Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-11T23:43:28.649948Z
Paper Citation Record · LEDGER
As of 19 August 2026, this Paper Citation Record lists 68 of 68 outbound references and 0 inbound Pith citation observations for arXiv:2607.03821.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-11T23:43:28.649948Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
68 of 68 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation dca2c3c6-1186-4ef0-a358-88a3e2d19e33 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents React: Synergizing reasoning and acting in language models,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f3df4cbe-6537-4127-942f-ed0f89a3d12b · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Toolformer: Language models can teach themselves to use tools,
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 434c079f-6475-441c-a699-2cbe8987a82f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Chatgpt plugins,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fa066d97-c493-496f-9d38-ce2f24e60067 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents What is microsoft 365 copilot?
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9879d03f-dc8f-4606-a15a-8b8f2f7c63f9 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Model context protocol,
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ead459a0-2ad3-4d4a-8e37-0cb00c4a2fde · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents OpenClaw,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 26126fcb-a15b-4847-83e1-def2d2878b26 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d773cc28-72dc-49d7-ad30-e32eb3087cdf · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Formalizing and benchmarking prompt injection attacks and defenses,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fff67a2c-b9bf-4c3f-bfd6-99c019a402a8 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8d91d6c0-f02f-4ed7-a99c-811fb6efcc2b · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents The dual llm pattern for building ai assistants that can resist prompt injection,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fb69f65f-e882-4682-a943-47ac5c597be1 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 285c5605-fad3-49bf-a22a-ee7a420b26e3 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Defeating Prompt Injections by Design
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ceaed338-de00-46f2-8064-13fc404bdf2f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Securing AI Agents with Information-Flow Control
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5b3d927d-6f33-4b1a-bc75-2ee3e65bea9c · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents PinchBench,
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9de6ba4a-ebbc-4602-aaf6-104919081a38 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Demystifying RCE vulnerabilities in LLM-integrated apps,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c6aca727-7578-49d2-9ab4-51ae5ef4f0f8 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents,
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf24e6b1-21f0-4818-8fea-888e4bea5f7f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents AGENTVIGIL: Automatic black- box red-teaming for indirect prompt injection against LLM agents,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 882da221-d8ed-4050-bd80-7898a459ec4b · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f174e6b4-bfa6-450a-9827-d0adc68dbdaa · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7c95462f-3b54-482b-b0bc-636a2eca3ec3 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Overcoming the retrieval barrier: Indirect prompt injection in the wild for LLM systems,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6e35e460-a5a2-4942-b7f3-4ca0e8c0aea4 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents ObliInjection: Order-oblivious prompt injection attack to LLM agents with multi-source data,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 882e2567-952c-4882-928f-b03f29063928 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered LLM agents,
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4b80a929-e222-4a6c-955f-7360eef6b3f3 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt injection attack to tool selection in LLM agents,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5b945dab-86de-41f1-96b2-ec684a6a57f4 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Available: https://www.ndss-symposium.org/ndss- paper/prompt-injection-attack-to-tool-selection-in-llm-agents/
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 707ad5aa-4db5-4f6b-b2c0-4196f9d91028 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents SpAIware: Uncovering a novel artificial intelligence attack vector through persistent memory in LLM applications and agents,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ae153de8-5f30-405f-820d-7432d7acf9c5 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Memory injection attacks on LLM agents via query-only interaction,
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c5e7cd97-a3b9-4f4a-81e2-0ecb909374ef · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 95266bf2-06bb-47ca-9c77-f4ae6bd75ff0 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents AirGapAgent: Protecting privacy-conscious conversational agents,
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d7fed1e6-e116-497d-bf6d-2365e4c49738 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8c59a475-771f-49d2-810a-9549a5b4cd9f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents ACE: A security architecture for LLM-integrated app systems,
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c92e960b-82e4-47d8-80d9-bb68f10c45a3 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Ignore Previous Prompt: Attack Techniques For Language Models
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ec6240b4-9108-4cff-a289-c1be0999ecda · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Jailbroken: How Does LLM Safety Training Fail?
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4c46affd-ac84-44db-9733-cc5622be7f73 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7249f692-e771-40e3-9be6-ae7690e9d25c · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc8c9450-ca6d-4062-b6bc-fd841cec45ce · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents StruQ: Defending Against Prompt Injection with Structured Queries
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 48306b39-cf50-4f26-a56f-c4788fb4604e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents SecAlign: Defending against prompt injection with preference optimization,
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 618748e7-8306-4956-9a7c-a5ab2d650a3e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Llama Prompt Guard 2,
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 52445bad-392b-4d91-ba0f-481e686e6f3e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents LlamaFirewall: An open source guardrail system for building secure AI agents
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 17091683-d763-4054-a35a-96ecbc467d19 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents DataSentinel: A game-theoretic detection of prompt injection attacks,
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 42c9e19f-6ee2-42ba-a3e7-7a02360d692e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bd9e7f4e-d0a8-4f3d-8535-63d5d01ef2ca · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Attention is all you need to defend against indirect prompt injection attacks in LLMs,
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fa054f62-2795-4ad7-98c8-6a2a4f9a53cc · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a5a2d4c3-80de-4f1d-a254-4f1d356c252e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d0a1c60e-41b9-4762-a575-6d9a2457a781 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents DRIFT: Dynamic rule-based defense with injection isolation for securing LLM agents,
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 759734b3-9ed2-43c2-ac3d-c918a3d29ada · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents ShieldAgent: Shielding agents via verifiable safety policy reasoning,
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d20f98ca-a415-40ce-93d9-2e11d463a69f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dcbd94a6-d90b-4cb3-8eee-1c3c723c46bf · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6fc5b00d-74af-4ecc-8d8f-5b149157070e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2041e5f4-7221-4875-b358-6eff8b6afffe · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Permissive information-flow analysis for large language models,
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation db07bc48-7ebe-4ebe-bc99-76253403e426 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Optimization-based prompt injection attack to LLM-as-a-judge,
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 59e95052-ea3e-4f48-9713-2a54f41b84dc · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents OpenShell: A safe, private runtime for autonomous AI agents,
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 37419af9-99c8-45a0-be4c-ba9465a6fde7 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Webhooks,
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f781b8ee-0b2a-4233-ad64-777a60019a19 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Configuration,
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c76b4449-a21d-4b33-b24d-1e9dcf3bcdc0 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Unresolved cited work
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7bb34070-789e-490d-8c82-77e285f646f2 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents gws: Google Workspace CLI,
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 040810cc-e61f-42db-a35a-2eb2519ed57b · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents GitHub CLI,
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c52f5f5f-d966-4c28-9e05-07c50195f8c3 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 67683645-9ea2-4f0d-ba4b-14659bbfbac6 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Great, now write an article about that: The crescendo multi-turn LLM jailbreak attack,
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f82c38fb-2c7f-4e1f-b78c-42d6d185762f · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents PoisonedRAG: Knowledge corruption attacks to retrieval-augmented generation of large language models,
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b6bcc6d7-2155-4201-8c3c-759ac403c9b1 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f082d9f9-40a2-4a0a-86e3-7febf098484c · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Optimizing agent planning for security and autonomy,
Reference 62
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a214d93e-87bd-495f-ac05-416f1694e95b · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Progent: Securing AI Agents with Privilege Control
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b31e0bc6-77f8-4d07-a83e-586c8767cefd · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Contextual Agent Security: A Policy for Every Purpose
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1092bb99-0554-414c-88d7-2399c63618c8 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents SAGA: A security architecture for governing AI agentic systems,
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf914bd3-be8f-489b-9fce-d95e06632c34 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Claude Code hooks reference,
Reference 66
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cabf711b-7a39-40a9-87f7-6d5411bce605 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Hermes Agent: Hooks,
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 66a8c0fe-fb11-487b-a116-ba50bb894277 · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Make agent defeat agent: Automatic detection of Taint-Style vulnerabilities in LLM-based agents,
Reference 68
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a0779c28-2aac-4ee1-9332-1943b60d6d4e · outbound
DualView: Preventing Indirect Prompt Injection in Personal AI Agents Quarterly report
Reference 69
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.