{"as_of":"2026-08-09T21:32:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:5fd7d8f8e36958e06cef0cfaa90b6d1630a5b895cec436b4b4b8f60df396a004","coverage":[{"denominator":69,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":69,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-02T01:34:16.274037Z","state":"measured"},{"denominator":69,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":69,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2607.14651/citation-record","integrity":"/paper/2607.14651/integrity","json":"/paper/2607.14651/citation-record.json","paper":"/paper/2607.14651"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2303.08774","last_updated":"2024-03-04T06:01:33Z","snapshot_observed_at":"2026-08-07T07:30:12.213965Z","submitted_at":"2023-03-15T17:15:04Z","title":"GPT-4 Technical Report","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2303.08774","snapshot_observed_at":"2026-08-02T01:34:09.350835Z","title":"Gpt-4 technical report.arXiv preprint arXiv:2303.08774, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.350835Z"},"links":{"cited_paper":"/paper/2303.08774","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:c460fdac9491f8e9ef3d44e4558b4031b2b791e0741ef0d5abc6324da855cc75","observation_id":"efb1544f-4945-4656-b4e8-d9142f5b2b0c","resolution":{"observed_at":"2026-08-02T01:34:09.350835Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2603.29403","last_updated":"2026-04-06T09:33:13Z","snapshot_observed_at":"2026-08-04T08:33:45.534264Z","submitted_at":"2026-03-31T08:05:54Z","title":"Security in LLM-as-a-Judge: A Comprehensive SoK","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2603.29403","snapshot_observed_at":"2026-08-02T01:34:09.462689Z","title":"Security in llm-as-a-judge: A comprehensive sok","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.462689Z"},"links":{"cited_paper":"/paper/2603.29403","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:fdae7b36237182ed261681ef88dbbfd003798908b0d2a35158cb225983a57266","observation_id":"a16b1393-4bed-48d8-a45e-8dfb1a9a37d1","resolution":{"observed_at":"2026-08-02T01:34:09.462689Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:09.573233Z","title":"Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.573233Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:33d330195c854035db007aec8ec74d8321efa5785873390365c18bf430814f09","observation_id":"02f83907-c1ef-45eb-a03b-56d8ef9170db","resolution":{"observed_at":"2026-08-02T01:34:09.573233Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2505.11548","last_updated":"2026-04-09T01:58:59Z","snapshot_observed_at":"2026-07-06T21:25:13.481613Z","submitted_at":"2025-05-15T08:14:58Z","title":"One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.11548","snapshot_observed_at":"2026-08-02T01:34:09.633226Z","title":"One shot dominance: Knowledge poisoning attack on retrieval-augmented generation systems","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.633226Z"},"links":{"cited_paper":"/paper/2505.11548","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:6eb4a31018e8b9460b2a5e12a3a4656768e6ca1303b4ea4254f520557feb91ae","observation_id":"23885b22-d53c-4feb-a2c2-3214076d8a0b","resolution":{"observed_at":"2026-08-02T01:34:09.633226Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:09.702664Z","title":"{StruQ}: Defending against prompt injection with structured queries","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.702664Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:25a8e1e6476e71c2f883037a054f1c9d20490442add86b59c0e7fb178cad25b1","observation_id":"899b38ee-2629-4b4c-b43a-835346108d79","resolution":{"observed_at":"2026-08-02T01:34:09.702664Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.00459","last_updated":"2025-08-02T13:44:03Z","snapshot_observed_at":"2026-08-04T09:37:10.818143Z","submitted_at":"2024-11-01T09:14:21Z","title":"Defense Against Prompt Injection Attack by Leveraging Attack Techniques","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.00459","snapshot_observed_at":"2026-08-02T01:34:09.793732Z","title":"Defense against prompt injection attack by leveraging attack techniques, 2025.URL https://arxiv","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.793732Z"},"links":{"cited_paper":"/paper/2411.00459","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:73e144d9293107be548038a8af5bc0f08bfdceb80cd12878354bdf1341085097","observation_id":"7500767e-94d2-45fa-b1f7-0b16d9e7e005","resolution":{"observed_at":"2026-08-02T01:34:09.793732Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:09.887486Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.887486Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:d40ea7b80816a99729643bd0f5d8f9238b04b57fe7cfe6c604add69eec8740d8","observation_id":"fb56b482-d5b2-45c1-8983-a331492f9308","resolution":{"observed_at":"2026-08-02T01:34:09.887486Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:09.994388Z","title":"Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:09.994388Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:5afcd04555520114df96768731f31d72376944c77932b53f49cf9d1e751592cf","observation_id":"55026f67-9df0-46e6-a444-49abfc50e492","resolution":{"observed_at":"2026-08-02T01:34:09.994388Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.059236Z","title":"Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.059236Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:ba35988cf4b326d8afe2ef2a248b03737e827e04468f630ac057591a46ac7bc1","observation_id":"efc735da-d2f6-41ab-a156-335d952c04aa","resolution":{"observed_at":"2026-08-02T01:34:10.059236Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.167616Z","title":"Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.167616Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:510f20fb7e137212d7f852255423876d124836f3bb290e8d4ee0f9df65ea5801","observation_id":"c120fc0d-d989-4756-b503-0bd6675f7431","resolution":{"observed_at":"2026-08-02T01:34:10.167616Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.271092Z","title":"A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.271092Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:c3d860a73e00f71064c846dd4a5806bcd8f27ad55c4202f4870d5e2ea0053a07","observation_id":"16582e86-54e5-40b3-aaec-3d6c699ee57f","resolution":{"observed_at":"2026-08-02T01:34:10.271092Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.368923Z","title":"Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.368923Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:eeb166384554641803c3fe339a1ae0bf680d644177141118b39bfc73c51c7e88","observation_id":"c0b78879-f55a-49a5-b2f3-82b9cba460b2","resolution":{"observed_at":"2026-08-02T01:34:10.368923Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.453299Z","title":"Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.453299Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:b69faf8f4487a009ded23e085657548a5df4f0a897ae7e771f0ae71cee9c6f0e","observation_id":"b52b464b-ad90-4bc9-a7c8-1f005b15d842","resolution":{"observed_at":"2026-08-02T01:34:10.453299Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2406.12793","last_updated":"2024-07-30T03:58:11Z","snapshot_observed_at":"2026-08-07T13:56:34.167869Z","submitted_at":"2024-06-18T16:58:21Z","title":"ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2406.12793","snapshot_observed_at":"2026-08-02T01:34:10.541857Z","title":"Chatglm: A family of large language models from glm-130b to glm-4 all tools","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.541857Z"},"links":{"cited_paper":"/paper/2406.12793","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:73c424225ed382ae841dbf6b9ac74d2df9638167ef97fa3929d4056a54c810d5","observation_id":"83c2cbb1-59ac-4a51-8518-4b3fc2388519","resolution":{"observed_at":"2026-08-02T01:34:10.541857Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.611404Z","title":"Gemini api documentation","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.611404Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:329034df03a4b107eeea45e79935fb212047e13ef76b99ea0f4f57457a57a69a","observation_id":"8440165c-5f2e-4d67-a00c-9f88677dacda","resolution":{"observed_at":"2026-08-02T01:34:10.611404Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.21783","last_updated":"2024-11-23T23:27:33Z","snapshot_observed_at":"2026-07-06T18:55:11.576666Z","submitted_at":"2024-07-31T17:54:27Z","title":"The Llama 3 Herd of Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.21783","snapshot_observed_at":"2026-08-02T01:34:10.671967Z","title":"The llama 3 herd of models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.671967Z"},"links":{"cited_paper":"/paper/2407.21783","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:786a024337c3c92d34ec6fe0a7c6f2d5c84f1c5ca68fa186750fd7042d91ac1a","observation_id":"059abb50-3316-47b0-a20e-74ededbc0ab1","resolution":{"observed_at":"2026-08-02T01:34:10.671967Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.776015Z","title":"A survey on llm-as-a-judge.The Innovation, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.776015Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:324e5eeeb441d8b7ad43102449b2da45063c145ba4c110a98e69ef45581e9653","observation_id":"2ec1c44d-63e1-4917-8d9f-61c102c43e99","resolution":{"observed_at":"2026-08-02T01:34:10.776015Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.831346Z","title":"The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.831346Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:49ac1c906b530efd53e2970f12d76717020aaefdd65944b85c0ec361142d7c1c","observation_id":"afa007e4-dfd9-4410-9512-eba3d15c3ffb","resolution":{"observed_at":"2026-08-02T01:34:10.831346Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2507.05257","last_updated":"2026-06-28T17:25:01Z","snapshot_observed_at":"2026-08-06T19:26:23.035442Z","submitted_at":"2025-07-07T17:59:54Z","title":"Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2507.05257","snapshot_observed_at":"2026-08-02T01:34:10.887333Z","title":"Evaluating memory in llm agents via incremental multi-turn interactions.arXiv preprint arXiv:2507.05257, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.887333Z"},"links":{"cited_paper":"/paper/2507.05257","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:3a2fa17e481c7e2729f0ada1c72e79aa65cdd3122d0281106e4bcd6310cd756d","observation_id":"0b553bd3-21fc-473c-9d75-8839b2b7c32c","resolution":{"observed_at":"2026-08-02T01:34:10.887333Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:10.951513Z","title":"Retrieval- augmented generation with estimation of source reliability","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.951513Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:1e1ef3dbb6094cd428e4cd130f5d5cb6e0309315252b9b91a8b1ff15e00f234a","observation_id":"82fcbff8-f1e7-481f-964f-cad1ddfca6a6","resolution":{"observed_at":"2026-08-02T01:34:10.951513Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2309.00614","last_updated":"2023-09-04T17:47:36Z","snapshot_observed_at":"2026-07-06T16:13:23.343694Z","submitted_at":"2023-09-01T17:59:44Z","title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.00614","snapshot_observed_at":"2026-08-02T01:34:10.996715Z","title":"Baseline defenses for adversarial attacks against aligned language models.arXiv preprint arXiv:2309.00614, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:10.996715Z"},"links":{"cited_paper":"/paper/2309.00614","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:4c0b1276249faf91c3f3762461c6e15f56f4afc0d9dff3c67adb9a2c7d193f46","observation_id":"02c2249e-63c4-4c56-85f9-fddacacfac84","resolution":{"observed_at":"2026-08-02T01:34:10.996715Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.069663Z","title":"The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.069663Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:7c0a41845de651e5103ca0a9cf2045623b7940dc3376cf5eb1e512d8ced80bc6","observation_id":"82c12249-9869-49e3-af51-8748428f3423","resolution":{"observed_at":"2026-08-02T01:34:11.069663Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.160512Z","title":"Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.160512Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:bef99c50da905dcc27ebf6ae82b90991b8a3de29e316648011ad15d6761d71da","observation_id":"a7e9a3dd-8055-45bc-b155-a4f2613bbed2","resolution":{"observed_at":"2026-08-02T01:34:11.160512Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.223600Z","title":"Memory os of ai agent","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.223600Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:c5dbeddecc5b3b3ace4943fafc14beda76c18c443a70d240ee588dc31dbf8246","observation_id":"4f54209b-39ae-4118-8ba6-1a9d344c7a2e","resolution":{"observed_at":"2026-08-02T01:34:11.223600Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2309.02705","last_updated":"2025-02-04T19:47:09Z","snapshot_observed_at":"2026-07-06T16:15:00.517258Z","submitted_at":"2023-09-06T04:37:20Z","title":"Certifying LLM Safety against Adversarial Prompting","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.02705","snapshot_observed_at":"2026-08-02T01:34:11.280395Z","title":"Certifying llm safety against adversarial prompting.arXiv preprint arXiv:2309.02705, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.280395Z"},"links":{"cited_paper":"/paper/2309.02705","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:e5941014aad808b805bec3fc85d94e1db08375c7341789a06b00a11965d6d993","observation_id":"6ca8f49f-5d36-498f-aaf9-9beb9e4c8a40","resolution":{"observed_at":"2026-08-02T01:34:11.280395Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.16548","last_updated":"2026-06-11T04:00:49Z","snapshot_observed_at":"2026-08-09T15:31:10.880967Z","submitted_at":"2026-04-17T06:28:22Z","title":"A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.16548","snapshot_observed_at":"2026-08-02T01:34:11.340723Z","title":"A survey on the security of long-term memory in llm agents: Toward mnemonic sovereignty.arXiv preprint arXiv:2604.16548, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.340723Z"},"links":{"cited_paper":"/paper/2604.16548","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:784ccc90234d5a4be368e9c4bab0579dd18fba2b1cd871c1b5b805a39a50b649","observation_id":"bf7399f4-f221-4ddf-a3eb-ba67ebea20e0","resolution":{"observed_at":"2026-08-02T01:34:11.340723Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.04434","last_updated":"2024-06-19T06:04:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-05-07T15:56:43Z","title":"DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.04434","snapshot_observed_at":"2026-08-02T01:34:11.398735Z","title":"Deepseek-v2: A strong, economical, and efficient mixture-of-experts language model.arXiv preprint arXiv:2405.04434, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.398735Z"},"links":{"cited_paper":"/paper/2405.04434","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:43d9912ce580f4c11b64d1c9f49258f331fb6a3673c3146ab045e96059d19f05","observation_id":"43fadf10-30fb-4f29-b8d8-6bcd5169fb13","resolution":{"observed_at":"2026-08-02T01:34:11.398735Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.19437","last_updated":"2025-02-18T17:26:38Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-12-27T04:03:16Z","title":"DeepSeek-V3 Technical Report","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.19437","snapshot_observed_at":"2026-08-02T01:34:11.457582Z","title":"Deepseek-v3 technical report.arXiv preprint arXiv:2412.19437, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.457582Z"},"links":{"cited_paper":"/paper/2412.19437","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:3068dcc4dd040c09d7c689b12eac573fd3a98dbd6615e1c8d451f4ad5c513f76","observation_id":"293ca6f7-b29d-41c7-9bfd-71b0100d51d5","resolution":{"observed_at":"2026-08-02T01:34:11.457582Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.522427Z","title":"Formalizing and benchmarking prompt injection attacks and defenses","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.522427Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:831af16bedfdb8b6b18b03e2072bee0623c59ffa61693b96c80ae5f2ff286a5f","observation_id":"87fafa08-223b-4569-84d6-8ec1e5486ee0","resolution":{"observed_at":"2026-08-02T01:34:11.522427Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.614142Z","title":"Datasentinel: A game-theoretic detection of prompt injection attacks","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.614142Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:d0ac784155d350b7471308205f5ec444fb375f2a2309b7125b59f489675e339c","observation_id":"346e16d3-252a-4336-9bdb-d4cc6974ce70","resolution":{"observed_at":"2026-08-02T01:34:11.614142Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2601.11868","last_updated":"2026-01-17T01:29:30Z","snapshot_observed_at":"2026-07-06T22:41:58.373427Z","submitted_at":"2026-01-17T01:29:30Z","title":"Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2601.11868","snapshot_observed_at":"2026-08-02T01:34:11.697836Z","title":"Terminal-bench: Benchmarking agents on hard, realistic tasks in command line interfaces.arXiv preprint arXiv:2601.11868, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.697836Z"},"links":{"cited_paper":"/paper/2601.11868","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:40b80c86ec9dd045a5d27be5feaf3b698e1dfcd3420298d48a6f5a3d991d482e","observation_id":"16249de5-45d1-4d97-b630-bd34820475e4","resolution":{"observed_at":"2026-08-02T01:34:11.697836Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.754997Z","title":"Prompt-guard-86m: A classifier model for detecting prompt attacks","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.754997Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:81bc7b8c19d39bab8185297daca0dfcb14964f68456ea04aee081ad7492b69bd","observation_id":"579581fd-396e-42e2-a371-16af1cc54dd4","resolution":{"observed_at":"2026-08-02T01:34:11.754997Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.819294Z","title":"Towards lifelong dialogue agents via timeline-based memory management","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.819294Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:ee62b6d45468aecae1a3cdcd295de59f445ddc07d1652865b8ca3b4171307612","observation_id":"c7f9ee4d-815c-46a7-9c18-3ea70c40d69e","resolution":{"observed_at":"2026-08-02T01:34:11.819294Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.873849Z","title":"Memgpt: towards llms as operating systems","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.873849Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:387ecd0a2a9e8b857462ae00a73817f69e681d35b7a994e4bb71fe9a4e0d8b79","observation_id":"cc4ee84f-140b-499e-b585-63e6d0cc97db","resolution":{"observed_at":"2026-08-02T01:34:11.873849Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.936398Z","title":"Generative agents: Interactive simulacra of human behavior","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.936398Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:9f1034a556ee871e150f979f7d0d635d86737e971f2ce47cb840dc8611d3ee78","observation_id":"d27938c0-b181-402b-95a3-9da8334ed102","resolution":{"observed_at":"2026-08-02T01:34:11.936398Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:11.976036Z","title":"The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:11.976036Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:1c90f43eaf91681b4b0d3168ecd09f71fb249253d4f88d8234ec5f491debe36b","observation_id":"849b30c4-d735-4143-ba6d-9f15ca477d56","resolution":{"observed_at":"2026-08-02T01:34:11.976036Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:12.062003Z","title":"The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.062003Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:6a245fdb618113082cc6c64074f078381fd4f66d27499c6d4cdbd873a2442bfd","observation_id":"362c6fdb-3e3e-4d7d-b9aa-48d86805e5b1","resolution":{"observed_at":"2026-08-02T01:34:12.062003Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:12.121949Z","title":"Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.121949Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:237db51655a19a82ebb32eabdae085af85bff52cd2ac3eb4c07ca4c00fca9e50","observation_id":"9fd0ca62-34f2-4e1b-808b-0bcfc5047ac1","resolution":{"observed_at":"2026-08-02T01:34:12.121949Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.03684","last_updated":"2024-06-11T19:02:52Z","snapshot_observed_at":"2026-07-06T16:28:22.350574Z","submitted_at":"2023-10-05T17:01:53Z","title":"SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.03684","snapshot_observed_at":"2026-08-02T01:34:12.201286Z","title":"Smoothllm: Defending large language models against jailbreaking attacks.arXiv preprint arXiv:2310.03684, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.201286Z"},"links":{"cited_paper":"/paper/2310.03684","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:989d78f3a2d8c6dd835a950b91725e0cb74e62affd9e7b260fe74f9d740e7f42","observation_id":"52db8d48-94bf-45bb-94b9-deb16acafb7d","resolution":{"observed_at":"2026-08-02T01:34:12.201286Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.11243","last_updated":"2026-05-22T11:17:25Z","snapshot_observed_at":"2026-08-08T03:10:46.351161Z","submitted_at":"2026-02-11T17:32:23Z","title":"Evaluating Memory Structure in LLM Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.11243","snapshot_observed_at":"2026-08-02T01:34:12.248312Z","title":"Evaluating memory structure in llm agents.arXiv preprint arXiv:2602.11243, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.248312Z"},"links":{"cited_paper":"/paper/2602.11243","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:61e2e4ee738402935b2d7f03760b8f38f32470bea81806cfc1f5686e048abb53","observation_id":"e868fda4-cf0d-444b-9bd6-e666565699c6","resolution":{"observed_at":"2026-08-02T01:34:12.248312Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2601.03267","last_updated":"2026-05-01T23:55:43Z","snapshot_observed_at":"2026-08-02T10:52:10.211700Z","submitted_at":"2025-12-19T07:05:38Z","title":"OpenAI GPT-5 System Card","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2601.03267","snapshot_observed_at":"2026-08-02T01:34:12.314535Z","title":"Openai gpt-5 system card.arXiv preprint arXiv:2601.03267, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.314535Z"},"links":{"cited_paper":"/paper/2601.03267","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:7408eb70fec7646ea6315c7554586fb1d32be99f5775a79f7311b810a3d1d9e0","observation_id":"c1b06b0f-111c-49b5-b599-615b192fd5e8","resolution":{"observed_at":"2026-08-02T01:34:12.314535Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:12.426621Z","title":"Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.426621Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:adebf04cd676dc9f79697b6145de2b6bec2564b531c781981bdffae30d7b98c5","observation_id":"10b60ffa-218f-4542-8754-7862088de365","resolution":{"observed_at":"2026-08-02T01:34:12.426621Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:12.590292Z","title":"Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.590292Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:a229a4101094216cdbc9119b7659a53a0ec25dad28e607d04de8ba09e1816329","observation_id":"b71f3248-c4b8-4034-961e-497c3c4634a0","resolution":{"observed_at":"2026-08-02T01:34:12.590292Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:12.917754Z","title":"Membench: Towards more comprehensive evaluation on the memory of llm-based agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:12.917754Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:cc3cc860523c309104087174108968003c8a0d1a6819c4b17d6ec92cc1fb4a9f","observation_id":"a5e3e748-0d2d-4e75-8c52-dd05a557b735","resolution":{"observed_at":"2026-08-02T01:34:12.917754Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.18948","last_updated":"2025-08-29T06:03:42Z","snapshot_observed_at":"2026-08-06T09:59:40.841111Z","submitted_at":"2024-11-28T06:29:46Z","title":"RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.18948","snapshot_observed_at":"2026-08-02T01:34:13.121805Z","title":"Revprag: Revealing poisoning attacks in retrieval-augmented generation through llm activation analysis.arXiv preprint arXiv:2411.18948, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:13.121805Z"},"links":{"cited_paper":"/paper/2411.18948","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:a7a6de886c934b373bbcf492a306cba1d8f606aba423109c2137cffaaba49cf5","observation_id":"92944e81-a041-401b-8bb5-220526e741ed","resolution":{"observed_at":"2026-08-02T01:34:13.121805Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:13.276252Z","title":"In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:13.276252Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:4df30921a6bb99455e9d5a39e593c404916d4103985b954d7998a5a771c90a27","observation_id":"5a3a6e97-80e6-46e1-b767-4a1ac706cc97","resolution":{"observed_at":"2026-08-02T01:34:13.276252Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:13.530907Z","title":"Injecmem: Memory injection attack on llm agent memory systems","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:13.530907Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:95e01048bb1638da070f6ac11025623b42540846503755e5b69c66754e83b213","observation_id":"047b3bea-3a53-43f8-b81a-d196d496aa46","resolution":{"observed_at":"2026-08-02T01:34:13.530907Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:13.705785Z","title":"Injecmem: Memory injection attack on llm agent memory systems","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:13.705785Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:4214fe63777145cf6b0d74828727081633ecfad552f3f6baa373a7bc3e2db98b","observation_id":"80a9a459-ee93-4e71-8f5a-86718df94357","resolution":{"observed_at":"2026-08-02T01:34:13.705785Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:13.873278Z","title":"Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:13.873278Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:8d4e919ed25b8e7d671b65e12262e15c9a2625a5a5b38aa5c7a7bc1cb0357737","observation_id":"df01ad7e-7082-4b78-b5b4-ef1160df2dcb","resolution":{"observed_at":"2026-08-02T01:34:13.873278Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:14.048192Z","title":"Unveiling privacy risks in llm agent memory","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:14.048192Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:4065eae14d16e1265c56e77ff864e41116fed924976580d85efd619668a19f84","observation_id":"c5f1adff-74f3-42b3-8aab-02e0106ad9d2","resolution":{"observed_at":"2026-08-02T01:34:14.048192Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:14.211428Z","title":"Badagent: Inserting and activating backdoor attacks in llm agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:14.211428Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:4d438b6bffdfac01d5f11442ff7257adca046646654dad1bc4e2d90b7d78f8d4","observation_id":"876712ef-fdda-4d18-99f1-5e966dce468f","resolution":{"observed_at":"2026-08-02T01:34:14.211428Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:14.466738Z","title":"A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:14.466738Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:df4afe3c224220ac701d5881c2c018a01a37296d5afbe22f1634ee688227dcb6","observation_id":"c3e2e727-36c2-4e6f-8d96-777960f3524b","resolution":{"observed_at":"2026-08-02T01:34:14.466738Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:14.714004Z","title":"Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:14.714004Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:193a631df78101a1f0117110b567eab4d8892bdbab30bd3847fd4bb278456e9f","observation_id":"82b6d6ba-3647-4f94-b88b-14bc2e4e6090","resolution":{"observed_at":"2026-08-02T01:34:14.714004Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14161","last_updated":"2025-09-10T08:35:19Z","snapshot_observed_at":"2026-08-01T16:27:28.241667Z","submitted_at":"2024-12-18T18:55:40Z","title":"TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.14161","snapshot_observed_at":"2026-08-02T01:34:14.888330Z","title":"Theagentcompany: benchmarking llm agents on consequential real world tasks.arXiv preprint arXiv:2412.14161, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:14.888330Z"},"links":{"cited_paper":"/paper/2412.14161","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:c6594bd76c3578eabef146758495d06b1bc1011784ffd5b9576a6fb3cd52f6d4","observation_id":"6515615e-6a8f-4969-b4d3-e622d0e6c7f9","resolution":{"observed_at":"2026-08-02T01:34:14.888330Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2505.09388","last_updated":"2025-05-14T13:41:34Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-05-14T13:41:34Z","title":"Qwen3 Technical Report","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.09388","snapshot_observed_at":"2026-08-02T01:34:15.040513Z","title":"Qwen3 technical report, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.040513Z"},"links":{"cited_paper":"/paper/2505.09388","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:627ca3ec58490be1306b42f1794d0ef8be4abcb2f677807799dc3561bd09d177","observation_id":"cc7fd6a9-b07f-41db-9747-5a38fc858013","resolution":{"observed_at":"2026-08-02T01:34:15.040513Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.15115","last_updated":"2025-01-03T02:18:21Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-12-19T17:56:09Z","title":"Qwen2.5 Technical Report","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.15115","snapshot_observed_at":"2026-08-02T01:34:15.185128Z","title":"Qwen2.5 technical report, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.185128Z"},"links":{"cited_paper":"/paper/2412.15115","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:1da077261d436c8f602136726926c1f4c0725e7c23e0b381eaf660414dc5953a","observation_id":"7108c89a-f2b8-407b-a2c8-bc0c1e275ef2","resolution":{"observed_at":"2026-08-02T01:34:15.185128Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.324713Z","title":"Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.324713Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:558ba95a6ba5ec06e8ef6b192dd8d1086f036f571164a3dffd9d988b93207daf","observation_id":"b9f9abd6-c324-4231-9331-7a2829d983e2","resolution":{"observed_at":"2026-08-02T01:34:15.324713Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.394297Z","title":"Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.394297Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:27dd09d0dbb3611943de93ebe2f60ce511d14d2556ae8ed0ae8c9ecd4bee74f0","observation_id":"03afb3c0-344e-426a-97f4-dc452860c5c2","resolution":{"observed_at":"2026-08-02T01:34:15.394297Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.468500Z","title":"Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.468500Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:2e64916759cf4cea6a34c02639ca3615cfc469135f1e9a67abc65d815a9d1516","observation_id":"8fb362eb-347a-4ab8-8738-19a31ef43ab1","resolution":{"observed_at":"2026-08-02T01:34:15.468500Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2406.12045","last_updated":"2024-06-17T19:33:08Z","snapshot_observed_at":"2026-08-08T21:08:39.676079Z","submitted_at":"2024-06-17T19:33:08Z","title":"$\\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2406.12045","snapshot_observed_at":"2026-08-02T01:34:15.551445Z","title":"τ-bench: A benchmark for tool-agent- user interaction in real-world domains.arXiv preprint arXiv:2406.12045, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.551445Z"},"links":{"cited_paper":"/paper/2406.12045","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:f6aa552e9ce897a71dbd26139a96a4af50deb688172b065de703e1d643c86fbb","observation_id":"24de91c5-82a8-4523-8f3c-da6301a92f30","resolution":{"observed_at":"2026-08-02T01:34:15.551445Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.637578Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.637578Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:150b72d2d35bba9042147f8724afea07a74654f96a5fdc590a283f470075dc52","observation_id":"e4219fa4-fa52-40af-9e37-97625fbcc785","resolution":{"observed_at":"2026-08-02T01:34:15.637578Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.701912Z","title":"A survey on trustworthy llm agents: Threats and countermeasures","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.701912Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:a417098a49294d8067553e4958824f445980d6b81ad9d364bd178acb52f025c7","observation_id":"f0618914-3d92-438a-abbb-8906a7a2e0f0","resolution":{"observed_at":"2026-08-02T01:34:15.701912Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.780493Z","title":"Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.780493Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:f867a9b171bf0076916bb3b06295afe17de5f6bf3e5b5101895eddc57ce8520d","observation_id":"3cd06f6e-8d1a-4ffe-822c-7ccfb03ddae0","resolution":{"observed_at":"2026-08-02T01:34:15.780493Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.854510Z","title":"Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.854510Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:a5762d59d78f7619d1b21af1a8c8f2cfc3ca0aa29a47fb85354ec43c20721a49","observation_id":"07bce797-16cb-4213-b2ba-8a92532579f1","resolution":{"observed_at":"2026-08-02T01:34:15.854510Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:15.939036Z","title":"Traceback of poisoning attacks to retrieval-augmented generation","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:15.939036Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:7c559ca91cc15570b57da6af735a407f6844a105f4c920cca2c7e6892d21b842","observation_id":"56c1e3e7-ccbc-4a82-9b88-1c7ee188afd6","resolution":{"observed_at":"2026-08-02T01:34:15.939036Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.02644","snapshot_observed_at":"2026-08-02T01:34:16.008911Z","title":"Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents.arXiv preprint arXiv:2410.02644, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:16.008911Z"},"links":{"cited_paper":"/paper/2410.02644","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:55a7e92f7808f97a4b95028d337bb8b8c06b71e09643216fbab35783ae89c0d6","observation_id":"5f5d9c08-2fe4-495f-bbb6-56a7c896eafc","resolution":{"observed_at":"2026-08-02T01:34:16.008911Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13501","last_updated":"2024-04-21T01:49:46Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-04-21T01:49:46Z","title":"A Survey on the Memory Mechanism of Large Language Model based Agents","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.13501","snapshot_observed_at":"2026-08-02T01:34:16.107470Z","title":"A survey on the memory mechanism of large language model based agents, 2024.URL https://arxiv","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:16.107470Z"},"links":{"cited_paper":"/paper/2404.13501","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:9fb663175545c5e9d819f2f9429180626bd9de640af38fbd5dfadfbe2f02c45a","observation_id":"9cc15a56-5bf4-4b03-a668-3bf0cee45f8e","resolution":{"observed_at":"2026-08-02T01:34:16.107470Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-02T01:34:16.185613Z","title":"Judging llm-as-a-judge with mt-bench and chatbot arena","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:16.185613Z"},"links":{"citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:935c407057746dc29f3068a7cc0d8c9d94d3171366eb4732deab22588b678c62","observation_id":"39fe3ff0-ba5a-4d15-be70-f549458eed3c","resolution":{"observed_at":"2026-08-02T01:34:16.185613Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.02623","last_updated":"2026-04-07T14:45:15Z","snapshot_observed_at":"2026-08-05T14:57:29.112440Z","submitted_at":"2026-04-03T01:25:12Z","title":"Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.02623","snapshot_observed_at":"2026-08-02T01:34:16.274037Z","title":"candidate_memory","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-02T01:34:16.274037Z"},"links":{"cited_paper":"/paper/2604.02623","citing_paper":"/paper/2607.14651"},"observation_digest":"sha256:a3d3ab1997c8dcf27f5dae1b8be10562cef3da632e01f7c74832545d11487db6","observation_id":"b2a5ba85-6a29-48de-bcc2-04b52117f3b0","resolution":{"observed_at":"2026-08-02T01:34:16.274037Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2607.14651","last_updated":"2026-07-16T07:19:33Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-08T22:40:25.280463Z","submitted_at":"2026-07-16T07:19:33Z","title":"MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents"},"reference_resolution":{"displayed":69,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":69,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":69},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 69 of 69 outbound references and 0 inbound Pith citation observations for arXiv:2607.14651."}