injection Attacks in Agentic Environments OET: Optimization-based prompt injection Evaluation Toolkit

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.899803Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:6aef447ed305e86409fba4b290ccdc756e0d8a6fd8461deda7fca0631d1a85d9

Observation 8c451372-cbde-49be-9b33-d29787b7304e · outbound

This paper cites Pandya, Andrey Labunets, Sicun Gao, and Earlence Fernandes.

Assessing Automated Prompt Injection Attacks in Agentic Environments Pandya, Andrey Labunets, Sicun Gao, and Earlence Fernandes

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.897950Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:a5b256fb11341986a8f4e9d7f0b58d11fc4f28cb3e48ff30244a31c90e3c1838

Observation 64bd7d9f-4c8d-4548-8f2e-014e775cf0b1 · outbound

This paper cites Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks.

Assessing Automated Prompt Injection Attacks in Agentic Environments Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.936259Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:63d60edf983a788c59ad0976cea42b7fd2a83ac875cf1d8c6b6a5f2cc46643be

Observation 3094d42c-5fa7-4ca0-9b85-25eb5f8f8652 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

Assessing Automated Prompt Injection Attacks in Agentic Environments Ignore Previous Prompt: Attack Techniques For Language Models

Reference 36

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.946439Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:5bb6a3a0cd028c85cd3ee4d296cc4a285825c72df1cac0756a96e4c73db2b96a

Observation e400f000-afd5-4203-bad2-5d11f5110455 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 37

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:4f296a201699e07b4bec6f6c1f0e2fa21dfcd44f4ed311da6134ed90933421ee

Observation 7f19c3da-a3ea-410a-acd0-feb6b13e3a5a · outbound

This paper cites 2019.Language Models are Unsupervised Multitask Learners.

Assessing Automated Prompt Injection Attacks in Agentic Environments 2019.Language Models are Unsupervised Multitask Learners

Reference 38

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:8a3b74563328f8ebb13bdc8dc6d6cf727d789240b22becbbe3964e24382a14c5

Observation f43af389-6a73-46f3-b5d8-ed7cc9bfcd94 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 39

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:c398b1c50f6894114373912096df68105d6184604d5ae74c076d95278e6d2a7d

Observation 24aadd62-b927-46f1-8f53-9be0fe420317 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

Assessing Automated Prompt Injection Attacks in Agentic Environments Prompt Injection Attack to Tool Selection in LLM Agents

Reference 40

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.892122Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:ce87c9f62c92c9baaf6bddb8bb9876d0f417f59b422ce97ad5d5a6aaeeaaa473

Observation adcf6bab-1648-43c3-9144-baaf690bee4b · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Assessing Automated Prompt Injection Attacks in Agentic Environments Progent: Securing AI Agents with Privilege Control

Reference 41

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.933633Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:8bce9843bb0627d2e5b82372eafb3f74fe2550a752e25904f039591d4f5f9bb2

Observation 4d2b9350-639a-4886-8b75-7ecdc24e3c81 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Assessing Automated Prompt Injection Attacks in Agentic Environments The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 42

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.930639Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:5434efd11032dca796ca3417c2a181019aac778f8ac93204d2343f8faea60173

Observation 56f0bc90-04e7-4d49-8d53-4db78cc3e317 · outbound

This paper cites https://doi.org/10.

Assessing Automated Prompt Injection Attacks in Agentic Environments https://doi.org/10

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.893714Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:e186d9f0d267cdd78daa28ac3e3d6f22a5670cb9a0836ae6e771d55514496421

Observation 412cde2d-a5bb-4fc3-bbf5-52bb12fd7d8a · outbound

This paper cites AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.945423Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:fedc874284571905081bbb7839e87171ab7388358fd66506ac4ea965932354b1

Observation 6bcc2151-383c-4332-8efe-494d9f1e9bc8 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 45

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:7a4c248dcd54b7a8e91e0a0bfcc8f5c4b279f43baf20ec34c6c4c84aa96e76f1

Observation 5e8bc831-6b73-4c07-ab03-1962a5f8371b · outbound

This paper cites System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective.

Assessing Automated Prompt Injection Attacks in Agentic Environments System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective

Reference 46

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.905749Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:1fe8b2343a9e21df5ef4f958984b73edb527e20ef8dfa189659ad7fa68a1c8ca

Observation cecd6181-85a9-455b-a630-d3d62fb60e05 · outbound

This paper cites Instructional Segment Embedding: Improving LLM Safety with Instruction Hierarchy.

Assessing Automated Prompt Injection Attacks in Agentic Environments Instructional Segment Embedding: Improving LLM Safety with Instruction Hierarchy

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.878883Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:fe14d11af3bb33c473839a55bfc8d353a1991b77266c07a5ffb728174500ff34

Observation cef3c106-1b6a-4445-abf4-79ecc87dd069 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 48

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:3e917b16c896cc4506966a5a418cfdc6055289cd8dc8ce115b49c1d19247c2e2

Observation 781b7d30-9e9f-4625-9836-57e222daef37 · outbound

This paper cites InNetwork and Distributed System Security (NDSS) Symposium.

Assessing Automated Prompt Injection Attacks in Agentic Environments InNetwork and Distributed System Security (NDSS) Symposium

Reference 49

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:ce0861ce3f72507f0ddd7015007f29aa3863c51267d947843fb00df6f71bc552

Observation 953d2702-ab30-4afe-85d9-b7a1cd92ca12 · outbound

This paper cites The rise and potential of large language model based agents: a survey.Sci.

Assessing Automated Prompt Injection Attacks in Agentic Environments The rise and potential of large language model based agents: a survey.Sci

Reference 50

Resolution
verified exact
doi, observed 2026-06-27T12:50:55.668211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:3eb3028181703bb2e1231eeb9240d19ccd5396eda0bd69ee96b5d7447ef431dd

Observation 5fdb94a6-5a64-4702-b374-2c10410c8a18 · outbound

This paper cites Qwen3 Technical Report.

Assessing Automated Prompt Injection Attacks in Agentic Environments Qwen3 Technical Report

Reference 51

Resolution
verified exact
local_arxiv, observed 2026-07-03T06:17:41.876385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2627bf849d0d9182608859cd43b10fc2c59af50eab56af369fe74051d21207b8

Observation 6b9709cd-e6fb-4490-84c9-7de61a943015 · outbound

This paper cites Align- ment under pressure: The case for informed adver- saries when evaluating llm defenses.

Assessing Automated Prompt Injection Attacks in Agentic Environments Align- ment under pressure: The case for informed adver- saries when evaluating llm defenses

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.881445Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:a3fd585d1ac9d2d0f4ebea6f7988a14dd02759ad7586d2a5a5f53671eabc563c

Observation a01fee04-b7c9-4f58-b529-93d3b7eaee0f · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 53

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:9f23ad8b2c17f84809324bdccf06f95a017ff0a9d489935ec6a05615d3cd2036

Observation 8cd79802-fef0-43b2-bd91-eedd15cb25ce · outbound

This paper cites Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1 , pages =.

Assessing Automated Prompt Injection Attacks in Agentic Environments Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1 , pages =

Reference 54

Resolution
metadata mismatch
arxiv_id, observed 2026-06-27T12:50:55.662337Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:bc25aacadc6526f480cd9fab1003b8fd3817c7a77ab1c401eb618961f0690292

Observation eee81a4c-cb9d-4310-b26c-483246ef7e9f · outbound

This paper cites scrolling screenshot.

Assessing Automated Prompt Injection Attacks in Agentic Environments scrolling screenshot

Reference 55

Resolution
malformed identifier
doi_truncated, observed 2026-06-27T12:50:55.673204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2af05a2307525672c326e5a4c8a17dc4b561c0a9391de902265e18917b439430

Observation 844c3d3e-c593-4552-8f5f-a6c9ae4b097d · outbound

This paper cites In: Zong, C., Xia, F., Li, W., Navigli, R.

Assessing Automated Prompt Injection Attacks in Agentic Environments In: Zong, C., Xia, F., Li, W., Navigli, R

Reference 56

Resolution
malformed identifier
doi_truncated, observed 2026-06-27T12:50:55.664837Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:7ea0bb87e5ae32824de6ad8bc48e5b82aeca7a2ea7305fe8410832ef445bdd8e

Observation 6d0b9b79-250c-4f5a-85fe-a20a1e1e19b7 · outbound

This paper cites Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification.

Assessing Automated Prompt Injection Attacks in Agentic Environments Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification

Reference 57

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.874042Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:b80c07e0358952dbbd16759a1f16c27cc931a1e1ce188528b64f6efafbb532b3

Observation 23bc665b-1513-4c67-8076-ab33edaecd18 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

Assessing Automated Prompt Injection Attacks in Agentic Environments RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 58

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T06:17:41.876038Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:15e28b709152b2ecc33e024e0efd18663639e974473862610e5bb822a2dba165

Observation e6297b21-717f-4ad1-9c61-2696e2fe86ce · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Assessing Automated Prompt Injection Attacks in Agentic Environments Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 59

Resolution
metadata mismatch
local_arxiv, observed 2026-07-03T06:17:41.866185Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2a19b975940f8745a4691517be0f9c94b0cc59d3cb87d2cc19a5d057d4bdce03

Observation 5f931fcc-b6b6-407c-8a16-1428f067818c · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 60

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:074d0be19c272b026e579154a49b65b36e54cd248bb4dc2bba0d06e5a6c95d03

Observation 99f0b189-84c0-408d-80d4-78713be86b05 · outbound

This paper cites attacker goals.

Assessing Automated Prompt Injection Attacks in Agentic Environments attacker goals

Reference 61

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.951974Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:a0b37f03bbb34a2dcfe32e21f7688b1fc9f46da4566cf5fc1594ff142e8ce641

Observation 459a8f6a-6c32-4349-a37d-3c9af55680c6 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 62

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:0dc0ff652349160d821b42f59ae32f2ac2457659c6e63ff857311bdddb187455

Observation a9c54ebc-9677-4043-bd78-df150935d3af · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 63

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:83dfe7543cc8a8e3556a498ae1686b30e092f45a021d4a0f17271bfbffa6b53b

Observation 8f66e165-a617-4c3a-9929-c8b0e50c3e06 · outbound

This paper cites [SYSTEM OVERRIDE].

Assessing Automated Prompt Injection Attacks in Agentic Environments [SYSTEM OVERRIDE]

Reference 64

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:65e3a27b0b669226fdd197761e6777f24ff7873f79ea6c9a2b7492a5818083ed

Observation 9930f064-7082-48ed-bc83-5f9f8db30951 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 65

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:666426cbe74872a7fc984e56a7876c4311e627f0e3ee349152b474bab75ca158

Observation 0b84a063-2a97-4256-b3ad-120945476152 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 66

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:1db347cd7a564fb92fb57d7a75f34902258ff187731820e0ba490dc247a70fab

Observation 4b8baf16-e2ef-47e9-b781-c0a8d4613c76 · outbound

This paper cites an unresolved cited work.

Assessing Automated Prompt Injection Attacks in Agentic Environments Unresolved cited work

Reference 67

Resolution
unresolved
no resolver link, observed 2026-06-27T12:47:09.467463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:2a7f3b88f54f7c72aedccdb1a869a01ca1bbd32aac6179075d5f3f3825ac763b

Pith citing papers

No inbound Pith citation observations are available.