Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T02:43:24.479481Z
Paper Citation Record · LEDGER
As of 8 August 2026, this Paper Citation Record lists 42 of 42 outbound references and 0 inbound Pith citation observations for arXiv:2607.25364.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T02:43:24.479481Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
42 of 42 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 1ba4f6a6-30fb-481a-8f5a-90e59fa7c11e · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Language models don’t always say what they think: Unfaithful explanations in chain-of-thought prompting,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 30f3eaf1-2751-44ea-8341-6fb671924c9c · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Measuring Faithfulness in Chain-of-Thought Reasoning
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1cceac1a-1566-4796-bcd4-e584f0a64e61 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Dissociation of Faithful and Unfaithful Reasoning in LLMs
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 66d7d7b2-43c9-45ed-9df5-cfde15ee7be0 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ReAct: Synergizing reasoning and acting in language models,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b4fd514e-2589-4ef1-9f3a-63bc552d2159 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Why should i trust you?: Explaining the predictions of any classifier,
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 47aabdc4-0bb3-4bb7-84ad-5ae7e145b974 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explanation in artificial intelligence: Insights from the social sciences,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 476171b9-768c-4051-8dc1-7c8216f482d3 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The mythos of model interpretability,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79da502c-62ce-433c-8703-257314de1352 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Interpreting interpretability: Understanding data scientists’ use of interpretability tools for machine learning,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2facfbaf-3ad0-45f4-809d-438e014232c2 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Manipulating and measuring model interpretability,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8474d2c9-58f9-4df3-9a52-9d220f5cc51e · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The protection of information in computer systems,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3c88cc5e-9ce7-4304-892a-5d7de42eb12b · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guide to attribute based access control (ABAC) definition and considerations,
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aabd5ec7-50c3-437a-9504-4ce3315f49d3 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Not what you’ve signed up for: Compromising real-world LLM-Integrated applications with indirect prompt injection,
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5b4eabb0-c7b8-4c40-9b63-5df472774372 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Identifying the risks of LM agents with an LM-Emulated sandbox,
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6a6fcd77-073b-4781-9175-6342a5c34068 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a839a774-fff0-4a4e-9df9-a93eb081b0ec · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e7adc28e-5ca5-46ae-80a4-90807afe7682 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Prompt injection attack to tool selection in LLM agents,
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 95438d9f-decf-490a-9b18-1353d82b4016 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales MCPTox: A benchmark for tool poisoning on real-world MCP servers,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e8bcb4a3-5204-483a-862b-dbba69d49b4e · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales StruQ: Defending against prompt injection with structured queries,
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 94859335-b483-49c4-af0b-ec5f630aaefe · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AttriGuard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations,
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f817ebf8-deca-4e8f-b4b7-7bfedb4edc14 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Tools – model context protocol specification, 2025-11-25,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 59685e37-29d5-4330-a633-1756888f2d4b · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Authorization – model context protocol specification, 2025-11-25,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d7a5f4b-1740-4ebf-bef3-9af82886f3bc · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Artificial intelligence risk management framework: Generative artificial intelligence profile,
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b48a26a1-8fed-4913-b31a-819a0130acb0 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales LLM01:2025 prompt injection,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b92a1314-4622-4363-9304-76ecd1f0775e · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Auditable Agents
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 48b4a103-e437-4b03-bb7b-d4b1637d0ecd · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Agent audit: A security analysis system for LLM agent applications,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0b823ec3-0b7a-4043-8ba5-7206228ce627 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales JSON canonicalization scheme (JCS),
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 889e1901-795c-4aed-8869-f65b2837f1dd · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 44635574-ed87-41ee-99d2-dc669a5f25ec · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-Assisted decision-making,
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 36b9d225-6749-4868-bc36-00a4604e4379 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Crying wolf: An empirical study of SSL warning effectiveness,
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2f9267a9-b8da-498d-9839-c33c470e550f · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guidelines for Human-AI interaction,
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79a844e1-04aa-409d-af1c-55737551824e · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explainable security,
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 93087a73-a41e-4ee4-a334-ab858490967c · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards explainable access control [BlueSky Paper],
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d8283456-f77a-43d9-8edb-0be319dba038 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales SmartAuth: User-centered authorization for the internet of things,
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5892d669-93d4-4927-8266-e12852075377 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AWare: Preventing abuse of privacy-sensitive sensors via operation bindings,
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 92cc9bb8-f2e2-4f13-ae0b-d9102364fe40 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Decision provenance: Harnessing data flow for accountable systems,
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 58b99851-2307-4081-99b6-9c54c7d3e4fd · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ACCESSPROV: Tracking the provenance of access control decisions,
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8dd6cb4f-e480-4019-89b8-bfcc21f5ff7c · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Defeating Prompt Injections by Design
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1fe5df0a-f9df-4553-89ca-46a108e0a5e3 · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing AI Agents with Information-Flow Control
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 972b83f8-82d8-4ab2-bf0e-d848e20dfd4a · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing agents with tracked capabilities,
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0f7f09be-02bd-42bf-9e67-f1b0cc3bbc2f · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents,
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1077a7db-9985-4860-b4de-c635c5cddfec · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards verifiably safe tool use for LLM agents,
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 918492e6-a78d-40df-b636-7d4301aef83b · outbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Available: https://openreview.net/forum?id=GEcwtMk1uA
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.