Pith. sign in

Paper Citation Record · LEDGER

Rethinking Agent Security as a Networking Problem

As of 18 August 2026, this Paper Citation Record lists 77 of 77 outbound references and 0 inbound Pith citation observations for arXiv:2608.12172.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.12172 v1

Coverage vector

measured 77 of 77 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-16T00:16:52.653903Z

measured 77 of 77 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

77 of 77 outbound references displayed

  • verified exact0
  • verified fuzzy46
  • unresolved31
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 307f55f9-9df6-44ed-9392-4dd75055892e · outbound

This paper cites Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution.

Rethinking Agent Security as a Networking Problem Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.303564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.303564Z digest=sha256:24fdd0a6cf6dcad1d68aaaf5152ff597686bf1a847f2b26bb101bc6de6f21bf1

Observation 75af99fd-35b9-45be-bb0e-539c3b19fb0a · outbound

This paper cites Model context protocol.

Rethinking Agent Security as a Networking Problem Model context protocol

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.138420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.309227Z digest=sha256:ae1fc5d5f435c86107b58fe5fc5c1538cfb49edb150f178871a3a7ff183ea3c1

Observation 7bc4a230-bca9-4d4e-90b1-0e0bda6b742d · outbound

This paper cites Air- GapAgent: Protecting privacy-conscious conversational agents.

Rethinking Agent Security as a Networking Problem Air- GapAgent: Protecting privacy-conscious conversational agents

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.123389Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.313941Z digest=sha256:0c91d1bb39d84b5799bde33c59898a6e132c0cfc6674698112c900f0e4c0dcb1

Observation 085a062e-7873-4d4d-87bf-6f2a28a46938 · outbound

This paper cites Off by default! InProceedings of the 4th ACM Workshop on Hot Topics in Networks (HotNets-IV), College Park, MD, 2005.

Rethinking Agent Security as a Networking Problem Off by default! InProceedings of the 4th ACM Workshop on Hot Topics in Networks (HotNets-IV), College Park, MD, 2005

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.098945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.323520Z digest=sha256:5774d4deeb86f889a82de05b51ef8fc2bc0893d89f02ce149d69d04eb8b2339a

Observation ac23da05-14a3-4f9e-ba6b-6351207f1f80 · outbound

This paper cites Freedman, Justin Pettit, Jianying Luo, Nick McKeown, and Scott Shenker.

Rethinking Agent Security as a Networking Problem Freedman, Justin Pettit, Jianying Luo, Nick McKeown, and Scott Shenker

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.083703Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.328579Z digest=sha256:88cbd0ba24aed24d7408a621739a82ad4fbf8ffde7f1e81cf6eb5f82b7e52aba

Observation 9742d581-a98e-4778-9ff6-d7453dbaab05 · outbound

This paper cites Freedman, Dan Boneh, Nick McKeown, and Scott Shenker.

Rethinking Agent Security as a Networking Problem Freedman, Dan Boneh, Nick McKeown, and Scott Shenker

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.069453Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.334111Z digest=sha256:6783c9e5ecfa77e9f65183b8654e3a30dda46612e6e14442792f815440cc6415

Observation 22ba1fa3-3d01-42f6-a726-dacd082a736b · outbound

This paper cites {StruQ}: Defending against prompt injection with structured queries.

Rethinking Agent Security as a Networking Problem {StruQ}: Defending against prompt injection with structured queries

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.054036Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.339433Z digest=sha256:da55e56734a36966bf53c634389024d435f6d6c6289e04d1f93a1df3b917801e

Observation 0fb0ed77-c5b1-4fcf-97e5-3e97c8b89892 · outbound

This paper cites Secalign: Defending against prompt injection with preference optimization.

Rethinking Agent Security as a Networking Problem Secalign: Defending against prompt injection with preference optimization

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.344313Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.344313Z digest=sha256:f30779ba8822f1d1e95c473e3b4b48d3749d7a969733b03975743df74888c44f

Observation 0334ae0a-09da-44dc-9871-32a9fb6b030c · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowl- edge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

Rethinking Agent Security as a Networking Problem Agentpoison: Red-teaming llm agents via poisoning memory or knowl- edge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.348775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.348775Z digest=sha256:ccf98b1b54418dbfba4400fbc5922e13e472adb225f7072bcfae5ad18e225f78

Observation b36724f7-1f7b-4d93-9381-ed66a003bfb7 · outbound

This paper cites Overprivileged by design: AI agents as cloud escalation vectors.

Rethinking Agent Security as a Networking Problem Overprivileged by design: AI agents as cloud escalation vectors

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.020107Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.353237Z digest=sha256:027aad8661e596f20097810a7e925f034328fcce3dff9d49ef3ab820673e0cb5

Observation 10c52286-c590-4493-99a8-3e7a23025f32 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Rethinking Agent Security as a Networking Problem Securing AI Agents with Information-Flow Control

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.357689Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.357689Z digest=sha256:167d233ac0c0a6a31051384189d63732a8cf9eaf5f034237a3bb587acf1302e9

Observation 4d423be8-c845-4d2b-ad13-3306bed23c1e · outbound

This paper cites Defeating Prompt Injections by Design.

Rethinking Agent Security as a Networking Problem Defeating Prompt Injections by Design

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.362927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.362927Z digest=sha256:03d3fbae13cb0ec93b7968ba53b8654bb0a0cb8a52e232a70b1bd566ab2fda25

Observation 1a09a59c-fecb-44a5-a867-1443ac50449a · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents.

Rethinking Agent Security as a Networking Problem AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.005425Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.367655Z digest=sha256:eceb8373fdc2a4a95a3ab44a8cacce276a5f92cf9b560416a7b1bc5c41d524bf

Observation 5d732177-794b-4a5f-a7fe-332b5dd6d2f2 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 57(7):1–36, 2025.

Rethinking Agent Security as a Networking Problem Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 57(7):1–36, 2025

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.372005Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.372005Z digest=sha256:4282a9889ccf4cc2e9f3e7caef6db141c1c361499d8cff30dabd7031bb8499c7

Observation 14a28adc-8e32-4b04-8a6f-ca792ee3b9cc · outbound

This paper cites an unresolved cited work.

Rethinking Agent Security as a Networking Problem Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-16T00:16:53.980500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.376540Z digest=sha256:b62321a0a9d82ced9a3a583552d97f801fd4c1094a24f7cff89865045a3026f8

Observation abdb78e1-07bf-4c0c-ad3f-540f869ee3ae · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction.Advances in Neural Information Processing Systems, 38:46697–46731, 2026.

Rethinking Agent Security as a Networking Problem Memory injection attacks on llm agents via query-only interaction.Advances in Neural Information Processing Systems, 38:46697–46731, 2026

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.965986Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.381100Z digest=sha256:72cb15d89eac0d990870c0952e9b5f493e855e42ea887ffe073924b2de9dff30

Observation afa7f544-284d-42f7-80a1-682cc86e9981 · outbound

This paper cites Towards verifiably safe tool use for llm agents.

Rethinking Agent Security as a Networking Problem Towards verifiably safe tool use for llm agents

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.952047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.385629Z digest=sha256:9cccc72cf42f49489baca71ff1486dd7f8a3f6fff0fd033828743440ae9ff76f

Observation a96d1fef-c4fd-498d-b08e-444032087434 · outbound

This paper cites AgentLeak: A full-stack benchmark for privacy leakage in multi-agent LLM systems.arXiv preprint arXiv:2602.11510, February 2026.

Rethinking Agent Security as a Networking Problem AgentLeak: A full-stack benchmark for privacy leakage in multi-agent LLM systems.arXiv preprint arXiv:2602.11510, February 2026

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.389986Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.389986Z digest=sha256:b825d461bf5a45cf853f8cd6208415f0adde67b241c52f20bffc667f99d626af

Observation 47c471bd-da43-4778-987e-87ab27143bc4 · outbound

This paper cites Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems, 38, 2026.

Rethinking Agent Security as a Networking Problem Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems, 38, 2026

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.937836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.394299Z digest=sha256:ee2f8a91dc5fc6c44170fceb67159098c6f2ebbebaad11282b0079bc7b3d60b1

Observation bd14a932-ea5c-4abf-beac-791911997f00 · outbound

This paper cites AI agents are the biggest data security threat you’re not governing.

Rethinking Agent Security as a Networking Problem AI agents are the biggest data security threat you’re not governing

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.922661Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.398764Z digest=sha256:59f71c693de31f6e662e5a3ff7a1584b9d818a214e338c581d99cc4c8b056f35

Observation 805acb9c-2d57-4b25-8f79-b61dc624336f · outbound

This paper cites Agent2agent (A2A) protocol.

Rethinking Agent Security as a Networking Problem Agent2agent (A2A) protocol

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.907836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.403122Z digest=sha256:c48ee4e62e2c6fabd37f2f5d23c0b733477f10367da10269d5bb0e0f2d877f8f

Observation 3274f44a-94e6-4713-bd52-2347f864e27d · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection.

Rethinking Agent Security as a Networking Problem Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.892852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.407983Z digest=sha256:1003b1f47bade19df35c1cfdda0cf4ffdd311eeb9bb3ee4cc4116f637f200daa

Observation 14e2ac38-18e9-4ab8-a80b-8296a1587c9a · outbound

This paper cites Bypassing LLM guardrails: An empirical analysis of eva- sion attacks against prompt injection and jailbreak detection systems, 2025.

Rethinking Agent Security as a Networking Problem Bypassing LLM guardrails: An empirical analysis of eva- sion attacks against prompt injection and jailbreak detection systems, 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.878294Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.412448Z digest=sha256:abfbed3e4d3f7710d62ed00cb66a1d899c5d479a183690d537e47b524ab1e4d6

Observation 096b3df7-3605-4b26-9a17-35957152ba5c · outbound

This paper cites The OAuth 2.0 authorization framework.

Rethinking Agent Security as a Networking Problem The OAuth 2.0 authorization framework

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.864145Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.417816Z digest=sha256:3ed8df58a3194152bf32f47a518ec0bcd990c7c60c6ed42ba4dc2e4b459947ab

Observation 42e92a12-2d7e-4a9f-9608-4b5405e86323 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Rethinking Agent Security as a Networking Problem Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.422410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.422410Z digest=sha256:d86ca08f25f66f91924d810240fb24ff4428b786591157c4559d119c6b40dc9c

Observation ad8ee4e6-8e34-41c1-9042-17c252d61947 · outbound

This paper cites Break- ing and fixing defenses against control-flow hijacking in multi-agent systems.arXiv preprint arXiv:2510.17276, 2025.

Rethinking Agent Security as a Networking Problem Break- ing and fixing defenses against control-flow hijacking in multi-agent systems.arXiv preprint arXiv:2510.17276, 2025

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.426857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.426857Z digest=sha256:3dcb18b2f0dbf6d022d24211c31e6e6b0341b81762eaf5997540769bf021c7ad

Observation 6e52efd2-8208-4a1e-921e-7b31bea700d2 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents.

Rethinking Agent Security as a Networking Problem The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.846847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.430727Z digest=sha256:6ae42832b1133ef29b55f2727672373a2b2497cf4ad23018c9655b784a962867

Observation 304440f1-a086-4495-a037-cd6867237972 · outbound

This paper cites A Critical Evaluation of Defenses against Prompt Injection Attacks.

Rethinking Agent Security as a Networking Problem A Critical Evaluation of Defenses against Prompt Injection Attacks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.434773Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.434773Z digest=sha256:c6773bc0cfddab7ec3a0da7b2c21d8c50fbc1762cfc34e04585b9a6062997d9d

Observation 3fa22a94-faa1-4e26-89f4-769eb59c2aef · outbound

This paper cites When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents.

Rethinking Agent Security as a Networking Problem When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.438925Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.438925Z digest=sha256:afb37bc69e8da4d6b3cff532d6413b05806d28956541c202b528eee04ab2d070

Observation d9f6ab40-a906-4dc3-bcbc-96f77a87229d · outbound

This paper cites Frans Kaashoek, Eddie Kohler, and Robert Morris.

Rethinking Agent Security as a Networking Problem Frans Kaashoek, Eddie Kohler, and Robert Morris

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.831339Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.444062Z digest=sha256:81e609e997a2518bb4750cc709a59fb3a686d60f52393788283f0518b8e0d797

Observation bbbe41cc-bd09-411d-bdb0-31dba52f50a1 · outbound

This paper cites Lakera guard.

Rethinking Agent Security as a Networking Problem Lakera guard

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.816326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.448593Z digest=sha256:4c108e0ea6de21282af0f162105cca62a3100b403a8dc15de70e903f926b5504

Observation 278e6b90-2561-48ca-80ea-0f884286fc83 · outbound

This paper cites Inan, Sahar Abdelnabi, Janardhan Kulka- rni, Lukas Wutschitz, Reza Shokri, Christopher G.

Rethinking Agent Security as a Networking Problem Inan, Sahar Abdelnabi, Janardhan Kulka- rni, Lukas Wutschitz, Reza Shokri, Christopher G

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.800917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.452882Z digest=sha256:adb9442619939b8940b976b93ec761194ba7a271248a68bd71146dd9883253f0

Observation c532226d-88ca-4992-b06f-1d85fee1064c · outbound

This paper cites Improving google a2a protocol: Protecting sensitive data and mitigating unintended harms in multi-agent systems.ACM Transactions on Software Engineering and Methodology, 2025.

Rethinking Agent Security as a Networking Problem Improving google a2a protocol: Protecting sensitive data and mitigating unintended harms in multi-agent systems.ACM Transactions on Software Engineering and Methodology, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.785731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.457328Z digest=sha256:a7d26aa8f6846c1ed15af46cd7c2eeb5fdc9724ce69514979f13df09b91cee42

Observation e45143a1-69f0-49d0-871a-87ea66245a92 · outbound

This paper cites ClawLess: A Security Model of AI Agents.

Rethinking Agent Security as a Networking Problem ClawLess: A Security Model of AI Agents

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.461950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.461950Z digest=sha256:ad308a194cc6a917927fcf15322d7890c51a007adf2a1737502f6cd72d7553f5

Observation 090b13fd-312f-4d4d-83f9-4f61e491471e · outbound

This paper cites Agentauditor: Human-level safety and security evaluation for llm agents.Advances in Neural Information Processing Systems, 38:43241–43298, 2026.

Rethinking Agent Security as a Networking Problem Agentauditor: Human-level safety and security evaluation for llm agents.Advances in Neural Information Processing Systems, 38:43241–43298, 2026

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.466663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.466663Z digest=sha256:45ca0e201d83f24c7909926c8cbac176d7dfed401596000c774fcd7d6af8305c

Observation 442b940f-952c-4a86-a9d5-1b2a443258f3 · outbound

This paper cites A holistic approach to undesired content detection in the real world.Proceedings of the AAAI Conference on Artificial Intelligence, 37(12):15009–15018, 2023.

Rethinking Agent Security as a Networking Problem A holistic approach to undesired content detection in the real world.Proceedings of the AAAI Conference on Artificial Intelligence, 37(12):15009–15018, 2023

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.759446Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.471715Z digest=sha256:ca7d1109b66f4bcc42ab9dc601c72969fa5d4c9e8bac049476193cd1ffa8c568

Observation 2f405ee0-9e96-42d5-97a8-4e2301388037 · outbound

This paper cites Same model, different hat.

Rethinking Agent Security as a Networking Problem Same model, different hat

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.744203Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.476231Z digest=sha256:60b4140ec65d71d064cf2df678c57c8a1e0783907374c714de5a0f22ae0aa7e0

Observation cc114753-dc35-4cc2-8ee8-5baf3c84c28f · outbound

This paper cites cell- mate: Sandboxing browser ai agents.arXiv preprint arXiv:2512.12594, 2025.

Rethinking Agent Security as a Networking Problem cell- mate: Sandboxing browser ai agents.arXiv preprint arXiv:2512.12594, 2025

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.480555Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.480555Z digest=sha256:ee0fff465d33069af6535655ffa61517d4b867b26b458b89d79d43ca837a23ce

Observation 131827f3-1758-499a-9774-f03e7d663a3d · outbound

This paper cites Veriguard: Enhancing llm agent safety via verified code generation.arXiv preprint arXiv:2510.05156, 2025.

Rethinking Agent Security as a Networking Problem Veriguard: Enhancing llm agent safety via verified code generation.arXiv preprint arXiv:2510.05156, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.485071Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.485071Z digest=sha256:93a87c977ebd93c6292c6da45a2a3614ab969c0d358213cf86c27a62c106765a

Observation 50dfe044-bab5-4465-88c6-05ce4b5a19bb · outbound

This paper cites Can LLMs keep a secret? Testing privacy implications of language models via contextual in- tegrity theory.

Rethinking Agent Security as a Networking Problem Can LLMs keep a secret? Testing privacy implications of language models via contextual in- tegrity theory

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.728575Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.489966Z digest=sha256:101714cc3389793fafaf42be9d2aed62a25a618977f21007681dd3a95f98817d

Observation 9b6b5d19-4a5b-4f10-ac96-cdcf9726ff52 · outbound

This paper cites Myers and Barbara Liskov.

Rethinking Agent Security as a Networking Problem Myers and Barbara Liskov

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.713491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.495140Z digest=sha256:a4a2ae5a6f837680a4fab7cb7bd714f0c1e533f93e97d70fa1daeae5ddc45140

Observation 069a84aa-156b-461f-81c9-a4922b5f4b3b · outbound

This paper cites Omni-leak: Orchestrator multi-agent net- work induced data leakage.arXiv preprint arXiv:2602.13477, 2026.

Rethinking Agent Security as a Networking Problem Omni-leak: Orchestrator multi-agent net- work induced data leakage.arXiv preprint arXiv:2602.13477, 2026

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.499684Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.499684Z digest=sha256:a857271004d051400248ba2e8b43cad169cb63ad5ef48bc700bc7e9ff57d9669

Observation 5511faee-4228-44ad-9675-d5451e996a66 · outbound

This paper cites Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents.

Rethinking Agent Security as a Networking Problem Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.504149Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.504149Z digest=sha256:ef8e7e392652523fb85969723ed75dadd5dfb4c4c6e3fc139177eec117435f12

Observation 8ce2dff6-41c4-42ae-98b4-c42a38b1fe79 · outbound

This paper cites Privacy as contextual integrity.Washington Law Review, 79(1):119–157, 2004.

Rethinking Agent Security as a Networking Problem Privacy as contextual integrity.Washington Law Review, 79(1):119–157, 2004

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.699595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.509103Z digest=sha256:d2d233288f4f328304ab2e3c134535439ad61261da410b01448bc1cc0ecd9e80

Observation 4a089823-b7eb-4048-963d-ad3800069634 · outbound

This paper cites Why traditional security fails in the age of non- deterministic AI.

Rethinking Agent Security as a Networking Problem Why traditional security fails in the age of non- deterministic AI

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.685891Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.513767Z digest=sha256:15cee4bf0d42ec2a4f5277f7eb7c7d71624ad39604cbaac3a2ad9968db51a68a

Observation 3d25ab42-31cf-458e-94d5-2162e3228003 · outbound

This paper cites Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents.

Rethinking Agent Security as a Networking Problem Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.518336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.518336Z digest=sha256:d3a30c7be4764615ebb0bbc7c9a8b297cb87496d6f6c16fd2a952cc6ea67675a

Observation 9ab5920f-18cb-49f4-b5b9-91884042d05a · outbound

This paper cites Agentbay: A hybrid interaction sandbox for seamless human-ai intervention in agentic systems.arXiv preprint arXiv:2512.04367, 2025.

Rethinking Agent Security as a Networking Problem Agentbay: A hybrid interaction sandbox for seamless human-ai intervention in agentic systems.arXiv preprint arXiv:2512.04367, 2025

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.523086Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.523086Z digest=sha256:42efbb9c642d4c7e82b304d27b8183bc9d1d116802e4a4f4c94985f68252bbf3

Observation 921df08d-5ba6-4670-a5c6-4363430229fb · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

Rethinking Agent Security as a Networking Problem Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.527562Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.527562Z digest=sha256:6c2fedf15e51915d5c892b9f57b5b66acb2d56ce3cf4bcb80b55bb1d97741e58

Observation 2b87b12c-7b12-4222-bb91-42439fdce24d · outbound

This paper cites NeMo guardrails: A toolkit for controllable and safe LLM applications with programmable rails.

Rethinking Agent Security as a Networking Problem NeMo guardrails: A toolkit for controllable and safe LLM applications with programmable rails

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.672607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.532549Z digest=sha256:93531bec31c891d21bdc204750922a70730a5dbe78b85a1d78121254ca2937d9

Observation b8655260-9447-4835-b15f-934814a0e315 · outbound

This paper cites Zero trust architecture.

Rethinking Agent Security as a Networking Problem Zero trust architecture

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.657947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.537273Z digest=sha256:755dbf1b43f23088dbbe23bbca951275dc7adeb41a1564eb79d0c0ce69f44a05

Observation c3cf9970-a376-4692-9cd8-1ea295bc4162 · outbound

This paper cites Saltzer, David P.

Rethinking Agent Security as a Networking Problem Saltzer, David P

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.641760Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.541066Z digest=sha256:6c78c9178a5b86046d0eee71b5f0a532a4cd81139d591735b64734906cdc671b

Observation 38eed1c4-1e1e-456b-a39e-017d6868533b · outbound

This paper cites Saltzer and Michael D.

Rethinking Agent Security as a Networking Problem Saltzer and Michael D

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.625403Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.545194Z digest=sha256:f532d2a4fb7d95842834165a6a10cfc968628658cc84d61245e801dd71fa634a

Observation e940e040-cba9-4421-9736-6850d2a20f13 · outbound

This paper cites Sandhu, Edward J.

Rethinking Agent Security as a Networking Problem Sandhu, Edward J

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.610001Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.548940Z digest=sha256:0c0bc43f36f101ce28076609a6669dc99fd73f0d2e5b86228039db50e6fb2701

Observation 7a57f245-ebd7-4ee6-8e9c-2307eb25f17a · outbound

This paper cites Pri- vacyLens: Evaluating privacy norm awareness of language models in action.

Rethinking Agent Security as a Networking Problem Pri- vacyLens: Evaluating privacy norm awareness of language models in action

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.594727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.552823Z digest=sha256:377089a4862632d573dc17a4b92fe88ae014167415e1eb1dacb39206ce9bbe04

Observation e7da0d6e-0a99-42be-9729-2f18aa7f6977 · outbound

This paper cites Rollback-recovery for middleboxes.

Rethinking Agent Security as a Networking Problem Rollback-recovery for middleboxes

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.578873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.557035Z digest=sha256:1ff1e9ee364432a676d870d2acf3d0ee92dbc1c1fbd1e0c8eda97f6966864a24

Observation a2d74c86-6d82-4e25-9cc5-cfb8197de3e3 · outbound

This paper cites Making middleboxes someone else’s problem: Network processing as a cloud service.

Rethinking Agent Security as a Networking Problem Making middleboxes someone else’s problem: Network processing as a cloud service

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.563237Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.561326Z digest=sha256:711a4be93f73a9fac3663f79aafaf53a210f9dd54c7c8fb5d539cb48e709a9b4

Observation 35ffd793-4f73-4ec1-9e49-f064a3a4a900 · outbound

This paper cites BlindBox: Deep packet inspection over encrypted traffic.

Rethinking Agent Security as a Networking Problem BlindBox: Deep packet inspection over encrypted traffic

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.546824Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.565286Z digest=sha256:83672c2346390fcae465dd1e337aa53bfed0b7955210d459f6cd0fc47bbe9651

Observation 4ee59f58-654d-4619-8d57-9397e3a25186 · outbound

This paper cites Progent: Programmable privilege control for llm agents.arXiv e-prints, pages arXiv–2504, 2025.

Rethinking Agent Security as a Networking Problem Progent: Programmable privilege control for llm agents.arXiv e-prints, pages arXiv–2504, 2025

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.530999Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.570710Z digest=sha256:57fda1ff4ef972d9def52b489d6f7fa2fe830e30314d371182a2b83f54d713a1

Observation 2174ba0f-82f6-4ec8-af11-665a1b2323b0 · outbound

This paper cites From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors.

Rethinking Agent Security as a Networking Problem From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.575056Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.575056Z digest=sha256:be80ded529f6d54502efd52a7228989acc1408640527f4dd4b57acfd833e7f96

Observation bddfdab1-8b69-45c3-a993-89ccd1560a7f · outbound

This paper cites AI agents are becoming authorization bypass paths.

Rethinking Agent Security as a Networking Problem AI agents are becoming authorization bypass paths

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.513775Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.579775Z digest=sha256:a1cc17405a30163b456f1a1593947dae23cee72378dd907c9538c33d2dd72622

Observation 798cea79-2e4d-4e8e-ba7b-28b3843d9506 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Rethinking Agent Security as a Networking Problem The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.583963Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.583963Z digest=sha256:ee529e7cf17446290b7fc81419150ca05100207a24bef8ff0c68bc7d34d04c59

Observation 3cbe6a92-cb31-4c05-874e-93726b8777f5 · outbound

This paper cites Privacy in action: Towards realistic privacy mitigation and evaluation for LLM-powered agents.

Rethinking Agent Security as a Networking Problem Privacy in action: Towards realistic privacy mitigation and evaluation for LLM-powered agents

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.498000Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.588580Z digest=sha256:7dd9aa21ee5d9dd72575186c5fdd8a7ec23de0209cccea04aa9dcd5cd89bfef9

Observation 81453714-72fd-42b8-b3fc-6b302b4f9afc · outbound

This paper cites Sok: Evaluating jailbreak guardrails for large language models.

Rethinking Agent Security as a Networking Problem Sok: Evaluating jailbreak guardrails for large language models

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.482391Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.593006Z digest=sha256:d6defc9bca072f845881738b66e8ef05c9b96df7aa153964599d59ce83893c1d

Observation 55a336a1-8651-4753-8173-270eafd5b5e7 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

Rethinking Agent Security as a Networking Problem IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.597372Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.597372Z digest=sha256:184c09c0334f27ad6eb9e2ef8304764336063fd69cc56cd68606d6e89a22a881

Observation 74e8b5f8-adc1-4ee6-b059-2ff98c63d02e · outbound

This paper cites GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning.

Rethinking Agent Security as a Networking Problem GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.602071Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.602071Z digest=sha256:e086bf7ad86119bcb19b25bdc2f94b4d645a9a27782636245455bcc12105783f

Observation 4a45c84b-e8d1-4c47-81fc-feee9fb2654b · outbound

This paper cites SIFF: A stateless internet flow filter to mitigate DDoS flooding attacks.

Rethinking Agent Security as a Networking Problem SIFF: A stateless internet flow filter to mitigate DDoS flooding attacks

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.466718Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.607052Z digest=sha256:9737b8f0973c3e9dbc8049fefadfb4dd15447004a583ead87b6d27dea3b87cb6

Observation c3312728-17f5-4e05-8cba-74ada3c8feb5 · outbound

This paper cites A DoS- limiting network architecture.

Rethinking Agent Security as a Networking Problem A DoS- limiting network architecture

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.450831Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.611415Z digest=sha256:a651c51398167bf60f10646912b1de2a5e11d3b8722ee97084739ebab2a26ddd

Observation b02123c1-dbfb-497b-a416-dee577e8c4a3 · outbound

This paper cites ReAct: Synergizing reasoning and acting in language models.

Rethinking Agent Security as a Networking Problem ReAct: Synergizing reasoning and acting in language models

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.616158Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.616158Z digest=sha256:b7febf2b5ade71fd63ecb021ec2e6ea2a1f65b133855772e308d9be15ad6d459

Observation d749151e-5914-4f48-8875-690664504b3c · outbound

This paper cites Temporal dynamics of mem- ory poisoning in web3-style llm agents.IEEE Access, 2026.

Rethinking Agent Security as a Networking Problem Temporal dynamics of mem- ory poisoning in web3-style llm agents.IEEE Access, 2026

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.425044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.620509Z digest=sha256:4b1e8137db718be665579d00ff24bf8f94628c78d990537147b11ba59413290a

Observation 524731c4-3e4c-4b1a-bd71-5b83f9c00d9c · outbound

This paper cites Making information flow explicit in HiStar.

Rethinking Agent Security as a Networking Problem Making information flow explicit in HiStar

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.409351Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.625041Z digest=sha256:31041d0e3c85d3c5539adb5add0b8c282732d850453bd228944ffae5056a1a01

Observation 26f6f9af-a124-467e-b693-d47653751744 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large lan- guage model agents.

Rethinking Agent Security as a Networking Problem Injecagent: Benchmarking indirect prompt injections in tool-integrated large lan- guage model agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.629850Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.629850Z digest=sha256:a63dc00b1c1578e70e6b58ed18b656262a421aeffd47f0c02c4bd4d084254a48

Observation e9121ddc-0084-4c58-b0a5-a12b43efabfc · outbound

This paper cites Towards Action Hijacking of Large Language Model-based Agent.

Rethinking Agent Security as a Networking Problem Towards Action Hijacking of Large Language Model-based Agent

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.634434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.634434Z digest=sha256:7772be59ee9fdcea6a1e0d63957bd9ad81e69f2e1085cc245b1704c49141b9fe

Observation fe36e78b-b5bf-4996-8d88-d11f94fc0f72 · outbound

This paper cites AgentDAM: Privacy leakage evaluation for autonomous web agents.

Rethinking Agent Security as a Networking Problem AgentDAM: Privacy leakage evaluation for autonomous web agents

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.382866Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.639378Z digest=sha256:28d11c7274ece75991d31bd94c787338404cf490e87b25ffbc54374fe4c05f73

Observation 8e10ec44-80f8-4ff2-94f6-1c098895bc68 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

Rethinking Agent Security as a Networking Problem RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.643873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.643873Z digest=sha256:c1baf1313cf9c9bf1e9e9afb23faeded037d4d7c881443f360094c5032c0a4a8

Observation a11e147c-8315-4aff-9114-684a09cfc24b · outbound

This paper cites Rescriber: Smaller- LLM-powered user-led data minimization for LLM-based chatbots.

Rethinking Agent Security as a Networking Problem Rescriber: Smaller- LLM-powered user-led data minimization for LLM-based chatbots

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.363098Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.648792Z digest=sha256:c7f0dd925b2c7ae9002f62c00db66a6960d8c9300c2483389c2b68fed141f540

Observation 97d3c3fa-887f-4d8e-bf85-d9d2c3c98277 · outbound

This paper cites CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities.

Rethinking Agent Security as a Networking Problem CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.653903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.653903Z digest=sha256:982f10edf501b3d28045218b36719b1870c586198784b7d1b182cf289ab7576d

Observation 51282d5b-1aa8-4e13-afdd-045001046885 · outbound

This paper cites an unresolved cited work.

Rethinking Agent Security as a Networking Problem Unresolved cited work

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.318565Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.318565Z digest=sha256:125e670fa9f38fbbc5e9429ab16840a75ccfb8f63db2954de2f7ae1f4b19f99a

Pith citing papers

No inbound Pith citation observations are available.