Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T00:54:57.479602Z
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 94 of 94 outbound references and 0 inbound Pith citation observations for arXiv:2608.02657.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T00:54:57.479602Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
94 of 94 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation d08fbfda-b34e-4243-8c83-f0030f19dcda · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Get my drift? catching llm task drift with activation deltas
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 66fab6d8-702a-4ecc-838a-c48f2fc9e688 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Prompt leakage effect and mitigation strategies for multi-turn llm applications
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 91de3c53-35a6-415b-95ed-0cf40ab86c8f · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Understanding intermediate layers using linear classifier probes
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ff90bb45-4397-4ff9-956f-2edd8c5bd96a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure IPIGuard : A novel tool dependency graph-based defense against indirect prompt injection in LLM agents
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e2e9699b-5c2f-453f-b38f-89a9b3e2222b · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Jailbreaking leading safety-aligned LLM s with simple adaptive attacks
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8cc9763a-8480-4557-8eb1-bb1e64a55016 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Many-shot jailbreaking
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 30cb68a9-404a-4d88-919d-0e074d8523f5 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Refusal in language models is mediated by a single direction
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1dad014f-f556-4ac1-b8e3-dad75af88d13 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Monitoring Reasoning Models for Misbehavior and the Risks of Promoting Obfuscation
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0e0e27b3-5bb3-4cae-92ed-2fa41f461abf · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Probing classifiers: Promises, shortcomings, and advances
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2e8ce96e-6279-4039-9eed-96ffd287cead · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Language models can explain neurons in language models
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 63e5737b-96ba-42cb-82fd-4e0fb201b452 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Bogdan, Uzay Macar, Neel Nanda, and Arthur Conmy
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a6a263c8-2f67-4aae-9e20-a3d706d5937e · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Reasoning Theater: Disentangling Model Beliefs from Chain-of-Thought
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a28847c1-2e00-4907-a14e-ef00c900d453 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Towards monosemanticity: Decomposing language models with dictionary learning
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 63baef44-47d6-4ed6-83ab-0f7c47353381 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Discovering latent knowledge in language models without supervision
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 56473867-639c-4524-b872-3b520e6d560d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Vpi-bench: Visual prompt injection attacks for computer-use agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 72eeef71-88fe-4937-8ebc-8b431c533a5d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ghostei-bench: Do mobile agents resilience to environmental injection in dynamic on-device environments? In ICLR, 2026
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4008ff70-ac65-45f8-949c-28426be73e33 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Struq: Defending against prompt injection with structured queries
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 89feb34e-ed98-4c2f-be38-e21986457ec7 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Secalign: Defending against prompt injection with preference optimization
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a36b39f7-071b-415a-89e2-6df75d2f875a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure HarmonyGuard: Toward Safety and Utility in Web Agents via Adaptive Policy Enhancement and Dual-Objective Optimization
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 15ec6143-48ab-4c62-a8cc-746c2cf77db2 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure LlamaFirewall: An open source guardrail system for building secure AI agents
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b234a609-1001-450b-9c75-f1abcba9a8f2 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Constitutional classifiers++: Efficient production-grade defenses against universal jailbreaks
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0c0b495-3417-41f4-986a-d71828e8602e · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8ac70048-ae95-416f-a63d-231248544b44 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defeating Prompt Injections by Design
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 966911ef-668d-4ccc-ab43-9189468bdaca · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure `` I ' ve decided to leak'': Probing internals behind prompt leakage intents
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation d0d96b01-9b34-4a1c-b49f-a8102a1655d3 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Safesearch: Automated red-teaming of LLM -based search agents
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6d6264ae-f349-4461-8f4e-b0b2d5f9cefa · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Memory injection attacks on llm agents via query-only interaction
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2eaef61b-b7c2-4df6-be65-02cc20df039d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Transcoders find interpretable llm feature circuits
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 0b403446-6ee0-4ab2-aecb-e7567a98b1cf · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c0cbdf7b-546c-42aa-b51a-009e357d52dc · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure WASP : Benchmarking web agent security against prompt injection attacks
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 64116890-5e9e-4b32-90d6-122cb6145892 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Patchscopes: A unifying framework for inspecting hidden representations of language models
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 19713e46-219d-41af-8531-70043a946e9f · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Not what you've signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 52dae4b0-414e-4e78-8dc9-83e6b29ee94d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 151fd113-bd15-441c-a967-ae04ca36a7e6 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Attriguard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e8380c2b-1bff-4d2a-aa42-494dbe876702 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Internal representations as indicators of hallucinations in agent tool selection
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 857e5167-3ac0-41a7-a5e7-a6535be22dec · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1b1909c9-be26-4bba-9d26-689ae0a87232 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Hsu, and Pin-Yu Chen
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 753b8d18-880a-439d-9d6c-5efc25da638b · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Safepath: Preventing harmful reasoning in chain-of-thought via early alignment
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 20cdfd49-d376-474e-a572-fa398ec22ad7 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Llm internal states reveal hallucination risk faced with a query
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6ba31737-4ee0-47ed-b5f0-f41c446651a3 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 09de3710-9633-48d0-9eb8-04646cbf2200 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Promptlocate: Localizing prompt injection attacks
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2fc9f139-ca42-42a9-9e5a-391b474f2f18 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Activation oracles: Training and evaluating llms as general-purpose activation explainers
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c531c47a-d446-4eb7-b2a2-98407dffcc16 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Le, and Tomas Pfister
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 132747cf-e63c-4979-82ce-86949a8c70b2 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Hendryx, Summer Yue, and Zifan Wang
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9c11e71a-89f3-4c64-94a6-067cddbbacce · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure OS -harm: A benchmark for measuring safety of computer use agents
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5aaea5ae-c316-4783-9714-1b9170c73a5a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Measuring AI ability to complete long software tasks
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation bbed69b4-bd07-4688-a003-e43f2c3f5d5d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Efficient memory management for large language model serving with pagedattention
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e7c7ba09-adf7-4d49-99a4-c14604383937 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Measuring Faithfulness in Chain-of-Thought Reasoning
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 39a8ec91-4374-48f9-80f7-73e24dbbf8c2 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f42caaef-7e1f-422e-8307-c64c9ca00cbe · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Inference-time intervention: Eliciting truthful answers from a language model
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6fcfaa42-5014-467e-adb2-77b49e572752 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e3e69242-191e-4971-bbae-f7de1d05b9dc · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Eia: Environmental injection attack on generalist web agents for privacy leakage
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a21ab69d-9501-4b4d-8754-cdc997fe6bdd · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Vigil: Defending llm agents against tool stream injection via verify-before-commit
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 58686ce0-c64a-498a-bb7f-8efaaba781bf · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 05a13b9a-444d-4532-bbee-ba60d073641f · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Traceaegis: Securing llm-based agents via hierarchical and behavioral anomaly detection
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0979778b-760e-4726-baed-2337ad6f4e30 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Prompt Injection attack against LLM-integrated Applications
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7b178dcf-91be-47ec-9a6d-c6d8c194ea2f · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Formalizing and benchmarking prompt injection attacks and defenses
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 71eee48b-2e5a-47dc-bf87-71ffb9f381d7 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Bogdan, Senthooran Rajamanoharan, and Neel Nanda
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c4d8cee7-3389-4157-b64f-ca4ec9ef9547 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure s1: Simple test-time scaling
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 893b2cf9-786d-4bd2-aa9f-68352e604a15 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c718d3d1-ec12-45bf-b72d-60bea70b0055 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure GPT-5.6 System Card
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 04037920-c5bb-4d12-9836-f7b1aad4e620 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure GPT‑5.5 System Card
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e515aa37-cf34-42f9-8805-3b0760dd2846 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure LLM s know more than they show: On the intrinsic representation of LLM hallucinations
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9a0ba171-7d4a-472c-9b56-b401a90e7323 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Owasp top 10 for agentic applications for 2026, 2025
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation d6bff5c4-1b84-4aa0-81c9-a23ebc63fc4a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Latent QA : Teaching LLM s to decode activations into natural language
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 78ca08a7-dca1-4c8f-89db-4590e1a59204 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The linear representation hypothesis and the geometry of large language models
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d03875ff-f35d-4ec4-98f4-7b63a190030b · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Scikit-learn: Machine learning in python
Reference 66
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bd11d624-c7f0-4fc0-97cc-22b34db60500 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ignore previous prompt: Attack techniques for language models
Reference 67
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5d5ee724-8cc8-41e5-ae4f-6fe05c7b9439 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Steering llama 2 via contrastive activation addition
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 86e8a1cb-7287-4fce-9297-bc8354c6458c · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Great, now write an article about that: The crescendo multi-turn llm jailbreak attack
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 863184d2-8aa0-42be-814d-e1743bc4b8c1 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ignore this title and hackaprompt: Exposing systemic vulnerabilities of llms through a global prompt hacking competition
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1f4cf12f-5893-4691-8b22-b7ef8e271ac8 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure PromptArmor: Simple yet Effective Prompt Injection Defenses
Reference 71
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6472a7d6-1abf-4bdd-9660-c053fd77c4d3 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Daniel Freeman, Theodore R
Reference 72
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 732b4a58-e52c-4901-aefa-6e93afcece8d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Tensor trust: Interpretable prompt injection attacks from an online game
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 304d6cf6-3ab3-4819-bb76-258b988ee964 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 74
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79e606ba-5f75-47a2-b994-d20998f4f783 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Raccoon: Prompt extraction benchmark of llm-integrated applications
Reference 75
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8f6737ba-73f0-4be0-a105-0ee6ecf82c30 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agentarmor: Enforcing program analysis on agent runtime trace to defend against prompt injection
Reference 76
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 86c19c39-f6c1-4edf-83cc-2e23a301e48b · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Automatic layer selection for hallucination detection
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 15774ad1-a8ea-4106-b132-d3bab8aa8cfd · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defending against indirect prompt injection by instruction detection
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 262a2156-1068-4ed9-8947-a7e8191de3eb · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Unresolved cited work
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6ef89cfa-42d3-4f04-9db6-015860dea1f5 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Guardagent: Safeguard LLM agents via knowledge-enabled reasoning
Reference 80
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1d493fda-8275-47c3-aafe-268b4c406d5e · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Qwen3 Technical Report
Reference 81
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6fe9ac39-009d-4c96-9856-8ad2cf964fa3 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure RAP-ID : Mechanistic prompt injection detection via impostor behavior analysis
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a53c2fca-6392-45a8-b876-3621dc0f40b5 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Reasoning Trap: How Enhancing LLM Reasoning Amplifies Tool Hallucination
Reference 83
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fba3050a-4673-47d2-9efc-7f027e406c2d · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents
Reference 84
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 345000b5-0375-4133-b06d-bbf6b52daf2a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Adaptive attacks break defenses against indirect prompt injection attacks on llm agents
Reference 85
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1b723bfd-acaa-4072-bbc1-098d825e287e · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agent security bench ( ASB ): Formalizing and benchmarking attacks and defenses in LLM -based agents
Reference 86
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6f700c98-420c-45a9-ab76-da7a81683c1a · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defense against prompt injection attacks via mixture of encodings
Reference 87
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5244c1af-d5fe-4fe5-93b3-f3e7a6e68f39 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Toolbehonest: A multi-level hallucination diagnostic benchmark for tool-augmented large language models
Reference 88
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ce8c1d43-1646-4b00-85f2-cf3c0e528993 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Iheval: Evaluating language models on following the instruction hierarchy
Reference 89
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 21c06b96-d2df-4fde-88d3-b7fe379aefa8 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Attention is all you need to defend against indirect prompt injection attacks in llms
Reference 90
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8223654b-2157-406e-b45c-b8ecaefc50dd · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure MELON : Provable defense against indirect prompt injection attacks in AI agents
Reference 91
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1ff8edec-df0e-4de2-a9c9-0cec8a9caa21 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Your Agent is More Brittle Than You Think: Uncovering Indirect Injection Vulnerabilities in Agentic LLMs
Reference 92
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eb73bb13-2cdf-4042-afa8-7ed1493e80ed · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Representation Engineering: A Top-Down Approach to AI Transparency
Reference 93
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b2b6154e-2b53-4867-94d6-4e6d841655d0 · outbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Pishield: Detecting prompt injection attacks via intrinsic llm features
Reference 94
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.