Pith. sign in

Paper Citation Record · LEDGER

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework

As of 12 August 2026, this Paper Citation Record lists 34 of 34 outbound references and 0 inbound Pith citation observations for arXiv:2607.19361.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.19361 v1

Coverage vector

measured 34 of 34 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T12:28:45.332809Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

34 of 34 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved34
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 5d28862d-fae3-4ee1-a886-4824d2dfb5ac · outbound

This paper cites CoSafe: A collection of multi-turn LLM conversations for safety evaluation.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework CoSafe: A collection of multi-turn LLM conversations for safety evaluation

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.252710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.252710Z digest=sha256:5182b8658735d540bb4f7665a3e631f8da70cb095f6f4e6bba2817ebc51962c6

Observation 19a12802-f880-4117-8fec-1909f2b22093 · outbound

This paper cites Guide for mapping types of information and information systems to security categories.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Guide for mapping types of information and information systems to security categories

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.464316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.464316Z digest=sha256:1077c8d5618b1a6e8c94db93798706e4731c6aca9ab29a3aab8f8e94bb7136e9

Observation df5dd028-2dfc-48b2-8fc6-5d4bffc19e09 · outbound

This paper cites HarmBench: A standardized evaluation framework for automated red teaming and robust refusal.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework HarmBench: A standardized evaluation framework for automated red teaming and robust refusal

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.697918Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.697918Z digest=sha256:ddf7edda2b9793043b2009b0cd94663b35b42851122f614224d638372ab86210

Observation 56207b61-97b9-4cad-8147-8521e1da08f7 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.764504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.764504Z digest=sha256:8fec1d5420b3f1edee4509ef6d7e0672dbe452279ddda8fdc5b6b1d9e463aaac

Observation 68d59a61-f47f-4f7e-a60f-00c156878653 · outbound

This paper cites Universal adver- sarial triggers for attacking and analyzing NLP.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Universal adver- sarial triggers for attacking and analyzing NLP

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.900976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.900976Z digest=sha256:d645e25c928a39b94d79339631a7904f6ad87171090966f40a6dca759832fbec

Observation c0e4edb4-4065-428e-b999-93282e9b7087 · outbound

This paper cites Do Anything Now.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Do Anything Now

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.027602Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.027602Z digest=sha256:cd505be30de38774e3aabd1ac305d144d95e4dec283da1e6e4e91f949e27341f

Observation 864be882-bf02-438c-a84d-4e2ad5157d04 · outbound

This paper cites Jailbroken: How does LLM safety training fail? InAdvances in Neural Information Processing Systems, volume 36, pages 71988– 72006.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Jailbroken: How does LLM safety training fail? InAdvances in Neural Information Processing Systems, volume 36, pages 71988– 72006

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.189772Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.189772Z digest=sha256:147baaee9e09ce494fb7c57c3fad48ac3469f3fd97e659254c9c557686ce9f57

Observation 25212952-a382-4def-92cd-49464773fd24 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Ignore Previous Prompt: Attack Techniques For Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.265990Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.265990Z digest=sha256:9401058e5ac16237780117dcf9f944ea3b4bd4af94433392a7e488191b6056de

Observation 7b8bacf4-3986-4ba9-b777-766826fd236c · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.441142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.441142Z digest=sha256:cc951cfb7885d45d89b3b842e50ab3d295f43460ad6d1c0f3dfa7fba9f7a81da

Observation 4659aad0-d9f8-4407-b99e-53ac129d3541 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.589308Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.589308Z digest=sha256:a54c0949934bf5ad1e107a31acfa378f5ec29a3dc5e325e4dcb263fd9159135e

Observation 394f09dc-e471-49c1-82ba-a426fa996511 · outbound

This paper cites Qwen3Guard Technical Report.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Qwen3Guard Technical Report

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.789128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.789128Z digest=sha256:54aeb262815e954b83b84c817400b316c2249536e58f5701b09999fddcf78d36

Observation 0131db4f-d951-4312-9da8-867a5324e1b1 · outbound

This paper cites CoSafe: Evaluating large language model safety in multi-turn dialogue coreference.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework CoSafe: Evaluating large language model safety in multi-turn dialogue coreference

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.879064Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.879064Z digest=sha256:13fad5c362ea85e4150d247b8c30f50abcafa0c4a5ea62db9401675174859787

Observation 71421a47-7c67-47ea-a769-0458ddf6eb4c · outbound

This paper cites AgentDoG: A Diagnostic Guardrail Framework for AI Agent Safety and Security.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework AgentDoG: A Diagnostic Guardrail Framework for AI Agent Safety and Security

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:42.990718Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:42.990718Z digest=sha256:02e3202d36b227a3b6dc5b5be65edf1a73f3dd2a25474476cb1563bcbf245fc4

Observation 1e147a70-fad7-4b4a-8d59-884a7d741f12 · outbound

This paper cites TraceSafe: A Systematic Assessment of LLM Guardrails on Multi-Step Tool-Calling Trajectories.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework TraceSafe: A Systematic Assessment of LLM Guardrails on Multi-Step Tool-Calling Trajectories

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.118124Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.118124Z digest=sha256:6619d7c55b925b387ff7c9d1f54084ea3285200ab87701c4c56e69806004818f

Observation 0e554159-ce59-4c6f-aa1f-d3ec84906917 · outbound

This paper cites Unsupervised domain adaptation by backpropagation.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Unsupervised domain adaptation by backpropagation

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.211721Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.211721Z digest=sha256:48461c27056fc8b14a568aa87abc91804fc656c91e05a9ef89ca7411d4d02156

Observation 9abe967a-8553-413c-9f18-e57a8e718e6f · outbound

This paper cites Bag of Tricks for Efficient Text Classification.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Bag of Tricks for Efficient Text Classification

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.384902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.384902Z digest=sha256:04d7b005484f67b063b57468fcb98f504b771eb8426cd956120f8fecdc555567

Observation 6466bbad-fc49-4a5b-b8fc-9398a49ca24a · outbound

This paper cites Artificial intelligence risk management frame- work (AI RMF 1.0).

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Artificial intelligence risk management frame- work (AI RMF 1.0)

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.451218Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.451218Z digest=sha256:086cfc92fb5875f12384a2de7da04dc476f654c3e378002547d273cfe1969c15

Observation fad88ade-cb31-4cd5-abcd-7327bf13b8bb · outbound

This paper cites an unresolved cited work.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Unresolved cited work

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.625277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.625277Z digest=sha256:f2c044af915e68dd758da83e33ad67759ccbcf125d6823fdf3edda62f201d0a1

Observation 0a1ed6e9-9733-48e1-bcea-70f601bb6959 · outbound

This paper cites Deep reinforcement learning from human preferences.Advances in Neural Information Processing Systems, 30, 2017.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Deep reinforcement learning from human preferences.Advances in Neural Information Processing Systems, 30, 2017

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.812167Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.812167Z digest=sha256:e7f75a9311a4cab7ef4816f70299f9ba2c4c88fbefdb9fbe1e754da146d92b3d

Observation 09bab118-c5f1-4e6c-95b2-96bdd978ca81 · outbound

This paper cites Claude’s model specification.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Claude’s model specification

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.917416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.917416Z digest=sha256:32761e21c976a9de5e769f59a4752f9c55bc4c7c0463cb37263929f8e26cdcbc

Observation 3569c20b-cb96-4742-85f1-90f3bdebf463 · outbound

This paper cites Constitutional AI: Harmlessness from AI Feedback.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Constitutional AI: Harmlessness from AI Feedback

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:43.978969Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:43.978969Z digest=sha256:d39a9059a2068f0f966c56085010506e08337394b3646df9904717f3c075c0a5

Observation dc55010d-9f52-4710-a63a-fa9f01831a7f · outbound

This paper cites an unresolved cited work.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Unresolved cited work

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.105850Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.105850Z digest=sha256:de1ebc69311b36a6103e3c4888a81725b45c193683392fae70a2cdffc2af01bf

Observation 1d3bb387-f0b7-41fd-b0a6-ad3feaf3f506 · outbound

This paper cites an unresolved cited work.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Unresolved cited work

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.203053Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.203053Z digest=sha256:61236d1a1e2d8c4b3cfaba4b06b29cb1d9e2da9fe6723a01c90c6c3e89baeedb

Observation bb4431c2-d99b-4a90-9bae-2977f9dee30c · outbound

This paper cites Calibrating noise to sen- sitivity in private data analysis.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Calibrating noise to sen- sitivity in private data analysis

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.360666Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.360666Z digest=sha256:3850e3656dc7f5f0dbc607eec5a0a4f57229b4d4bbbb55943139620218d1591a

Observation 1cb14a48-8ad6-4978-aa9a-5973fc4e3753 · outbound

This paper cites Now Publishers, 2014.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Now Publishers, 2014

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.469478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.469478Z digest=sha256:2c53b844826295561cc6e1dd8dcc33c0a7628937184787f191195bef8221a377

Observation 0f32d9e9-da7d-4b76-89cd-73ff82c600e3 · outbound

This paper cites Pearson, Dietrich A.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Pearson, Dietrich A

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.584551Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.584551Z digest=sha256:db72d7d6070b6fa1a4f013c1e4474945c49b137851a2ea1fc2506b0da9845f0a

Observation 6f7adbc8-efa8-44c3-8b0e-159813d18156 · outbound

This paper cites Robust de-anonymization of large sparse datasets.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Robust de-anonymization of large sparse datasets

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.703147Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.703147Z digest=sha256:2754576da98dd755b291ef9206310ed86a7d4ca002d92596cf55115516dcfae0

Observation 43b6f1b8-c027-4c5f-bb0a-e90a1f01c76c · outbound

This paper cites Williams and Steve Young.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Williams and Steve Young

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.788021Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.788021Z digest=sha256:fc6e012f82fbe7384fb30975379818d0ea9031938782e656485b9d15c37291db

Observation d5f37b76-11c4-4bfd-b51e-a5e48fc0a008 · outbound

This paper cites Williams.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Williams

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.879215Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.879215Z digest=sha256:5f19ddcae5993c0d421dcbe0081d138530c255ababcd63558155b3b9b6cdf6a8

Observation e58d2af8-6805-4548-8d90-406bba2db93e · outbound

This paper cites Williams.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Williams

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:44.965897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:44.965897Z digest=sha256:e25fa907ff26b86445b490034bd671ba77b04fdf53c9dab8b31a7d82a7d9ea58

Observation 3afe6ea5-163d-4d94-9634-13949c33b33c · outbound

This paper cites Neural belief tracker: Data-driven dialogue state tracking.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Neural belief tracker: Data-driven dialogue state tracking

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:45.034756Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:45.034756Z digest=sha256:854f1143ef7a7dcb48e8ea0ab4ad678477d5027540d5f7b5fb9234e4d0667db1

Observation 427f6071-af47-4b86-863d-beda0c51b498 · outbound

This paper cites Tod-BERT: Pre-trained natural language understanding for task-oriented dialogue.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Tod-BERT: Pre-trained natural language understanding for task-oriented dialogue

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:45.087590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:45.087590Z digest=sha256:68b94ca5ee2ab8b699f60ba9358f3c26c6c5eba9d771dfdfe74d21765b82c898

Observation 7290e048-5de8-4c72-a287-20e5a69fe0cb · outbound

This paper cites an unresolved cited work.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework Unresolved cited work

Reference 2008

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:41.564364Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:41.564364Z digest=sha256:8e140fdbf7938a09978a5a0d816a065b26dcc27c4610074596521564284fee65

Observation da1e53e6-5c53-4d0d-b888-f63816c8b951 · outbound

This paper cites WildChat: 1M ChatGPT Interaction Logs in the Wild.

Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework WildChat: 1M ChatGPT Interaction Logs in the Wild

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T12:28:45.332809Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T12:28:45.332809Z digest=sha256:3e53ef3235ae992109be8ec0ee91e39c1c10b444a96a23627ed0e943dccc0312

Pith citing papers

No inbound Pith citation observations are available.