Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-11T08:31:36.099368Z
Paper Citation Record · LEDGER
As of 17 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 1 inbound Pith citation observation for arXiv:2607.05120.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-11T08:31:36.099368Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-01T21:47:02.723794Z
A source-named dated measurement, never combined with another source.
Source: cited_works
65 of 65 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation b2ad5205-633a-4304-bb06-898f0114687d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Chatgpt,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3cdf4264-41b7-4ea4-9348-9ff7faea68bd · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Claude in chrome,
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 351f3568-13be-46d0-9267-a3953b926509 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Google gemini cli,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 97975772-6001-48e1-aec3-0a914974cfd0 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Cross-site scripting (xss) attacks and defense mechanisms: classification and state-of-the-art,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3b2be458-3acd-469b-948c-d00a4ccd3913 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Clarke-Salt,SQL injection attacks and defense
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c077783f-db76-4093-989d-96dd4aedb0e2 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d60a3ead-99eb-4f53-8a86-f018ab8c7572 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Injection attack against LLM-integrated Applications
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aa3314d3-c3fa-4027-98e2-0b3b8e754aea · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ff8b731a-f784-41bb-8327-b93aea98fd3d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9710b8c7-0f4b-4c32-b81c-2e2c3e4bf1d3 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents {StruQ}: Defending against prompt injection with structured queries,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f334b0a3-0707-4504-abdb-fe7d55d084ba · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Datasentinel: A game-theoretic detection of prompt injection attacks,
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 98bac509-7806-4ad5-b02d-770b779a9707 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents PromptArmor: Simple yet Effective Prompt Injection Defenses
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c00bd23e-3b1f-4081-9750-42e7b28dca22 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 06284f71-e3be-4aa2-9643-7498b27d9bc9 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Defeating Prompt Injections by Design
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79aa6edc-c976-400b-95cf-2ad149ccc101 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Claude code,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3f9f1c59-cfea-4e3a-baf4-6c49d1628fd8 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Unresolved cited work
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5114a6ac-373b-4460-8ba8-a003bc0c0ba8 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Google antigravity,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a662b706-24e1-4cbf-a36c-3a54aacdad25 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Nanobrowser - open source ai web agent,
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3e6da0e5-bd43-4186-8371-a632b58d4a29 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d8755bb9-9c53-4372-9750-e82163526e73 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Toolformer: Language models can teach themselves to use tools,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8d8b969-6124-4a8c-b340-7c065e00981f · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Unresolved cited work
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4c0522da-0bf0-4a5e-91e8-2fc657b05cae · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3e7a3ec7-f6c3-4933-8cff-e1b0af2da59d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Eia: Environmental injection attack on generalist web agents for privacy leakage,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c500a932-bbf8-43ef-9566-fcbf7d81dba0 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Agentvigil: Generic black-box red-teaming for indirect prompt injection against llm agents,
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 78859368-5870-4106-b258-08ffdc69049c · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Dissecting adversarial robustness of multimodal lm agents,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8fee6ffa-4277-4d24-943c-19a1240eda4e · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Data execution prevention,
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9f837cff-9e22-448a-9604-2bcf81afed4c · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Formalizing and benchmarking prompt injection attacks and defenses,
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2bddc5c5-00cb-4240-8c74-b0a1bac283e8 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Delimiters won’t save you from prompt injection,
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ef129ad2-b293-43bf-9f7c-a35baf8c6c3e · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 92a8f9da-1d35-44ad-b36a-a5ac21848e4d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Chatgpt atlas,
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 31ebb0e0-1170-4d19-a53a-04238dd915f7 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Pytorch: An imperative style, high-performance deep learning library,
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 87286852-4156-48ac-803e-41264a591113 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents {TensorFlow}: a system for {Large-Scale} machine learning,
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2ce2515c-9779-466d-bebe-c2fa8720e388 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Github cli,
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 76d6bedb-24c4-41dc-b409-4e2bd9f4d459 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Github mcp server,
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d60d25a4-17a4-4dc0-9138-abd2ae1e2de6 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Keeping llms aligned after fine-tuning: The crucial role of prompt templates,
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f3188ae9-53d7-42bf-b598-c3578230d089 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents LlamaFirewall: An open source guardrail system for building secure AI agents
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9eb4f866-d0b6-498b-bfa0-d98b81f35732 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Design Patterns for Securing LLM Agents against Prompt Injections
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0528cdd3-554e-4a5d-a767-ace6916c8319 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems,
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0735d94d-5e06-4a47-831e-1591fd8354c2 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents ACE: A Security Architecture for LLM-Integrated App Systems
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5dd1713b-be86-47b1-9b78-f801b4b96b6d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Progent: Securing AI Agents with Privilege Control
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1a059039-8f7b-4ab3-b758-2b3dd2bcdabf · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Contextual agent security: A policy for every purpose,
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f6c6e136-9b37-4948-82df-e6098eaf48e9 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Towards automating data access permissions in ai agents,
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 51b73398-6d18-4c87-8c88-ccc3cad9cf4e · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents The dual llm pattern for building ai assistants that can resist prompt injection,
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4e8ba3a0-d568-4feb-90df-954b596d3b68 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 61fdd182-957a-42bf-a2e4-f3bd96768d0a · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Securing AI Agents with Information-Flow Control
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 56c5da6e-2985-40fb-8e97-bf2b4794304f · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Permissive information-flow analysis for large language models,
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 35e2a5b8-66c6-43c9-92ad-54bb216f8e7f · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents How good are llms at processing tool outputs?
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ed286d7a-9d26-4d38-b8a8-6d92d56097fb · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Llama prompt guard 2,
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d3b265e4-301c-4cfb-9d66-2d77b8258018 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents React: Synergizing reasoning and acting in language models,
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a486fd7e-83da-4857-ac0c-66e3dfecfcc9 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Great, now write an article about that: The crescendo {Multi-Turn}{LLM} jailbreak attack,
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation de4602ce-ebe3-40e8-91ec-10029032a4dd · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Universal adversarial triggers for attacking and analyzing NLP,
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 74448141-3b7a-41fc-ad64-a5e8e28087c0 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Autodan: Generating stealthy jailbreak prompts on aligned large language models,
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 06a654c9-40ef-48c7-8130-60f5110a5ffc · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Open sesame! universal black- box jailbreaking of large language models,
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f4f301ce-b07e-4ab4-8cb8-6de2ca6b356d · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Jailbreak Attacks and Defenses Against Large Language Models: A Survey
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41b0f911-0f95-4b49-9d8c-f76431c2a69b · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Pleak: Prompt leaking attacks against large language model applications,
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0833b53e-7bac-4fb6-bbf1-bf3d0321e259 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Ignore Previous Prompt: Attack Techniques For Language Models
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e8475828-cbb4-4a10-93df-e90e0ecbd824 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Effective Prompt Extraction from Language Models
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 51add82a-8060-4348-bbd4-2cf44c449ae3 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Les dissonances: Cross-tool harvesting and polluting in multi-tool empowered llm agents,
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc151831-632a-4836-9ca5-43723a7c1b6e · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Task injection – exploiting agency of autonomous ai agents,
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4aa1d9cf-8616-4beb-9bf5-cd2622676114 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Optimization-based prompt injection attack to llm-as-a-judge,
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8b0dca96-adff-4126-acdb-c100e9781103 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases,
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df324fb1-a787-4af5-b498-94d104213b04 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 62
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6709bc17-544d-4bfc-aab3-6a02e291add6 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Benchmarking and defending against indirect prompt injection attacks on large language models,
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b14e7e5c-79ac-4608-8271-2138dfdce6fd · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents WASP: Benchmarking web agent security against prompt injection attacks,
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b258b0a1-5a87-4228-ab68-c25d4736f567 · outbound
Agent Data Injection Attacks are Realistic Threats to AI Agents Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 19955a6f-658c-4b33-a1af-67c02f4b52e5 · inbound
Refusal is Not Safety! Benchmarking Latent Safety Risks of LLM-Driven Content Humorization Agent Data Injection Attacks are Realistic Threats to AI Agents
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.