Pith. sign in

Paper Citation Record · LEDGER

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation

As of 17 August 2026, this Paper Citation Record lists 21 of 21 outbound references and 0 inbound Pith citation observations for arXiv:2607.14006.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.14006 v1

Coverage vector

measured 21 of 21 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T03:05:25.734583Z

measured 21 of 21 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

21 of 21 outbound references displayed

  • verified exact2
  • verified fuzzy0
  • unresolved15
  • parse uncertain0
  • malformed identifier4
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation b0fd21a2-aa6e-400d-9aad-27e460b9709e · outbound

This paper cites NIST Special Publication 800-115, National Institute of Standards and Technology, Gaithersburg, MD, USA (2008).

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation NIST Special Publication 800-115, National Institute of Standards and Technology, Gaithersburg, MD, USA (2008)

Reference 1

Resolution
verified exact
doi, observed 2026-08-02T03:09:07.518731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-02T03:05:23.285132Z digest=sha256:985554056db00215fe8475fc4a0ede0c8d2bb6ae1305502927e536b05e14c4ac

Observation 94d3e682-71e3-44d4-86f9-0d2dbb0f3d69 · outbound

This paper cites https://attack.mitre.org/.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https://attack.mitre.org/

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:23.353021Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:23.353021Z digest=sha256:c9cce1f195dd855feb052f880a96b17d1a0f39d59b2d9fec8d93874bdedc2898

Observation cdae8dbe-77d3-4f34-9465-46e4e6a53e4a · outbound

This paper cites Explaining and Harnessing Adversarial Examples.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation Explaining and Harnessing Adversarial Examples

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:23.454563Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:23.454563Z digest=sha256:3b46ed11a74872fccff8559a1c592cbac9ca59f1d439390a08d8853a21e8257c

Observation 046a0012-3817-4ebe-8502-d26050b90d64 · outbound

This paper cites Pattern Recognition84, 317–331 (2018) https://doi.org/10.1016/ j.patcog.2018.07.023.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation Pattern Recognition84, 317–331 (2018) https://doi.org/10.1016/ j.patcog.2018.07.023

Reference 4

Resolution
malformed identifier
no resolver link, observed 2026-08-02T03:05:23.567592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:23.567592Z digest=sha256:9a2569fded5e6426a36cafced9a14862163509a5deb90933d030d26b00d77086

Observation 28f465da-5057-4b9b-89bb-8ac5ca7594ac · outbound

This paper cites ACM Computing Surveys54(5), 1–36 (2021) https://doi.org/10.1145/3453158.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation ACM Computing Surveys54(5), 1–36 (2021) https://doi.org/10.1145/3453158

Reference 5

Resolution
verified exact
doi, observed 2026-08-02T03:09:07.311126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-02T03:05:23.666588Z digest=sha256:b18c81bc721b4745eb2172a3b067bd726952e714e12ac0682ca8ac538ba0ab7d

Observation 32d76f52-9943-4950-869d-354b462fd77f · outbound

This paper cites https://genai.owasp.org/llm-top-10/.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https://genai.owasp.org/llm-top-10/

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:23.779240Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:23.779240Z digest=sha256:6b057e6c7f8397ddc297c8df81d645c8b573ed08f056ea4bde90a0a04545553c

Observation 5e036853-b3b8-42b1-9532-1ae7456c5462 · outbound

This paper cites IEEE Access14, 12875–12899 (2026) https://doi.org/10.1109/ACCESS.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation IEEE Access14, 12875–12899 (2026) https://doi.org/10.1109/ACCESS

Reference 7

Resolution
malformed identifier
no resolver link, observed 2026-08-02T03:05:23.875555Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:23.875555Z digest=sha256:6ca75c078ad602541f4c8336f4332bfc2e167e0b388703fe80f4a542566b556e

Observation 88c610aa-d019-4410-836f-d137261cef62 · outbound

This paper cites Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.010667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.010667Z digest=sha256:1e7e8a1ba7bf4bc9578114d532f2b7cee5c02d00fda63d7140482349908b1f97

Observation 583b1f33-cf54-4562-a659-c65cb7c1156b · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.126216Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.126216Z digest=sha256:c20cf64ad9b81c1ea19021cb5ed8f09297c307e71c25fa2c510a64ae227169b9

Observation 6033cc9e-4dbb-49a5-82e9-29ce11a953c3 · outbound

This paper cites NIST Trustworthy and Responsible AI NIST AI 600-1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2024).

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation NIST Trustworthy and Responsible AI NIST AI 600-1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2024)

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.251147Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.251147Z digest=sha256:95654384898f1ce5e2ef8595aaf461b785ec2927221c24927472ce33092c0f70

Observation 8f7d0e91-086c-4c2a-9e79-5f5f29f4ea0a · outbound

This paper cites https://atlas.mitre.org/.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https://atlas.mitre.org/

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.350128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.350128Z digest=sha256:a4aaedfdc9c4343a5cc5980196a1c00d1e358e74a34d7ccffbd99605005cdf62

Observation dfb9f66c-8441-4dfd-9a77-d178d150c8dd · outbound

This paper cites https://owasp.org/ www-project-ai-security-and-privacy-guide/.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https://owasp.org/ www-project-ai-security-and-privacy-guide/

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.465501Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.465501Z digest=sha256:ac830a5c3f1b11258d32c8e794a382075c98809a6ae3622624bb930182baeee2

Observation 08304201-c604-455f-bfb4-e6ea1ea72756 · outbound

This paper cites NIST Trustworthy and Responsible AI NIST AI 100-1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2023).

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation NIST Trustworthy and Responsible AI NIST AI 100-1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2023)

Reference 13

Resolution
malformed identifier
no resolver link, observed 2026-08-02T03:05:24.578719Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.578719Z digest=sha256:3bc08d3921154c34291bed24137bd42aca93604bd584c56119826cd5c19cb7a0

Observation 6a209313-9cd5-4bec-a73d-371d58e70340 · outbound

This paper cites https://www.iso.org/standard/77304.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https://www.iso.org/standard/77304

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.694539Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.694539Z digest=sha256:e067a5a8c78b32824ed61cd28defb7a909d62a717abe4869df085abcf15ca010

Observation 4b8aa762-78bd-4f19-a116-7ee7eb0d5fdc · outbound

This paper cites ACM SIGOPS Operating Systems Review22(4), 36–38 (1988) https://doi.org/ 10.1145/54289.871709.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation ACM SIGOPS Operating Systems Review22(4), 36–38 (1988) https://doi.org/ 10.1145/54289.871709

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:24.874180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:24.874180Z digest=sha256:b0d8e46d2fb80bf184c78d2d2c650f2819aa945e6bd7d1615cc4a273f49ebbb9

Observation f39ca71e-5766-4c2c-be3f-c9de7722b1cb · outbound

This paper cites https:// owasp.org/www-project-machine-learning-security-top-10/.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation https:// owasp.org/www-project-machine-learning-security-top-10/

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:25.001264Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.001264Z digest=sha256:8654554e1ba45dcbe66db80a0e376ed35fd08ad0dbc58d16a04f9f1d63f51f80

Observation 0b61ffca-4e28-4df6-9518-66c472225755 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:25.152096Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.152096Z digest=sha256:321c0b1753c0a6d45984ba626135145ecbae8a703afdefe797c7e1707fe90795

Observation e8b83c0e-01d6-46fb-a0d1-a1920db44b3d · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation StruQ: Defending Against Prompt Injection with Structured Queries

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:25.268927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.268927Z digest=sha256:98008102104fa494e67929bb206aecfa31e326021fbab04ac7aba2db93549410

Observation a9800dc2-eb01-4d53-82c4-692fcc9a5262 · outbound

This paper cites Accepted to USENIX Security 2026 (2026).

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation Accepted to USENIX Security 2026 (2026)

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:25.434494Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.434494Z digest=sha256:ac1da5bfa4ec035079a3ab51c2ec401811b5b5044981955b20eb816b5dd80c7b

Observation 1b516cb1-0922-4300-9f8a-cc1c031a9566 · outbound

This paper cites ACM Computing Surveys57(7), 1–36 (2025) https://doi.org/10.1145/3716628 41.

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation ACM Computing Surveys57(7), 1–36 (2025) https://doi.org/10.1145/3716628 41

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T03:05:25.596038Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.596038Z digest=sha256:9e4d7441ff634fac26124fc8fead22ee4faf7b4bfcce35234568b21d4415e2e0

Observation 5f3d8af6-479d-4c18-b49c-9a470ce9249e · outbound

This paper cites NIST Special Publication 800-160, Volume 2, Revision 1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2021).

Rethinking Penetration Testing for AI-Enabled Systems: From Resource Compromise to Behavioral Objective Violation NIST Special Publication 800-160, Volume 2, Revision 1, National Institute of Standards and Technology, Gaithersburg, MD, USA (2021)

Reference 21

Resolution
malformed identifier
no resolver link, observed 2026-08-02T03:05:25.734583Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T03:05:25.734583Z digest=sha256:7bb2f07060c53ecb7ab3d2fc11f26780bf7b6f45ddd77dda57d8be11e431e158

Pith citing papers

No inbound Pith citation observations are available.