Pith. sign in

Paper Citation Record · LEDGER

Agent Data Injection Attacks are Realistic Threats to AI Agents

As of 17 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 1 inbound Pith citation observation for arXiv:2607.05120.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.05120 v1

Coverage vector

measured 65 of 65 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-11T08:31:36.099368Z

measured 66 of 66 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-01T21:47:02.723794Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

65 of 65 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved65
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation b2ad5205-633a-4304-bb06-898f0114687d · outbound

This paper cites Chatgpt,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Chatgpt,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:4630a663c0796407e6ce8d83bb14ce1490fefa1c5ed09c970f91e1776af29afc

Observation 3cdf4264-41b7-4ea4-9348-9ff7faea68bd · outbound

This paper cites Claude in chrome,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Claude in chrome,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:6577ebe148412dfb5a00d85f3d3ec32f18e306765f6d79d3f09a0b8d29d1db89

Observation 351f3568-13be-46d0-9267-a3953b926509 · outbound

This paper cites Google gemini cli,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Google gemini cli,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:74428d93aca0764958a4180dcc7acf68c920a71ad88f193119ce6113dc56489c

Observation 97975772-6001-48e1-aec3-0a914974cfd0 · outbound

This paper cites Cross-site scripting (xss) attacks and defense mechanisms: classification and state-of-the-art,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Cross-site scripting (xss) attacks and defense mechanisms: classification and state-of-the-art,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:0d0792ae69d0fb478c96accf73c5d8ff1190b92a2ef1ad96b137afc25810fcb4

Observation 3b2be458-3acd-469b-948c-d00a4ccd3913 · outbound

This paper cites Clarke-Salt,SQL injection attacks and defense.

Agent Data Injection Attacks are Realistic Threats to AI Agents Clarke-Salt,SQL injection attacks and defense

Reference 5

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:0a693ffdd6920c00e92696dee7421b4ff511402c602622d8da5e0c64a3677a76

Observation c077783f-db76-4093-989d-96dd4aedb0e2 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:e40addfb0b6803da005913be73c3ea531723545f6dc9edcb3ea8a7748a189057

Observation d60a3ead-99eb-4f53-8a86-f018ab8c7572 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Injection attack against LLM-integrated Applications

Reference 7

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:d0fdda46259c8a0ba0df0213e54925b6fe06a326a10e74751559613617a26021

Observation aa3314d3-c3fa-4027-98e2-0b3b8e754aea · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

Agent Data Injection Attacks are Realistic Threats to AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5ab2b98b1c4135c0787a40e42e232ec4529df678e6b9959d881047f95ccfcf01

Observation ff8b731a-f784-41bb-8327-b93aea98fd3d · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Agent Data Injection Attacks are Realistic Threats to AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:ff256309e5eb686ccc08637e5fa2405eb679f5228fd0db7ec897ae3b7375192d

Observation 9710b8c7-0f4b-4c32-b81c-2e2c3e4bf1d3 · outbound

This paper cites {StruQ}: Defending against prompt injection with structured queries,.

Agent Data Injection Attacks are Realistic Threats to AI Agents {StruQ}: Defending against prompt injection with structured queries,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5d41adc8c7bb0cfc7f5ec5431f7cf9b35dd609efe79467ab983a1f4755af7b6d

Observation f334b0a3-0707-4504-abdb-fe7d55d084ba · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Datasentinel: A game-theoretic detection of prompt injection attacks,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:d90f5702206d431cdf39e44f02643249db0546ddb20dd291f635a6edda6523e5

Observation 98bac509-7806-4ad5-b02d-770b779a9707 · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

Agent Data Injection Attacks are Realistic Threats to AI Agents PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 12

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:30cc97e6f4d501984953ed3b71855538fbbb285445486f4ca242ce62766e7743

Observation c00bd23e-3b1f-4081-9750-42e7b28dca22 · outbound

This paper cites Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents.

Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:07b1b40e148b8a3177ea1c431215d600c498722cf62a68f6829744c2b1968ae9

Observation 06284f71-e3be-4aa2-9643-7498b27d9bc9 · outbound

This paper cites Defeating Prompt Injections by Design.

Agent Data Injection Attacks are Realistic Threats to AI Agents Defeating Prompt Injections by Design

Reference 14

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:95a880d64d2bf76ca85aee82b61ddd90c106ef1d03c3a5795146545d85918939

Observation 79aa6edc-c976-400b-95cf-2ad149ccc101 · outbound

This paper cites Claude code,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Claude code,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:3f434e1e92b27fe5b9b1f9790c66bcceb2f9126cbe32eb58bd82b1cc5b6899ef

Observation 3f9f1c59-cfea-4e3a-baf4-6c49d1628fd8 · outbound

This paper cites an unresolved cited work.

Agent Data Injection Attacks are Realistic Threats to AI Agents Unresolved cited work

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:accdbe6f5f6b2890d6828060247753bab871f01293c0c9d5a9b64d3a24ef381a

Observation 5114a6ac-373b-4460-8ba8-a003bc0c0ba8 · outbound

This paper cites Google antigravity,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Google antigravity,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:586865b76087ce17e57d8a6be8a61633fc1f769221e7ea705842777b3b625363

Observation a662b706-24e1-4cbf-a36c-3a54aacdad25 · outbound

This paper cites Nanobrowser - open source ai web agent,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Nanobrowser - open source ai web agent,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5a8d872a44564c87ad58624f36ae933dbeacacfb0e29db5c5647133bf1cf798b

Observation 3e6da0e5-bd43-4186-8371-a632b58d4a29 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:127a3c44846d6fc26a4a4843825e10d808848369f2559bcf796e06f557f4e924

Observation d8755bb9-9c53-4372-9750-e82163526e73 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Toolformer: Language models can teach themselves to use tools,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:0b6d1e03a1f3e9d351008e2cfc993af090bdfb24e7672209105f4c5a6433aed5

Observation b8d8b969-6124-4a8c-b340-7c065e00981f · outbound

This paper cites an unresolved cited work.

Agent Data Injection Attacks are Realistic Threats to AI Agents Unresolved cited work

Reference 21

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:6f28bfa004422b9b4aa0d55335a6c875ba3473726332fbb9923060307560cd8b

Observation 4c0522da-0bf0-4a5e-91e8-2fc657b05cae · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 22

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:17cf14a538022bb9810ad341f46ea8277186aa741c059a4a3d66ac51de67a1eb

Observation 3e7a3ec7-f6c3-4933-8cff-e1b0af2da59d · outbound

This paper cites Eia: Environmental injection attack on generalist web agents for privacy leakage,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Eia: Environmental injection attack on generalist web agents for privacy leakage,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:be384d27e6d4ff771f04f84a36e57d12be906f4cc2e9955380100edfbadbc3bc

Observation c500a932-bbf8-43ef-9566-fcbf7d81dba0 · outbound

This paper cites Agentvigil: Generic black-box red-teaming for indirect prompt injection against llm agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Agentvigil: Generic black-box red-teaming for indirect prompt injection against llm agents,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:12b9ffc5f44c145b9aa030067f3c497188e2016458107610344491b99ad6d947

Observation 78859368-5870-4106-b258-08ffdc69049c · outbound

This paper cites Dissecting adversarial robustness of multimodal lm agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Dissecting adversarial robustness of multimodal lm agents,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:952c35757bd9baab27ecde84c5fa11d1e6b704bdf8f684f714a03c4a0127e352

Observation 8fee6ffa-4277-4d24-943c-19a1240eda4e · outbound

This paper cites Data execution prevention,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Data execution prevention,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:44369e4eb460ad923697089b3395036f291ea7d2cba27c58f6978cc104c86e61

Observation 9f837cff-9e22-448a-9604-2bcf81afed4c · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Formalizing and benchmarking prompt injection attacks and defenses,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:a69a09e5b50a5a3b7fd76b678fa4f408007126d22af767dfb1d19b59478a8602

Observation 2bddc5c5-00cb-4240-8c74-b0a1bac283e8 · outbound

This paper cites Delimiters won’t save you from prompt injection,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Delimiters won’t save you from prompt injection,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:f1ad0a34c5521afaba44de5a5129d16154882eb4f68407f990b30ec75d93ab66

Observation ef129ad2-b293-43bf-9f7c-a35baf8c6c3e · outbound

This paper cites Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous.

Agent Data Injection Attacks are Realistic Threats to AI Agents Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous

Reference 29

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:d1dec96f7c0d784c11e2ed8f96d2b04369eae2352003790beced3c0a8455ffd9

Observation 92a8f9da-1d35-44ad-b36a-a5ac21848e4d · outbound

This paper cites Chatgpt atlas,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Chatgpt atlas,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:262975add65aa56fcb1ef61cc681f1f127c8953244a529ad4e142e79881a203c

Observation 31ebb0e0-1170-4d19-a53a-04238dd915f7 · outbound

This paper cites Pytorch: An imperative style, high-performance deep learning library,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Pytorch: An imperative style, high-performance deep learning library,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:ec423f5a73212e504e6ddd8887c620089d0def4e8c2dbf8b8a58389c638bfed9

Observation 87286852-4156-48ac-803e-41264a591113 · outbound

This paper cites {TensorFlow}: a system for {Large-Scale} machine learning,.

Agent Data Injection Attacks are Realistic Threats to AI Agents {TensorFlow}: a system for {Large-Scale} machine learning,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:ce88b04f18f839faae9e7b8d9088c4e947929adb561a4d711003c8fcb7ad2555

Observation 2ce2515c-9779-466d-bebe-c2fa8720e388 · outbound

This paper cites Github cli,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Github cli,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:61ca58e0955bb62d318ad5d6deb81ef6122ffad1ff0dfc2b3d96b1096d3cb12c

Observation 76d6bedb-24c4-41dc-b409-4e2bd9f4d459 · outbound

This paper cites Github mcp server,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Github mcp server,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:bff8be730bfc1f903ce1bbe3198191409fa848840da84fc758ac3e7aee46204f

Observation d60d25a4-17a4-4dc0-9138-abd2ae1e2de6 · outbound

This paper cites Keeping llms aligned after fine-tuning: The crucial role of prompt templates,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Keeping llms aligned after fine-tuning: The crucial role of prompt templates,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:6438ca97836184e368b95905293fd03a3942c18be4b650799c77eb23bba9601d

Observation f3188ae9-53d7-42bf-b598-c3578230d089 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

Agent Data Injection Attacks are Realistic Threats to AI Agents LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 36

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:2510f9686ad273344111e9fc19a4bce78694c5bd1879b41932eda72c79764b59

Observation 9eb4f866-d0b6-498b-bfa0-d98b81f35732 · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

Agent Data Injection Attacks are Realistic Threats to AI Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 37

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:c3bbd81ce488cbc01358b387a4d5bc65e6a60b71a28a292120a1e705eff6d938

Observation 0528cdd3-554e-4a5d-a767-ace6916c8319 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems,.

Agent Data Injection Attacks are Realistic Threats to AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:8878b35ac06895a629f7b043f3e7a3abf2cd4ca26202c99caadaf1675ddce5a2

Observation 0735d94d-5e06-4a47-831e-1591fd8354c2 · outbound

This paper cites ACE: A Security Architecture for LLM-Integrated App Systems.

Agent Data Injection Attacks are Realistic Threats to AI Agents ACE: A Security Architecture for LLM-Integrated App Systems

Reference 39

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:8cf6ffc4df9c1304e3e62342b1b51c4ebdd10016d005ecf31a0c6e78f6674b35

Observation 5dd1713b-be86-47b1-9b78-f801b4b96b6d · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Agent Data Injection Attacks are Realistic Threats to AI Agents Progent: Securing AI Agents with Privilege Control

Reference 40

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:0d237245ad94399b79aa60119a36ba9a39c241796fb3df25f6fcfa768b0dab89

Observation 1a059039-8f7b-4ab3-b758-2b3dd2bcdabf · outbound

This paper cites Contextual agent security: A policy for every purpose,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Contextual agent security: A policy for every purpose,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:303d731363146a7553d2462697beff6e5cf505adac5b4c0be6d06d33c0afb084

Observation f6c6e136-9b37-4948-82df-e6098eaf48e9 · outbound

This paper cites Towards automating data access permissions in ai agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Towards automating data access permissions in ai agents,

Reference 42

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:22db54c080c1cf3c683d7b175b9cf51784ddbef9abcd66eae181ce8d57446079

Observation 51b73398-6d18-4c87-8c88-ccc3cad9cf4e · outbound

This paper cites The dual llm pattern for building ai assistants that can resist prompt injection,.

Agent Data Injection Attacks are Realistic Threats to AI Agents The dual llm pattern for building ai assistants that can resist prompt injection,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5ca289feb59a52e2de9072de3900dd7698dfb6fce276e019b48c1fd1df6ce515

Observation 4e8ba3a0-d568-4feb-90df-954b596d3b68 · outbound

This paper cites System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective.

Agent Data Injection Attacks are Realistic Threats to AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective

Reference 44

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:ccd7a4da34da618972faeff9ff0ed0b28a9be75ead6f7a63a1922b9967cf7ae3

Observation 61fdd182-957a-42bf-a2e4-f3bd96768d0a · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Agent Data Injection Attacks are Realistic Threats to AI Agents Securing AI Agents with Information-Flow Control

Reference 45

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:3e1e981b0eac63b48732b14c91ca405c97f4888f5f92e81eefad32cb8147e8a8

Observation 56c5da6e-2985-40fb-8e97-bf2b4794304f · outbound

This paper cites Permissive information-flow analysis for large language models,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Permissive information-flow analysis for large language models,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:176302cbb5a65649004591987f95fa04b20bb288c41cb70fb3841507b8925f64

Observation 35e2a5b8-66c6-43c9-92ad-54bb216f8e7f · outbound

This paper cites How good are llms at processing tool outputs?.

Agent Data Injection Attacks are Realistic Threats to AI Agents How good are llms at processing tool outputs?

Reference 47

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:743454e057623af36c99526c1705c1d31c7e6e75c415d954f248565c47578cc1

Observation ed286d7a-9d26-4d38-b8a8-6d92d56097fb · outbound

This paper cites Llama prompt guard 2,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Llama prompt guard 2,

Reference 48

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:3524c27e9cfdcdc2bd7d9e1138745ce5a64eac92986ea08d8330e9ee2d45e05b

Observation d3b265e4-301c-4cfb-9d66-2d77b8258018 · outbound

This paper cites React: Synergizing reasoning and acting in language models,.

Agent Data Injection Attacks are Realistic Threats to AI Agents React: Synergizing reasoning and acting in language models,

Reference 49

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:de941e4c5d2b98d624e67715180a88de883de48de1fea5348692ff2adffdaf62

Observation a486fd7e-83da-4857-ac0c-66e3dfecfcc9 · outbound

This paper cites Great, now write an article about that: The crescendo {Multi-Turn}{LLM} jailbreak attack,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Great, now write an article about that: The crescendo {Multi-Turn}{LLM} jailbreak attack,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:dd2ccd5417a7bbb072efe0f5edd7a606672aea4597cc756913fe84e6fe273c6a

Observation de4602ce-ebe3-40e8-91ec-10029032a4dd · outbound

This paper cites Universal adversarial triggers for attacking and analyzing NLP,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Universal adversarial triggers for attacking and analyzing NLP,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:7e41d4f329db4259d1754479fa4bf057711e5a11d9de67cc8c783e119ca776c8

Observation 74448141-3b7a-41fc-ad64-a5e8e28087c0 · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Autodan: Generating stealthy jailbreak prompts on aligned large language models,

Reference 52

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:4e5717a82de7915a904c013bff935cdc934b17a35f73d919faf2e2e667b525bc

Observation 06a654c9-40ef-48c7-8130-60f5110a5ffc · outbound

This paper cites Open sesame! universal black- box jailbreaking of large language models,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Open sesame! universal black- box jailbreaking of large language models,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5547e4e2aa2274bc99ae3828dde5e955aa7724b44aba640bbe36c0b28bf76007

Observation f4f301ce-b07e-4ab4-8cb8-6de2ca6b356d · outbound

This paper cites Jailbreak Attacks and Defenses Against Large Language Models: A Survey.

Agent Data Injection Attacks are Realistic Threats to AI Agents Jailbreak Attacks and Defenses Against Large Language Models: A Survey

Reference 54

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:25558a9b897c5c26c4c0f0b748683b13da654e465e85834f3ea7f72ec7eb85fa

Observation 41b0f911-0f95-4b49-9d8c-f76431c2a69b · outbound

This paper cites Pleak: Prompt leaking attacks against large language model applications,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Pleak: Prompt leaking attacks against large language model applications,

Reference 55

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:2f8cf0d613dfd4ae50c40b15faa3f1a27375470daea207f77455d067f6d8836f

Observation 0833b53e-7bac-4fb6-bbf1-bf3d0321e259 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

Agent Data Injection Attacks are Realistic Threats to AI Agents Ignore Previous Prompt: Attack Techniques For Language Models

Reference 56

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:8f49db63923afae8e0e35a256a4287c53ce6cc7344109443fcc3779559ade6db

Observation e8475828-cbb4-4a10-93df-e90e0ecbd824 · outbound

This paper cites Effective Prompt Extraction from Language Models.

Agent Data Injection Attacks are Realistic Threats to AI Agents Effective Prompt Extraction from Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5178c57036dab5f20a1e918b8a7cde7f4cd40850759cb0a2ac19e7c5f104e2f7

Observation 51add82a-8060-4348-bbd4-2cf44c449ae3 · outbound

This paper cites Les dissonances: Cross-tool harvesting and polluting in multi-tool empowered llm agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Les dissonances: Cross-tool harvesting and polluting in multi-tool empowered llm agents,

Reference 58

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:c3cb764fb1f86843abc46459927a2799ccd01741a2d188f43e04b5301a6d2e87

Observation cc151831-632a-4836-9ca5-43723a7c1b6e · outbound

This paper cites Task injection – exploiting agency of autonomous ai agents,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Task injection – exploiting agency of autonomous ai agents,

Reference 59

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:799da2ae162e8e2458f72345ca1343a8e2347461fe5cdec20cef27456ae8ef8b

Observation 4aa1d9cf-8616-4beb-9bf5-cd2622676114 · outbound

This paper cites Optimization-based prompt injection attack to llm-as-a-judge,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Optimization-based prompt injection attack to llm-as-a-judge,

Reference 60

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:14ec63eeabfec81642c68b772b938ced9e47af45953d30b0bddc157fb4dac7c8

Observation 8b0dca96-adff-4126-acdb-c100e9781103 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases,

Reference 61

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:54213c0eb6ac1c43f184c6e55b3520a1be512eb6145caffe4b38f9d05ddb4372

Observation df324fb1-a787-4af5-b498-94d104213b04 · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

Agent Data Injection Attacks are Realistic Threats to AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 62

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:7d55e28d0917738441764655a733e7c1b3f6b3e76132d29acb4e405be2dec1d3

Observation 6709bc17-544d-4bfc-aab3-6a02e291add6 · outbound

This paper cites Benchmarking and defending against indirect prompt injection attacks on large language models,.

Agent Data Injection Attacks are Realistic Threats to AI Agents Benchmarking and defending against indirect prompt injection attacks on large language models,

Reference 63

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:33014a2f76e817aafbcc7f2267ae08a9df352affdd5b9e62221aad24a3b8d005

Observation b14e7e5c-79ac-4608-8271-2138dfdce6fd · outbound

This paper cites WASP: Benchmarking web agent security against prompt injection attacks,.

Agent Data Injection Attacks are Realistic Threats to AI Agents WASP: Benchmarking web agent security against prompt injection attacks,

Reference 64

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:6ded162e89887f1ef174cb65583376eac0f1e366c3debdc8c071cbb0eb08c0db

Observation b258b0a1-5a87-4228-ab68-c25d4736f567 · outbound

This paper cites Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening.

Agent Data Injection Attacks are Realistic Threats to AI Agents Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening

Reference 65

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:099d3396e2cb8824b3c3470d2d1820ad49a23d31ad84bbd8a7e463cd5055519b

Pith citing papers

Observation 19955a6f-658c-4b33-a1af-67c02f4b52e5 · inbound

Refusal is Not Safety! Benchmarking Latent Safety Risks of LLM-Driven Content Humorization cites this paper.

Refusal is Not Safety! Benchmarking Latent Safety Risks of LLM-Driven Content Humorization Agent Data Injection Attacks are Realistic Threats to AI Agents

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T21:47:02.723794Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T21:47:02.723794Z digest=sha256:97e980bd10aea72765d16931f9feae82d425cbd4680a993632a61b984ad324f7