Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T15:07:27.137476Z
Paper Citation Record · LEDGER
As of 14 August 2026, this Paper Citation Record lists 23 of 23 outbound references and 0 inbound Pith citation observations for arXiv:2607.19432.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T15:07:27.137476Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
23 of 23 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 297ecb51-a18b-4f54-92bf-ea852bf64b3f · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Introducing the Model Context Protocol,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7fcd43c2-53aa-4586-b12f-09ea20480fdb · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 04849e86-e6cb-4d28-b1be-e6afc5c30c46 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP Security Notification: Tool Poison- ing Attacks and GitHub MCP Prompt Injection,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf71caf9-db01-46bd-968c-f1304c3ddaaa · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems WhatsApp MCP Exploited via Rug-Pull At- tack,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0881bdf9-edf7-46d9-bf0c-d7d0962ec40f · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems STAC: When Innocent Tools Form Dangerous Chains for LLM Agents
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 65f1943e-24c4-473c-9887-ab358dc24999 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems The Promptware Kill Chain,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b5ead94-6e06-456a-a533-e26dd79ef1c2 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCPShield: A Security Cognition Layer for Adaptive Trust Calibration in Model Context Protocol Agents,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f1ba299a-d8ca-40a0-93da-835264868d79 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 00143c95-048a-4af2-a9b5-3d83aadadea0 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MindGuard: Tracking, Detecting, and Attributing MCP Tool Poisoning Attack via Decision Dependence Graph,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5d1b7a0b-8918-4914-97de-e8df3ed51067 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCPTox: A Benchmark for Tool Poisoning on Real-World MCP Servers,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ac9760dd-fcee-4ada-9c1f-9d509e6b9ad9 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5160222a-3cc9-4d01-9c55-94a5df232b4b · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems A systematic survey on multi- step attack detection,
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 773bc88e-6868-40d6-8314-ee3e5b2081b4 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Real-time multistep attack prediction based on hidden Markov models,
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a689a81e-7bc8-4f53-a1c5-e2e4fb0545ef · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems KAIROS: Practical Intrusion Detection and Investigation using Whole- system Provenance,
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3205e2af-fccb-4420-b4f0-10af8a31d27b · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MAAC: Multi-step Attack Alert Correlation using Semantic Vectorization,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 419dc962-5f29-4880-9bb4-9ac28e2d0310 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f8e68bd0-9940-4d46-a07c-075d574fcc25 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real- World MCP Servers,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bba5fd3a-39c3-46de-b413-da05b33b197e · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 81f4d9d6-bcbd-4dce-a97d-b887707ba0fe · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Temporal Attack Pattern Detection in Multi-Agent AI Workflows: An Open Framework for Training Trace-Based Security Models,
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 480047d8-bc68-41a9-a14e-5ea1cdd6f4c3 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 11ef57fd-0de9-4141-a9b8-845aaf3494d7 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Cross-Agent Privilege Escalation: When Agents Free Each Other,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8c0ed8bd-ff51-4e02-b3e7-88c98fe23732 · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Poison Everywhere: No Output from Your MCP Server is Safe,
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a8fa1f76-858c-4d0a-8631-7fbab9b279bb · outbound
ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Available: https://www.anthropic.com/news/ model-context-protocol
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.