Pith. sign in

Paper Citation Record · LEDGER

Rethinking Agent Security as a Networking Problem

As of 17 August 2026, this Paper Citation Record lists 77 of 77 outbound references and 0 inbound Pith citation observations for arXiv:2608.12172.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.12172 v1

Coverage vector

measured 77 of 77 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-16T00:16:52.653903Z

measured 77 of 77 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

77 of 77 outbound references displayed

  • verified exact0
  • verified fuzzy46
  • unresolved31
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 307f55f9-9df6-44ed-9392-4dd75055892e · outbound

This paper cites Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution.

Rethinking Agent Security as a Networking Problem Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.303564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.303564Z digest=sha256:a0e96cf463e167faa1e98a253e00225693d8a913d85a637c6e26a86f0deef1b7

Observation 75af99fd-35b9-45be-bb0e-539c3b19fb0a · outbound

This paper cites Model context protocol.

Rethinking Agent Security as a Networking Problem Model context protocol

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.138420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.309227Z digest=sha256:f68f053c3171ba9ecde878fcff8caac5a904ef6756af985f96dfdad3a2f6133f

Observation 7bc4a230-bca9-4d4e-90b1-0e0bda6b742d · outbound

This paper cites Air- GapAgent: Protecting privacy-conscious conversational agents.

Rethinking Agent Security as a Networking Problem Air- GapAgent: Protecting privacy-conscious conversational agents

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.123389Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.313941Z digest=sha256:dd04bb78b0567995af75494c6268c760c9c92ad5f60e8be82f2c8d3837d92f7e

Observation 085a062e-7873-4d4d-87bf-6f2a28a46938 · outbound

This paper cites Off by default! InProceedings of the 4th ACM Workshop on Hot Topics in Networks (HotNets-IV), College Park, MD, 2005.

Rethinking Agent Security as a Networking Problem Off by default! InProceedings of the 4th ACM Workshop on Hot Topics in Networks (HotNets-IV), College Park, MD, 2005

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.098945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.323520Z digest=sha256:ce25d0bac1cc8911cf754106573ee56e0c47e77bd90ffb4d3b20fa13f75adf1f

Observation ac23da05-14a3-4f9e-ba6b-6351207f1f80 · outbound

This paper cites Freedman, Justin Pettit, Jianying Luo, Nick McKeown, and Scott Shenker.

Rethinking Agent Security as a Networking Problem Freedman, Justin Pettit, Jianying Luo, Nick McKeown, and Scott Shenker

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.083703Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.328579Z digest=sha256:626b977dd6440d6317eedae9f9267eb2dcfceeec84fd0a672a5e138922a04de1

Observation 9742d581-a98e-4778-9ff6-d7453dbaab05 · outbound

This paper cites Freedman, Dan Boneh, Nick McKeown, and Scott Shenker.

Rethinking Agent Security as a Networking Problem Freedman, Dan Boneh, Nick McKeown, and Scott Shenker

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.069453Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.334111Z digest=sha256:4550f5bee699fcc8d055b7a0dd177e0bdefc6e1ec99bb72a77f1e4dab2364cce

Observation 22ba1fa3-3d01-42f6-a726-dacd082a736b · outbound

This paper cites {StruQ}: Defending against prompt injection with structured queries.

Rethinking Agent Security as a Networking Problem {StruQ}: Defending against prompt injection with structured queries

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.054036Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.339433Z digest=sha256:3482055d95a34669e89b42ecc4b099a0a07c2d16765c288f6bad95af41e1ee46

Observation 0fb0ed77-c5b1-4fcf-97e5-3e97c8b89892 · outbound

This paper cites Secalign: Defending against prompt injection with preference optimization.

Rethinking Agent Security as a Networking Problem Secalign: Defending against prompt injection with preference optimization

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.344313Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.344313Z digest=sha256:4ab4e329ed098aa8c70f77d09bad4b530ab7dc4917812a95d252eb0c6fd445cf

Observation 0334ae0a-09da-44dc-9871-32a9fb6b030c · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowl- edge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

Rethinking Agent Security as a Networking Problem Agentpoison: Red-teaming llm agents via poisoning memory or knowl- edge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.348775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.348775Z digest=sha256:317feeafff67ec7b78a494bdbff4c5b88cdeba858e48eb7df8765de6c11bb15f

Observation b36724f7-1f7b-4d93-9381-ed66a003bfb7 · outbound

This paper cites Overprivileged by design: AI agents as cloud escalation vectors.

Rethinking Agent Security as a Networking Problem Overprivileged by design: AI agents as cloud escalation vectors

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.020107Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.353237Z digest=sha256:dd9e59bd3bfa4d6e4a40b8318dda97fd651f5868394f927dd2db9c4d8ec39f60

Observation 10c52286-c590-4493-99a8-3e7a23025f32 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Rethinking Agent Security as a Networking Problem Securing AI Agents with Information-Flow Control

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.357689Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.357689Z digest=sha256:0cb0e8cae023809924df0fd8caf559b473dd30197dc240cbb930ef195c6623a0

Observation 4d423be8-c845-4d2b-ad13-3306bed23c1e · outbound

This paper cites Defeating Prompt Injections by Design.

Rethinking Agent Security as a Networking Problem Defeating Prompt Injections by Design

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.362927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.362927Z digest=sha256:7a1e2120ae0e0facee251a557dea3913f3e155a7bc68746a956bc0577c07a654

Observation 1a09a59c-fecb-44a5-a867-1443ac50449a · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents.

Rethinking Agent Security as a Networking Problem AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:54.005425Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.367655Z digest=sha256:427b24be4daf340985a1d5979c8c3dfaab2079cba0285e58eb03fecc25f21bed

Observation 5d732177-794b-4a5f-a7fe-332b5dd6d2f2 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 57(7):1–36, 2025.

Rethinking Agent Security as a Networking Problem Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 57(7):1–36, 2025

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.372005Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.372005Z digest=sha256:809d725bccf9c6488c793335adf343e88fa20bb91a0f485504c0043eb5e29fda

Observation 14a28adc-8e32-4b04-8a6f-ca792ee3b9cc · outbound

This paper cites an unresolved cited work.

Rethinking Agent Security as a Networking Problem Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-16T00:16:53.980500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.376540Z digest=sha256:c1fdf48bc3c8d892ee72d5621c1610e14627145fe2e7c8617f77dc0eaaf97e37

Observation abdb78e1-07bf-4c0c-ad3f-540f869ee3ae · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction.Advances in Neural Information Processing Systems, 38:46697–46731, 2026.

Rethinking Agent Security as a Networking Problem Memory injection attacks on llm agents via query-only interaction.Advances in Neural Information Processing Systems, 38:46697–46731, 2026

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.965986Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.381100Z digest=sha256:5bbaf36f41f3dc5b9a16c022a183ce1970506bcebf8b7240cbb6f756e832dc77

Observation afa7f544-284d-42f7-80a1-682cc86e9981 · outbound

This paper cites Towards verifiably safe tool use for llm agents.

Rethinking Agent Security as a Networking Problem Towards verifiably safe tool use for llm agents

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.952047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.385629Z digest=sha256:3857e36cacf62b13a8efadf0ed281766e930d782a5d8b3b49f046d266b141c17

Observation a96d1fef-c4fd-498d-b08e-444032087434 · outbound

This paper cites AgentLeak: A full-stack benchmark for privacy leakage in multi-agent LLM systems.arXiv preprint arXiv:2602.11510, February 2026.

Rethinking Agent Security as a Networking Problem AgentLeak: A full-stack benchmark for privacy leakage in multi-agent LLM systems.arXiv preprint arXiv:2602.11510, February 2026

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.389986Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.389986Z digest=sha256:1135eb3fbcf2232c7dbb1be7ac0b4c7fdab52948f6d0633902166c2807301a7d

Observation 47c471bd-da43-4778-987e-87ab27143bc4 · outbound

This paper cites Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems, 38, 2026.

Rethinking Agent Security as a Networking Problem Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems, 38, 2026

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.937836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.394299Z digest=sha256:0e017bae49af9b6be7fce05cf97850ecc28967726de038a54cf1e125ce689d8d

Observation bd14a932-ea5c-4abf-beac-791911997f00 · outbound

This paper cites AI agents are the biggest data security threat you’re not governing.

Rethinking Agent Security as a Networking Problem AI agents are the biggest data security threat you’re not governing

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.922661Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.398764Z digest=sha256:ce51098189da4a81cad3edd7c3ab1b77131f5244fdd2dd4e48a98119cd2732ba

Observation 805acb9c-2d57-4b25-8f79-b61dc624336f · outbound

This paper cites Agent2agent (A2A) protocol.

Rethinking Agent Security as a Networking Problem Agent2agent (A2A) protocol

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.907836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.403122Z digest=sha256:7f2708c32de683540e5b3efc4b484dff0152866505f47befab33bd69134931c1

Observation 3274f44a-94e6-4713-bd52-2347f864e27d · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection.

Rethinking Agent Security as a Networking Problem Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.892852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.407983Z digest=sha256:5ea92592c2ddc1d0d4fa0e64122e1b921089a8266bafa20cd6c4b06d17e68075

Observation 14e2ac38-18e9-4ab8-a80b-8296a1587c9a · outbound

This paper cites Bypassing LLM guardrails: An empirical analysis of eva- sion attacks against prompt injection and jailbreak detection systems, 2025.

Rethinking Agent Security as a Networking Problem Bypassing LLM guardrails: An empirical analysis of eva- sion attacks against prompt injection and jailbreak detection systems, 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.878294Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.412448Z digest=sha256:b6435dab8df3c0b9b3021a45f78116813d542e417acfce1801aaa7353466e00c

Observation 096b3df7-3605-4b26-9a17-35957152ba5c · outbound

This paper cites The OAuth 2.0 authorization framework.

Rethinking Agent Security as a Networking Problem The OAuth 2.0 authorization framework

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.864145Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.417816Z digest=sha256:d48598289973f890e0703e25f066f6eec76ca48dc028d876b1f3357d2f2bb2c8

Observation 42e92a12-2d7e-4a9f-9608-4b5405e86323 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Rethinking Agent Security as a Networking Problem Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.422410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.422410Z digest=sha256:01a9ccebc6dbb7a1ffcc4b98ba43265fb3abc89c014eeec7debf00817316ce15

Observation ad8ee4e6-8e34-41c1-9042-17c252d61947 · outbound

This paper cites Break- ing and fixing defenses against control-flow hijacking in multi-agent systems.arXiv preprint arXiv:2510.17276, 2025.

Rethinking Agent Security as a Networking Problem Break- ing and fixing defenses against control-flow hijacking in multi-agent systems.arXiv preprint arXiv:2510.17276, 2025

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.426857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.426857Z digest=sha256:98bb9fb1da83ecbe8b227dacb228728fc22b207530b58819ba63d323fee5c3e9

Observation 6e52efd2-8208-4a1e-921e-7b31bea700d2 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents.

Rethinking Agent Security as a Networking Problem The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.846847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.430727Z digest=sha256:9c28e9a10d4043b92b54673f1d685e3b6c64d497111de0c73f99604f9a4e563d

Observation 304440f1-a086-4495-a037-cd6867237972 · outbound

This paper cites A Critical Evaluation of Defenses against Prompt Injection Attacks.

Rethinking Agent Security as a Networking Problem A Critical Evaluation of Defenses against Prompt Injection Attacks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.434773Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.434773Z digest=sha256:beb4fb2027d59a32c3cf85c4c789068684618f39f3d5ecca0f53584fbedc552e

Observation 3fa22a94-faa1-4e26-89f4-769eb59c2aef · outbound

This paper cites When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents.

Rethinking Agent Security as a Networking Problem When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.438925Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.438925Z digest=sha256:785b42366b2ba379b13ded3ee2472ade8908c3d5bcf2686807b645a1b04e9183

Observation d9f6ab40-a906-4dc3-bcbc-96f77a87229d · outbound

This paper cites Frans Kaashoek, Eddie Kohler, and Robert Morris.

Rethinking Agent Security as a Networking Problem Frans Kaashoek, Eddie Kohler, and Robert Morris

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.831339Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.444062Z digest=sha256:1e79d1ad5531dac921aacdf412c3d1be400dfd46f3249f9c3ef6c7e2f498803e

Observation bbbe41cc-bd09-411d-bdb0-31dba52f50a1 · outbound

This paper cites Lakera guard.

Rethinking Agent Security as a Networking Problem Lakera guard

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.816326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.448593Z digest=sha256:ebec486cf3aa79947b6025b40c9bbeff23accae9094fb4e7aac4b0fac85eed24

Observation 278e6b90-2561-48ca-80ea-0f884286fc83 · outbound

This paper cites Inan, Sahar Abdelnabi, Janardhan Kulka- rni, Lukas Wutschitz, Reza Shokri, Christopher G.

Rethinking Agent Security as a Networking Problem Inan, Sahar Abdelnabi, Janardhan Kulka- rni, Lukas Wutschitz, Reza Shokri, Christopher G

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.800917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.452882Z digest=sha256:eaea3319d8dbf57ee25d70663c54f11256ea35ec7dca50d3efcd225dd2c8e95e

Observation c532226d-88ca-4992-b06f-1d85fee1064c · outbound

This paper cites Improving google a2a protocol: Protecting sensitive data and mitigating unintended harms in multi-agent systems.ACM Transactions on Software Engineering and Methodology, 2025.

Rethinking Agent Security as a Networking Problem Improving google a2a protocol: Protecting sensitive data and mitigating unintended harms in multi-agent systems.ACM Transactions on Software Engineering and Methodology, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.785731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.457328Z digest=sha256:e7670e1163d51934253514b30c9dbfa5e37aae03ee3be9f5c5b73c63fc49e96c

Observation e45143a1-69f0-49d0-871a-87ea66245a92 · outbound

This paper cites ClawLess: A Security Model of AI Agents.

Rethinking Agent Security as a Networking Problem ClawLess: A Security Model of AI Agents

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.461950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.461950Z digest=sha256:76279dc0c671a35b6d2337eb90f1f84844789f9f9a550342e2f92fb1c4aac829

Observation 090b13fd-312f-4d4d-83f9-4f61e491471e · outbound

This paper cites Agentauditor: Human-level safety and security evaluation for llm agents.Advances in Neural Information Processing Systems, 38:43241–43298, 2026.

Rethinking Agent Security as a Networking Problem Agentauditor: Human-level safety and security evaluation for llm agents.Advances in Neural Information Processing Systems, 38:43241–43298, 2026

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.466663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.466663Z digest=sha256:a4ca88cc054e0c36f490eae305b18004926c1b6e37bcf0ebcda42b5af721566d

Observation 442b940f-952c-4a86-a9d5-1b2a443258f3 · outbound

This paper cites A holistic approach to undesired content detection in the real world.Proceedings of the AAAI Conference on Artificial Intelligence, 37(12):15009–15018, 2023.

Rethinking Agent Security as a Networking Problem A holistic approach to undesired content detection in the real world.Proceedings of the AAAI Conference on Artificial Intelligence, 37(12):15009–15018, 2023

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.759446Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.471715Z digest=sha256:71157f3146d2b8615e679eaad2a79118827ff1164db4c46319fa97e6f291f50b

Observation 2f405ee0-9e96-42d5-97a8-4e2301388037 · outbound

This paper cites Same model, different hat.

Rethinking Agent Security as a Networking Problem Same model, different hat

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.744203Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.476231Z digest=sha256:aeb48a5a456269ae684a4a3fed269dbcf15f0f496d9530d05e5e7284a349532e

Observation cc114753-dc35-4cc2-8ee8-5baf3c84c28f · outbound

This paper cites cell- mate: Sandboxing browser ai agents.arXiv preprint arXiv:2512.12594, 2025.

Rethinking Agent Security as a Networking Problem cell- mate: Sandboxing browser ai agents.arXiv preprint arXiv:2512.12594, 2025

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.480555Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.480555Z digest=sha256:2152740012cda589e0b4faa0177b82beab11d36937df25de0fb1fba06ccf6d5a

Observation 131827f3-1758-499a-9774-f03e7d663a3d · outbound

This paper cites Veriguard: Enhancing llm agent safety via verified code generation.arXiv preprint arXiv:2510.05156, 2025.

Rethinking Agent Security as a Networking Problem Veriguard: Enhancing llm agent safety via verified code generation.arXiv preprint arXiv:2510.05156, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.485071Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.485071Z digest=sha256:5fcc43806bed8542967f78a78bca661c7fb72f7cd90660fccf67434c2a31d974

Observation 50dfe044-bab5-4465-88c6-05ce4b5a19bb · outbound

This paper cites Can LLMs keep a secret? Testing privacy implications of language models via contextual in- tegrity theory.

Rethinking Agent Security as a Networking Problem Can LLMs keep a secret? Testing privacy implications of language models via contextual in- tegrity theory

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.728575Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.489966Z digest=sha256:f9859c024ae7f3ea030bf2df3cdc91c94e5aa055262d56a3d11c83630ddbece5

Observation 9b6b5d19-4a5b-4f10-ac96-cdcf9726ff52 · outbound

This paper cites Myers and Barbara Liskov.

Rethinking Agent Security as a Networking Problem Myers and Barbara Liskov

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.713491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.495140Z digest=sha256:5c6bb8e2d433ffcbd7f52d6648cc3fcb1c55fb3250b3abf183c134ebf8966b74

Observation 069a84aa-156b-461f-81c9-a4922b5f4b3b · outbound

This paper cites Omni-leak: Orchestrator multi-agent net- work induced data leakage.arXiv preprint arXiv:2602.13477, 2026.

Rethinking Agent Security as a Networking Problem Omni-leak: Orchestrator multi-agent net- work induced data leakage.arXiv preprint arXiv:2602.13477, 2026

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.499684Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.499684Z digest=sha256:ddde05826fff7c867c80371ef58294440cf7ea84606bc74dd676f637b923fc1a

Observation 5511faee-4228-44ad-9675-d5451e996a66 · outbound

This paper cites Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents.

Rethinking Agent Security as a Networking Problem Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.504149Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.504149Z digest=sha256:d8543987fe92f58134668423ef2cba84c411d1084abc6ae713c18633af0b53ee

Observation 8ce2dff6-41c4-42ae-98b4-c42a38b1fe79 · outbound

This paper cites Privacy as contextual integrity.Washington Law Review, 79(1):119–157, 2004.

Rethinking Agent Security as a Networking Problem Privacy as contextual integrity.Washington Law Review, 79(1):119–157, 2004

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.699595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.509103Z digest=sha256:ab6095e7ec1b8eb83bbbd89d22e072b629c6c89fc5577b673890f9057409c283

Observation 4a089823-b7eb-4048-963d-ad3800069634 · outbound

This paper cites Why traditional security fails in the age of non- deterministic AI.

Rethinking Agent Security as a Networking Problem Why traditional security fails in the age of non- deterministic AI

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.685891Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.513767Z digest=sha256:542c3cc3a24ae3eeda0288b9075af2e0cadaa27bef248ded673da2dd1da1a1f0

Observation 3d25ab42-31cf-458e-94d5-2162e3228003 · outbound

This paper cites Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents.

Rethinking Agent Security as a Networking Problem Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.518336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.518336Z digest=sha256:8edd288686348af79f6fcdc5b6acf692d64d9341f8cb4d702997986f9f780679

Observation 9ab5920f-18cb-49f4-b5b9-91884042d05a · outbound

This paper cites Agentbay: A hybrid interaction sandbox for seamless human-ai intervention in agentic systems.arXiv preprint arXiv:2512.04367, 2025.

Rethinking Agent Security as a Networking Problem Agentbay: A hybrid interaction sandbox for seamless human-ai intervention in agentic systems.arXiv preprint arXiv:2512.04367, 2025

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.523086Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.523086Z digest=sha256:ee00074efa0d17a2842a4080196650b64d1a6592c49fe5a26c8f3adef5120482

Observation 921df08d-5ba6-4670-a5c6-4363430229fb · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

Rethinking Agent Security as a Networking Problem Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.527562Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.527562Z digest=sha256:514a3907e764d7699ba1d75d38c93f8ec5ebd2fd49db5844fbe50a8dbbc800a8

Observation 2b87b12c-7b12-4222-bb91-42439fdce24d · outbound

This paper cites NeMo guardrails: A toolkit for controllable and safe LLM applications with programmable rails.

Rethinking Agent Security as a Networking Problem NeMo guardrails: A toolkit for controllable and safe LLM applications with programmable rails

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.672607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.532549Z digest=sha256:10842e6038eb38d56e8248566ae3ce11c2995a35ffb8d58e55753784edb06913

Observation b8655260-9447-4835-b15f-934814a0e315 · outbound

This paper cites Zero trust architecture.

Rethinking Agent Security as a Networking Problem Zero trust architecture

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.657947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.537273Z digest=sha256:3e61246d9a7eb96c0a66440d8cdaed589d0f9d7d989902be0aaa90dc331d6f9d

Observation c3cf9970-a376-4692-9cd8-1ea295bc4162 · outbound

This paper cites Saltzer, David P.

Rethinking Agent Security as a Networking Problem Saltzer, David P

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.641760Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.541066Z digest=sha256:7a31e022c8e633a89230c0a0ea36457c63962c8ecb47927302aeae69264e9fc9

Observation 38eed1c4-1e1e-456b-a39e-017d6868533b · outbound

This paper cites Saltzer and Michael D.

Rethinking Agent Security as a Networking Problem Saltzer and Michael D

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.625403Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.545194Z digest=sha256:094e41dc263b7832282eecfe57e9c4ea232c1ac496d48d120ee1d70c3c09e69d

Observation e940e040-cba9-4421-9736-6850d2a20f13 · outbound

This paper cites Sandhu, Edward J.

Rethinking Agent Security as a Networking Problem Sandhu, Edward J

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.610001Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.548940Z digest=sha256:31eca98742f7aa764c1b4beb0395a3c2d4cb46f4d54c636b5f494f60fa36f076

Observation 7a57f245-ebd7-4ee6-8e9c-2307eb25f17a · outbound

This paper cites Pri- vacyLens: Evaluating privacy norm awareness of language models in action.

Rethinking Agent Security as a Networking Problem Pri- vacyLens: Evaluating privacy norm awareness of language models in action

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.594727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.552823Z digest=sha256:c4e63ef0202a137ae4e3990878fcdf781abd49d4a99bbe1280f6ae83f5bb076c

Observation e7da0d6e-0a99-42be-9729-2f18aa7f6977 · outbound

This paper cites Rollback-recovery for middleboxes.

Rethinking Agent Security as a Networking Problem Rollback-recovery for middleboxes

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.578873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.557035Z digest=sha256:6daac12ed9f8c34cab84c422151d1fd80569e286ace00772c97d82a679f822c2

Observation a2d74c86-6d82-4e25-9cc5-cfb8197de3e3 · outbound

This paper cites Making middleboxes someone else’s problem: Network processing as a cloud service.

Rethinking Agent Security as a Networking Problem Making middleboxes someone else’s problem: Network processing as a cloud service

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.563237Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.561326Z digest=sha256:518a9c8dec26466a16cf833270be0d9fc9426a5398d32060622759a80cef7dc6

Observation 35ffd793-4f73-4ec1-9e49-f064a3a4a900 · outbound

This paper cites BlindBox: Deep packet inspection over encrypted traffic.

Rethinking Agent Security as a Networking Problem BlindBox: Deep packet inspection over encrypted traffic

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.546824Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.565286Z digest=sha256:8caf385d885902e532e02d7e63d22dbe36c2e5fee21fbad28c6398b7bc0c7e20

Observation 4ee59f58-654d-4619-8d57-9397e3a25186 · outbound

This paper cites Progent: Programmable privilege control for llm agents.arXiv e-prints, pages arXiv–2504, 2025.

Rethinking Agent Security as a Networking Problem Progent: Programmable privilege control for llm agents.arXiv e-prints, pages arXiv–2504, 2025

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.530999Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.570710Z digest=sha256:d60b45a3609fca8c9d8ec110f9d77c2e74f2a166a1ed64ce84ecdb7678b8357a

Observation 2174ba0f-82f6-4ec8-af11-665a1b2323b0 · outbound

This paper cites From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors.

Rethinking Agent Security as a Networking Problem From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.575056Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.575056Z digest=sha256:067047e08ae3abddc1bc0e4eb9840db3fe061b1cdde1af131ad803da857b47d5

Observation bddfdab1-8b69-45c3-a993-89ccd1560a7f · outbound

This paper cites AI agents are becoming authorization bypass paths.

Rethinking Agent Security as a Networking Problem AI agents are becoming authorization bypass paths

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.513775Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.579775Z digest=sha256:e697b29b4a14b4c2e04ea46d1dfbe7171c4a04803f10fda89b49bb4135e2e732

Observation 798cea79-2e4d-4e8e-ba7b-28b3843d9506 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Rethinking Agent Security as a Networking Problem The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.583963Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.583963Z digest=sha256:9bd8a732db432793f6df26b1ef4c0658489ebf4886ddd1060034d5cdeff3ae43

Observation 3cbe6a92-cb31-4c05-874e-93726b8777f5 · outbound

This paper cites Privacy in action: Towards realistic privacy mitigation and evaluation for LLM-powered agents.

Rethinking Agent Security as a Networking Problem Privacy in action: Towards realistic privacy mitigation and evaluation for LLM-powered agents

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.498000Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.588580Z digest=sha256:6d2d3d5e64a1abe6be47fd55e5716122679ade5e485c65bbb4a52bdf9dd53965

Observation 81453714-72fd-42b8-b3fc-6b302b4f9afc · outbound

This paper cites Sok: Evaluating jailbreak guardrails for large language models.

Rethinking Agent Security as a Networking Problem Sok: Evaluating jailbreak guardrails for large language models

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.482391Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.593006Z digest=sha256:c4b72f80885310bec64c983ed39891d7cbfb953ea70e07c8c32d03410ede13a0

Observation 55a336a1-8651-4753-8173-270eafd5b5e7 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

Rethinking Agent Security as a Networking Problem IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.597372Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.597372Z digest=sha256:6b6a350e7e1467a7dc7a262091d68698488f3a967513d911701798d1cc2eba15

Observation 74e8b5f8-adc1-4ee6-b059-2ff98c63d02e · outbound

This paper cites GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning.

Rethinking Agent Security as a Networking Problem GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.602071Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.602071Z digest=sha256:3b0804597d8965a48e571c93ad0551fdf8c8b98c9fc6cccc2e1d01f2fa983669

Observation 4a45c84b-e8d1-4c47-81fc-feee9fb2654b · outbound

This paper cites SIFF: A stateless internet flow filter to mitigate DDoS flooding attacks.

Rethinking Agent Security as a Networking Problem SIFF: A stateless internet flow filter to mitigate DDoS flooding attacks

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.466718Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.607052Z digest=sha256:8851664940c06c84faedf921e8ad4ae54312119c77134975ab857175113a1f51

Observation c3312728-17f5-4e05-8cba-74ada3c8feb5 · outbound

This paper cites A DoS- limiting network architecture.

Rethinking Agent Security as a Networking Problem A DoS- limiting network architecture

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.450831Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.611415Z digest=sha256:78df9dcd12fcdd09ee3ec1c5252db0cbbdac36b84732c24d3ad0a5c2e7b2b22b

Observation b02123c1-dbfb-497b-a416-dee577e8c4a3 · outbound

This paper cites ReAct: Synergizing reasoning and acting in language models.

Rethinking Agent Security as a Networking Problem ReAct: Synergizing reasoning and acting in language models

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.616158Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.616158Z digest=sha256:aad43c312610fdbf94c672333e7592512c6214e6497156d057fc22b642a7c8e1

Observation d749151e-5914-4f48-8875-690664504b3c · outbound

This paper cites Temporal dynamics of mem- ory poisoning in web3-style llm agents.IEEE Access, 2026.

Rethinking Agent Security as a Networking Problem Temporal dynamics of mem- ory poisoning in web3-style llm agents.IEEE Access, 2026

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.425044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.620509Z digest=sha256:d74172a4d5d65a41a0c5f4f1051a365e673d5925570a705ec2b6ad297254d45b

Observation 524731c4-3e4c-4b1a-bd71-5b83f9c00d9c · outbound

This paper cites Making information flow explicit in HiStar.

Rethinking Agent Security as a Networking Problem Making information flow explicit in HiStar

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.409351Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.625041Z digest=sha256:a5cf8298e163fb15c1fad5ccb9b0f1a1a184bf9e92b5ce8bbc4b8d6b70c93bd5

Observation 26f6f9af-a124-467e-b693-d47653751744 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large lan- guage model agents.

Rethinking Agent Security as a Networking Problem Injecagent: Benchmarking indirect prompt injections in tool-integrated large lan- guage model agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.629850Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.629850Z digest=sha256:9f56612c88156444651a87bdec3a4ea4b76b1b1832e4ff4b9c4fe6428207e812

Observation e9121ddc-0084-4c58-b0a5-a12b43efabfc · outbound

This paper cites Towards Action Hijacking of Large Language Model-based Agent.

Rethinking Agent Security as a Networking Problem Towards Action Hijacking of Large Language Model-based Agent

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.634434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.634434Z digest=sha256:86739f7bbf042bb069ed5959978d3fd9cdbc2eda09068e7d775b8f0bd3168c01

Observation fe36e78b-b5bf-4996-8d88-d11f94fc0f72 · outbound

This paper cites AgentDAM: Privacy leakage evaluation for autonomous web agents.

Rethinking Agent Security as a Networking Problem AgentDAM: Privacy leakage evaluation for autonomous web agents

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.382866Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.639378Z digest=sha256:8cf9d7c9d258bec65192353de20677497a03da3e4946346a73cab6892bb52866

Observation 8e10ec44-80f8-4ff2-94f6-1c098895bc68 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

Rethinking Agent Security as a Networking Problem RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.643873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.643873Z digest=sha256:375cffd2aac3ec36fa87aa1c51cbebf0be63abfbe18531bf9516ddf8c7e513c7

Observation a11e147c-8315-4aff-9114-684a09cfc24b · outbound

This paper cites Rescriber: Smaller- LLM-powered user-led data minimization for LLM-based chatbots.

Rethinking Agent Security as a Networking Problem Rescriber: Smaller- LLM-powered user-led data minimization for LLM-based chatbots

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T00:16:53.363098Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-16T00:16:52.648792Z digest=sha256:752940f07128cdf1f006a90760b5064086d32c5f708964bc64f5ee860d666a58

Observation 97d3c3fa-887f-4d8e-bf85-d9d2c3c98277 · outbound

This paper cites CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities.

Rethinking Agent Security as a Networking Problem CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.653903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.653903Z digest=sha256:9b07094f14c6816c6761861f943ec1180e7f469d8eb66fb8bb7f1b67f490dbc5

Observation 51282d5b-1aa8-4e13-afdd-045001046885 · outbound

This paper cites an unresolved cited work.

Rethinking Agent Security as a Networking Problem Unresolved cited work

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.318565Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.318565Z digest=sha256:9b9df542c0ca5d509d625ac3f0588a979c28b04486ef7f3e1b033aa1ff970d74

Pith citing papers

No inbound Pith citation observations are available.