Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-02T01:34:16.274037Z
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 69 of 69 outbound references and 0 inbound Pith citation observations for arXiv:2607.14651.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-02T01:34:16.274037Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
69 of 69 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation efb1544f-4945-4656-b4e8-d9142f5b2b0c · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents GPT-4 Technical Report
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a16b1393-4bed-48d8-a45e-8dfb1a9a37d1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Security in LLM-as-a-Judge: A Comprehensive SoK
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 02f83907-c1ef-45eb-a03b-56d8ef9170db · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 23885b22-d53c-4feb-a2c2-3214076d8a0b · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 899b38ee-2629-4b4c-b43a-835346108d79 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents {StruQ}: Defending against prompt injection with structured queries
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7500767e-94d2-45fa-b1f7-0b16d9e7e005 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Defense Against Prompt Injection Attack by Leveraging Attack Techniques
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fb56b482-d5b2-45c1-8983-a331492f9308 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 55026f67-9df0-46e6-a444-49abfc50e492 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation efc735da-d2f6-41ab-a156-335d952c04aa · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c120fc0d-d989-4756-b503-0bd6675f7431 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 16582e86-54e5-40b3-aaec-3d6c699ee57f · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c0b78879-f55a-49a5-b2f3-82b9cba460b2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b52b464b-ad90-4bc9-a7c8-1f005b15d842 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 83c2cbb1-59ac-4a51-8518-4b3fc2388519 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8440165c-5f2e-4d67-a00c-9f88677dacda · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Gemini api documentation
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 059abb50-3316-47b0-a20e-74ededbc0ab1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The Llama 3 Herd of Models
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2ec1c44d-63e1-4917-8d9f-61c102c43e99 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on llm-as-a-judge.The Innovation, 2024
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation afa007e4-dfd9-4410-9512-eba3d15c3ffb · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0b553bd3-21fc-473c-9d75-8839b2b7c32c · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82fcbff8-f1e7-481f-964f-cad1ddfca6a6 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Retrieval- augmented generation with estimation of source reliability
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 02c2249e-63c4-4c56-85f9-fddacacfac84 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Baseline Defenses for Adversarial Attacks Against Aligned Language Models
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82c12249-9869-49e3-af51-8748428f3423 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a7e9a3dd-8055-45bc-b155-a4f2613bbed2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4f54209b-39ae-4118-8ba6-1a9d344c7a2e · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory os of ai agent
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6ca8f49f-5d36-498f-aaf9-9beb9e4c8a40 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Certifying LLM Safety against Adversarial Prompting
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bf7399f4-f221-4ddf-a3eb-ba67ebea20e0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 43fadf10-30fb-4f29-b8d8-6bcd5169fb13 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 293ca6f7-b29d-41c7-9bfd-71b0100d51d5 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V3 Technical Report
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 87fafa08-223b-4569-84d6-8ec1e5486ee0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Formalizing and benchmarking prompt injection attacks and defenses
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 346e16d3-252a-4336-9bdb-d4cc6974ce70 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Datasentinel: A game-theoretic detection of prompt injection attacks
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 16249de5-45d1-4d97-b630-bd34820475e4 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 579581fd-396e-42e2-a371-16af1cc54dd4 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Prompt-guard-86m: A classifier model for detecting prompt attacks
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c7f9ee4d-815c-46a7-9c18-3ea70c40d69e · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Towards lifelong dialogue agents via timeline-based memory management
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc4ee84f-140b-499e-b585-63e6d0cc97db · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memgpt: towards llms as operating systems
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d27938c0-b181-402b-95a3-9da8334ed102 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Generative agents: Interactive simulacra of human behavior
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 849b30c4-d735-4143-ba6d-9f15ca477d56 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 362c6fdb-3e3e-4d7d-b9aa-48d86805e5b1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9fd0ca62-34f2-4e1b-808b-0bcfc5047ac1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 52db8d48-94bf-45bb-94b9-deb16acafb7d · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e868fda4-cf0d-444b-9bd6-e666565699c6 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory Structure in LLM Agents
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c1b06b0f-111c-49b5-b599-615b192fd5e8 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents OpenAI GPT-5 System Card
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 10b60ffa-218f-4542-8754-7862088de365 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b71f3248-c4b8-4034-961e-497c3c4634a0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a5e3e748-0d2d-4e75-8c52-dd05a557b735 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Membench: Towards more comprehensive evaluation on the memory of llm-based agents
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 92944e81-a041-401b-8bb5-220526e741ed · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5a3a6e97-80e6-46e1-b767-4a1ac706cc97 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 047b3bea-3a53-43f8-b81a-d196d496aa46 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 80a9a459-ee93-4e71-8f5a-86718df94357 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df01ad7e-7082-4b78-b5b4-ef1160df2dcb · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c5f1adff-74f3-42b3-8aab-02e0106ad9d2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unveiling privacy risks in llm agent memory
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 876712ef-fdda-4d18-99f1-5e966dce468f · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Badagent: Inserting and activating backdoor attacks in llm agents
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c3e2e727-36c2-4e6f-8d96-777960f3524b · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82b6d6ba-3647-4f94-b88b-14bc2e4e6090 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6515615e-6a8f-4969-b4d3-e622d0e6c7f9 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc7fd6a9-b07f-41db-9747-5a38fc858013 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen3 Technical Report
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7108c89a-f2b8-407b-a2c8-bc0c1e275ef2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen2.5 Technical Report
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b9f9abd6-c324-4231-9331-7a2829d983e2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 03afb3c0-344e-426a-97f4-dc452860c5c2 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8fb362eb-347a-4ab8-8738-19a31ef43ab1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24de91c5-82a8-4523-8f3c-da6301a92f30 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e4219fa4-fa52-40af-9e37-97625fbcc785 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unresolved cited work
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f0618914-3d92-438a-abbb-8906a7a2e0f0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on trustworthy llm agents: Threats and countermeasures
Reference 62
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3cd06f6e-8d1a-4ffe-822c-7ccfb03ddae0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 07bce797-16cb-4213-b2ba-8a92532579f1 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 56c1e3e7-ccbc-4a82-9b88-1c7ee188afd6 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Traceback of poisoning attacks to retrieval-augmented generation
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5f5d9c08-2fe4-495f-bbb6-56a7c896eafc · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 66
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9cc15a56-5bf4-4b03-a668-3bf0cee45f8e · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on the Memory Mechanism of Large Language Model based Agents
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 39fe3ff0-ba5a-4d15-be70-f549458eed3c · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Judging llm-as-a-judge with mt-bench and chatbot arena
Reference 68
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b2a5ba85-6a29-48de-bcc2-04b52117f3b0 · outbound
MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
Reference 69
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.