Pith. sign in

Paper Citation Record · LEDGER

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

As of 7 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2608.00747.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00747 v2

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T04:17:02.594840Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved26
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation bb170696-a993-47e8-ac53-8a7eea8e35f0 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Ignore Previous Prompt: Attack Techniques For Language Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.494770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.494770Z digest=sha256:2733afb962f315cf6193b2f63f8d00819b4305f2a5cf147ad3cacde2fe0c875b

Observation e51ae8f8-dfe0-4058-aeab-bfe27432df12 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.499370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.499370Z digest=sha256:b0d6ad387b7cd728d779c15cb4276ce631519783a0c7b44e19bcc7a7242c528a

Observation 7c2b1b60-bd8f-485e-ba4e-d4076050b839 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.503427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.503427Z digest=sha256:1c8b1293739b19dcbdcad444effe08135aae298a386851d6cb2ba0fba78f150b

Observation ce38dc26-2af1-4fe8-ab2e-b556bf871fa2 · outbound

This paper cites A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.507970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.507970Z digest=sha256:71e4a14b1fd949a1952dbde46ac18c9ed01bdaa5ffb7d767ec46eb3303d199c6

Observation b3b9ed97-2620-415b-96a6-711d66e37531 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt Injection Attack to Tool Selection in LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.512504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.512504Z digest=sha256:44188a37cf1048b8d4a7cc1fa628b5c46be8e710a26bc92079a52dc6fa996f18

Observation 558cf644-7c68-49fd-9844-57c81c380287 · outbound

This paper cites Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.516491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.516491Z digest=sha256:65329038da1fe3a21b875d0b4451451e7547d44d5939e4c859cc296b7375dd13

Observation f5e615bf-34cc-4b35-992c-a4881832719f · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Memory injection attacks on llm agents via query-only interaction,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.520587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.520587Z digest=sha256:e1dc79c039b20375132a5a57b05f329eeb9a06cd0644125409ccbae4c988ea54

Observation b85e4991-a6ec-41a2-ab09-3bd45cd0dd9f · outbound

This paper cites Prompt infection: Llm-to-llm prompt injection within multi-agent systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt infection: Llm-to-llm prompt injection within multi-agent systems,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.524559Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.524559Z digest=sha256:ee68ea5bbdc7a6f03cf1a64e4239a2489e769ec28a27759c2d478041ad6cd2b2

Observation a13f49f7-e8f2-4232-9e0b-09ee727c3222 · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.527779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.527779Z digest=sha256:5697abece997a37b9b07eb413beb3705488309ff2760b8f43b40840a73f213c2

Observation d1181928-a6dd-4bc4-81e2-21c2891f11cb · outbound

This paper cites IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.531826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.531826Z digest=sha256:bd9527bd8dc7497fb67bbc388762779a6bc5805679c7e8e2cad2a5b884143926

Observation df05d453-c18f-46f1-af60-291b8c858210 · outbound

This paper cites Multi-Agent Systems Execute Arbitrary Malicious Code.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:b850d4f1445fabf3f9e565b8f2dcf697cd3576cf08362be402fe797fa4c52195

Observation a261c141-7ae3-4579-b997-dfd297475108 · outbound

This paper cites Red-teaming llm multi-agent systems via communication attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Red-teaming llm multi-agent systems via communication attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.539306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.539306Z digest=sha256:eef3e419f63df282d6ad1ae62196234cb5ca9f5042263bac8ec62777d4b39c0e

Observation 8af621a0-4dd1-4298-be2e-110119c99a48 · outbound

This paper cites Breaking agents: Compromising autonomous llm agents through malfunction amplification,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Breaking agents: Compromising autonomous llm agents through malfunction amplification,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.543199Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.543199Z digest=sha256:c9f86e1eb447f55f0e03b390f471e3ae524f6239cab484f1bdb51f7a943f1135

Observation 59e1107c-10eb-4979-88e4-7a47f7bb4241 · outbound

This paper cites BadRobot: Jailbreaking Embodied LLM Agents in the Physical World.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems BadRobot: Jailbreaking Embodied LLM Agents in the Physical World

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.546665Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.546665Z digest=sha256:bb6026bf3f3011c18f11797da7ccfea5eb9cbbc4bdeb6f60c6c5c6750000a034

Observation 92ca83d1-8370-4254-a965-5d995bd50553 · outbound

This paper cites A study on prompt injection attack against llm-integrated mobile robotic systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A study on prompt injection attack against llm-integrated mobile robotic systems,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.550312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.550312Z digest=sha256:a0178d3f02fc39badd8bc3ca933d3f71cdfa70c88ad5d31627e78ae5962d5582

Observation 780ac79f-a127-4fe2-a6d8-35f377c52541 · outbound

This paper cites Long-horizon planning for multi- agent robots in partially observable environments,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Long-horizon planning for multi- agent robots in partially observable environments,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.553854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.553854Z digest=sha256:402318a6fcd0f322baa3a12f94e788854d98554ce99e279f9878fe53cc57a9ef

Observation b770397f-38d6-4569-a686-d40e456a5ef4 · outbound

This paper cites AI2-THOR: An Interactive 3D Environment for Visual AI,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems AI2-THOR: An Interactive 3D Environment for Visual AI,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.557683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.557683Z digest=sha256:60b0bf5cbdfec53e8e4ad384fbb27c127f155b0a09f6bb3a0aca231d819a327b

Observation 94a70e48-81f1-47a6-b2e5-c5d52ffe3948 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Formalizing and benchmarking prompt injection attacks and defenses,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.561146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.561146Z digest=sha256:f7f5612c549bf5108d996b39b5c3a6365c6c3204887dbd88d991fcca782cc995

Observation 5989c688-0522-4bc9-a1f1-35dda94cdeef · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.564492Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.564492Z digest=sha256:42994624ac19ccc9a72c0bb651c9b7d6793f36b70f1e17df6cdf64537e34b77f

Observation c55359a1-2b3c-49f6-9650-7e85313e2762 · outbound

This paper cites Jailbreaking llm-controlled robots,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking llm-controlled robots,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.568841Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.568841Z digest=sha256:6bedeb2dbe357a814dad0c92871982de19a389379f039248eb07b177a8a25b88

Observation f0d232bb-7615-44f2-9eb3-c775250afb6d · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking black box large language models in twenty queries,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.573034Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.573034Z digest=sha256:d8e9ae201af19c14a48c793963159975b30c1a767057c1f45348fc413821216e

Observation ccb795ea-410c-463e-b843-18a3122bd09c · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.576515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.576515Z digest=sha256:edd05518a3c4e42063f3889b42c0c5af698539bebe215faf683f3a0f52580662

Observation 3a84d894-086c-40ad-9149-71cfca548d58 · outbound

This paper cites Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.580448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.580448Z digest=sha256:937afd05873a5bd5dcb103ba6df8f77314d14cbac2edcdda4596dba6abbf48f8

Observation f0902229-485e-4fd6-9b20-fbef892648d8 · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.584306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.584306Z digest=sha256:709b37efc6bc0d235d6c47e3007b87d27c938c59444131ad5eed69989cc69424

Observation 3b86aa3e-7ec1-4254-bdcd-bd320813b959 · outbound

This paper cites Sentence-bert: Sentence embeddings using siamese bert-networks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Sentence-bert: Sentence embeddings using siamese bert-networks,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.587650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.587650Z digest=sha256:0636f2b0a916d12ba53d657f230c1f21ce3f6f0edd9629f2196dd69c7292061c

Observation f4472c28-19f9-4a15-a6fe-6d667a43d765 · outbound

This paper cites Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.591154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.591154Z digest=sha256:16782b51b51335526be6252540a98f525e0a9f6764f1d717ec381bccbfc82f93

Observation 7b3561d9-29b1-40cc-91cb-e557b307c12c · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T04:17:02.594840Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.594840Z digest=sha256:f67d1b340ce67cddc7816b24eab7640f4cdae762a2f7e5bd9edb7738ca65ae2e

Pith citing papers

No inbound Pith citation observations are available.