Pith. sign in

Paper Citation Record · LEDGER

Prompt Injection 2.0: Hybrid AI Threats

As of 23 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 5 inbound Pith citation observations for arXiv:2507.13169.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.13169 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 5 of 5 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T17:12:27.840223Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-22T12:51:33.393440Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact2
  • verified fuzzy1
  • unresolved25
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation e22e7f76-32cd-4cb3-869f-3183830e0afa · outbound

This paper cites Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples.

Prompt Injection 2.0: Hybrid AI Threats Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.088522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.088522Z digest=sha256:395675e422834e173a148513bf22047918637741ad16ea59f80b9b2271d7e38e

Observation 28fbf030-816c-41ff-903c-2df09f0a7f9c · outbound

This paper cites C., & Heichman, R.

Prompt Injection 2.0: Hybrid AI Threats C., & Heichman, R

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T16:34:08.065627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:03.214886Z digest=sha256:61eeb61fa6761922e6ddfdd246a3fc0b78c9728db0c360704f311773d19498e2

Observation 4ba24e3f-f487-4b02-a626-63b6ad009055 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Prompt Injection 2.0: Hybrid AI Threats Prompt Injection attack against LLM-integrated Applications

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.313953Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.313953Z digest=sha256:9b75a726054aafa19b4cc2689f30edb6b0e4650622eb54ccbe1e5284902ece8e

Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.407180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.407180Z digest=sha256:88f34c7c8da1eb17f896d0aa8cc63b74858bdbf16a6aa04623eb85a122810990

Observation 2c8e481a-6979-4c1e-91d7-eb514330e081 · outbound

This paper cites From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?.

Prompt Injection 2.0: Hybrid AI Threats From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.503194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.503194Z digest=sha256:edd38902e5f713512b11c844875a36ae26789d23f3edda13fb28cc94912ad9ff

Observation 81b7056d-e92d-4262-a83a-cfadff70051b · outbound

This paper cites AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development.

Prompt Injection 2.0: Hybrid AI Threats AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.402350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:03.624743Z digest=sha256:8fafcd7a358bfb39ec34d93000ff602b7a5777bfa395ca833ec01ba0224d1fee

Observation 74108fff-12a9-4135-8e67-a6a18bca8085 · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

Prompt Injection 2.0: Hybrid AI Threats Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.695223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.695223Z digest=sha256:5310e60462cd66f576c1795c60dee9b5f18b60a9971ba75a5c3572a214685bcb

Observation 9ffcd4e8-6f3c-4856-9cce-4421416681fa · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 8

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.818080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:03.778176Z digest=sha256:11e287d33bee5794be1342e1d92ff0a0f2dba243df4fe102de0286ff058665e6

Observation 67a374ee-c085-4de3-abb1-fb82d9c1fefe · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Prompt Injection 2.0: Hybrid AI Threats Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.842222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.842222Z digest=sha256:a6aa356c25d31bc8c7ac2d1ed18ba38969d80e7eb4a1e5fc87132273f12fd110

Observation 7f4cdc41-655f-434b-9be2-a74bc3172ba9 · outbound

This paper cites Defeating Prompt Injections by Design.

Prompt Injection 2.0: Hybrid AI Threats Defeating Prompt Injections by Design

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.919189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.919189Z digest=sha256:36007f18ce921247298e31147fb717b7d5acdb4d93af3922c3250acbb971c11b

Observation 1c073cff-1405-48a5-91aa-b7a78fc582b7 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 11

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.505229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:04.001119Z digest=sha256:e9a4701b6e3033e895dd72b42f7b5bd898b8b15a892353ec860b68ade31e2b75

Observation 43d9d6d4-67cb-4608-89d9-d5c6532faf25 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.307622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:04.096370Z digest=sha256:14cf67dec48638b739c1829adcd77938a9928272bd561dae40c9ce587fb45ac4

Observation 0c024737-d7c3-4a78-9b2f-f2c999750230 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 13

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.022398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:04.192243Z digest=sha256:98b136c6c7eda4c365f5fdb55f4ba2cae11f92fe331e0ad5cd676874c7ff348a

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:d5569044ed6428281c4a922308485df5141592db5c90cc9a406677a625e3373f

Observation 932b69ab-e882-49e0-a697-a9bbcf822bb9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.877652Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:04.375475Z digest=sha256:59c6208c488b4addb3aa52abcf5478c85bf36b39b1b03b93b0c212f77ec7cf88

Observation e379a488-61be-486e-b10a-30e052f70bbd · outbound

This paper cites XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants.

Prompt Injection 2.0: Hybrid AI Threats XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.094966Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:04.450450Z digest=sha256:5e870d3d338771741a1cabee44d4f42601dc7e43ddd9d83c9e10883968ec9018

Observation 97ca63c5-25a5-4980-94cb-1c29107c98e0 · outbound

This paper cites The Hidden Dangers of Browsing AI Agents.

Prompt Injection 2.0: Hybrid AI Threats The Hidden Dangers of Browsing AI Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.510763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.510763Z digest=sha256:695d348748e49aaa535aea97a86776bc8d9f08aabcd10f7cddc7bad2b3af31f3

Observation 48ce344e-7e62-45bd-8d86-18374023e328 · outbound

This paper cites Learning to Poison Large Language Models for Downstream Manipulation.

Prompt Injection 2.0: Hybrid AI Threats Learning to Poison Large Language Models for Downstream Manipulation

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.598552Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.598552Z digest=sha256:1593db3187e631283955257845790878b09fdbb25ad1f28f40c7a5de92c6b514

Observation fb31b710-e5d8-497a-9bb8-b335be88601d · outbound

This paper cites Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.667309Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.667309Z digest=sha256:11c7bb8e919a5da714f5195cf12f2c867c3dba4c7d532a81f6935faf09d4a405

Observation 8a60a853-a16d-4b30-beb5-e095804b0e30 · outbound

This paper cites Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.754226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.754226Z digest=sha256:5ec842867836052fc2a5c0f52f1c5698a69310978b9dc77303256c6cb930ef20

Observation fbe5eca5-fc2b-4390-98d2-c32b7d9b82ac · outbound

This paper cites Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.853306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.853306Z digest=sha256:c0b08aa5fbf60de4d85e17a3d7a166fd395fd65dc4bb4ad3bfdff28267273712

Observation 2a247095-3659-4852-b88a-22fed94a42b8 · outbound

This paper cites Manipulating Multimodal Agents via Cross-Modal Prompt Injection.

Prompt Injection 2.0: Hybrid AI Threats Manipulating Multimodal Agents via Cross-Modal Prompt Injection

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.952025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.952025Z digest=sha256:fe695d6c392218f2acf514b1182472ec6e570a1ee485505d5dc70f19963d1157

Observation 6514fbca-975f-4253-a587-05efbc389ff9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.771915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:05.011939Z digest=sha256:713890700658da55c9fd6094f9f8ab8ae5490cf0a9e0b8eb5eea9122f536d474

Observation 80107157-42c9-4510-a17b-5ec0990ce669 · outbound

This paper cites Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs.

Prompt Injection 2.0: Hybrid AI Threats Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.101373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.101373Z digest=sha256:12a6c8f938cd24286cca5f8d4d6a584e5add371a4fdb0293d3482006e59269ba

Observation 711b04e6-a84a-4b06-8648-54f847ee47d8 · outbound

This paper cites Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition.

Prompt Injection 2.0: Hybrid AI Threats Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.169846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.169846Z digest=sha256:68f7f0a75a491414e8fba142864bdf9635d655e5382f4d81653245680c7a6f54

Observation 901f6257-6605-4160-b812-d5c36cc18a4a · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 26

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T16:34:06.657603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-06T16:34:05.255867Z digest=sha256:94b0898f6459d1ae307b16e3764e5723f970a38785428614b476c283ac57c413

Observation 53d2c546-ea9f-4636-bf87-72f6c0317db7 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

Prompt Injection 2.0: Hybrid AI Threats LLM Agents can Autonomously Hack Websites

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.325342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.325342Z digest=sha256:bb58b9152c0ba70661567a74d3bfd1c3def62e85a91d6b28a9f42a7595ed1dbc

Observation 4a6efbb7-8971-44ae-aabf-67ad24ecb2ae · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.379319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.379319Z digest=sha256:a7f7085f7809c09a810c67ebf20d698039f673eb10207e51f86af05891415d9c

Observation 8a6b4405-be54-4aaf-bad0-de88deabf587 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Prompt Injection 2.0: Hybrid AI Threats Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.446734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.446734Z digest=sha256:1c90d56062a549ee6a62709b7e92baf4734d5f73359bdf88bd5764d0f1b3b8c5

Pith citing papers

Observation 51c7b986-b513-4390-95db-b9db5eb0b004 · inbound

POT: Inducing Overthinking in LLMs via Black-Box Iterative Optimization cites this paper.

POT: Inducing Overthinking in LLMs via Black-Box Iterative Optimization Prompt Injection 2.0: Hybrid AI Threats

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-15T17:12:27.840223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T17:12:27.840223Z digest=sha256:aa64317257227afd2baf14762fdfb7300305cd8d465c6319e4e094bf2cb04342

Observation e5e416d9-e605-440c-b626-69eb3f50bd19 · inbound

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities cites this paper.

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Prompt Injection 2.0: Hybrid AI Threats

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-18T18:06:43.025006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-18T18:04:09.528381Z digest=sha256:09469d32ee9de3ed4066fe0badf377a5f9570b3fb324a80cf71e86da9245bdf4

Observation 406e2f80-5836-4e26-8605-0a1161a23245 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Prompt Injection 2.0: Hybrid AI Threats

Reference 61

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.431852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:d9219179470d6f974884b35fa0f9c155d545e9c3ec1188bd327663c270fbb6d7

Observation 621df737-31d9-4a80-9d4e-e92f691c623e · inbound

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation cites this paper.

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Prompt Injection 2.0: Hybrid AI Threats

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:51:33.396810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-22T12:46:44.819224Z digest=sha256:1bfcecb2b865ce37c0677adf53d8b8ce5a765ac9bbdabe23d6192f6913f4d0b9

Observation 3e6f750e-bd37-43e2-be17-717b63583de1 · inbound

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis cites this paper.

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis Prompt Injection 2.0: Hybrid AI Threats

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-11T04:15:53.991771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T04:15:53.991771Z digest=sha256:b7a1c0a56fb321659dde644cce72555c9aa84c77448284084cefc16c4875ffa8