Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T13:28:21.836925Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 75 of 75 outbound references and 2 inbound Pith citation observations for arXiv:2505.23817.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T13:28:21.836925Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-07-01T08:17:10.481202Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z
75 of 75 outbound references displayed
External citation measurements
0
arxiv_reference, observed 2026-08-05T02:28:24.338817Z
Observation 904ae51b-c775-413c-b332-05ed7340ee58 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models GPT-4 Technical Report
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3409a184-0836-489a-8886-b6fc5dffd51a · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Prompt leakage effect and mitigation strategies for multi-turn LLM applications
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 68f541b0-139e-495c-ad6b-6eec07333f52 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Harmful content generation
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation cfbd207a-b95b-4558-9006-2464ad7c8d96 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models How Susceptible are LLMs to Influence in Prompts?
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e476f65-7f2c-43a4-a050-3de0463c1a4d · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Large Language Models: A survey of their development, capabilities, and applications
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 965523e6-8e41-4123-92a5-50e4aeec9dae · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Introducing the next generation of Claude
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 264951e0-35c1-4b96-af56-b6c3b95f317d · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Language models are few-shot learners
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0c4c3386-82fd-4c9b-854e-d5ad2a8135df · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models System prompt leakage
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation dacd04bf-49a9-4a19-93d6-1baad2ea8909 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Security and privacy challenges of Large Language Models: A survey
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 18dc2fd6-bafc-438e-91d7-fb40e553749a · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models google/txgemma-9b-chat
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a66f8d0c-2eef-45ec-ad8b-b91a03eae4d3 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models tiiuae/falcon3-7b-instruct
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 7aa40db5-8083-4292-be28-58c7902b7ceb · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models meta-llama/llama-3.1-8b-instruct
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 16bd48d7-df57-4aea-b5b2-cc68ffca1bbd · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models The Llama 3 Herd of Models
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 75d57d93-2ec7-4c25-8b8f-99fa28be6c03 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Do LLMs "know" internally when they follow instructions?
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b5911f80-068c-4bc2-abf7-15e1af6fae08 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models LLM System Prompt Leakage: Prevention Strategies
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 76c02757-bf5a-488a-ac44-e9e1ae5c7dae · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Pleak: Prompt Leaking Attacks against Large Language Model Applications
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2af08ee1-16db-402e-8136-758dd48bcbdc · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models ChatGPT roles
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a8932f52-8035-46bd-9b9c-30d2957f624b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Exploiting programmatic behavior of LLMs: Dual-use through standard security attacks
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 9c6d2e89-f6f6-4b7a-b19b-2e82c88b1d99 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models What is a prompt injection attack? https://www.ibm.com/ think/topics/prompt-injection, 2024
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 7179ff40-a2b6-4f0f-8ae0-b42c81278ced · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Cosine similarity to determine similarity measure: Study case in online essay assessment
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 227d56cf-4a72-4ca8-954f-adc32a8a8f80 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 04c296ac-4f0e-4b54-8c69-ca54abaae151 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Rouge: A package for automatic evaluation of summaries
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 30a345e2-d63f-489f-b53b-e898990292be · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df8f36f9-83c9-4aec-85a8-5af897699b7f · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Use of LLMs for Illicit Purposes: Threats, Prevention Measures, and Vulnerabilities
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24a3a16c-7ad3-457e-9e14-52f68f6040bb · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Adversarial Fine-Tuning of Language Models: An Iterative Optimisation Approach for the Generation and Detection of Problematic Content
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0c3d2a8e-a1ec-4e24-a3a3-2a45f0f9b91d · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models GPT-4 System Card
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation bcdb0479-0497-4716-ac7c-f434048734fc · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Introducing GPT-4.1 in the API
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 5c86a944-cd53-4906-8dde-a15a4c7d60d9 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Prompt Obfuscation for Large Language Models
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9b6fa092-b653-4055-9006-2a6a0a5eca04 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Ignore Previous Prompt: Attack Techniques For Language Models
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 38ed03f7-5671-439e-9928-0906af6f2d3a · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Instruction defense
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 677e49f2-382d-49d0-a7f4-736a24f30952 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Chatgpt roles
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation e5ae70ec-8c69-4734-8707-9998edb73825 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Prompt Stealing Attacks Against Large Language Models
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation af023c88-0c17-4978-99fc-96cd4461ca92 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2023e019-f348-4999-b99f-971ea631d18e · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Do Anything Now
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation deeb8f5a-a1c3-4b84-b42c-c29b0de78707 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f332e495-a5e7-459f-b185-e37b3f13fa49 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models ChunkRAG: Novel LLM-Chunk Filtering Method for RAG Systems
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 733cf314-bd1b-42d2-887d-7732eb270e68 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Gemini: A Family of Highly Capable Multimodal Models
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a49f65a8-ab1e-4156-97c4-1d7f848a4cff · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Falcon 3 family of open foundation models, December 2024
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 161fb040-ee28-4bec-9480-cd9a8c4f7b3b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Sandwich attack: Multi-language Mixture Adaptive Attack on LLMs
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f905274b-f7b1-4004-95f6-a38bce22d580 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Synthetic Multilingual LLM Prompts: A synthetic multilingual prompt dataset for prompting llms
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 20202f5c-7b09-449a-bf81-997ce875bb6f · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models The Art of Defending: A Systematic Evaluation and Analysis of LLM Defense Strategies on Safety and Over-Defensiveness
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation c697ad06-cd63-4715-b734-3431039dbec4 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Attention is all you need
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5e5ac694-5ff5-46f1-86c1-ab14a96b5bb0 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Jaeger, Fan Zhang, Rory Pilgrim, Yossi Matias, Joelle Barral, David Fleet, and Shekoofeh Azizi
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation b11abeee-d132-4cfb-aee1-84801f49987e · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models A Tutorial on LLM Reasoning: Relevant Methods behind ChatGPT o1
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a17c2539-2ea3-4a32-a41f-8417f4da89e1 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Raccoon: Prompt Extraction Benchmark of LLM-Integrated Applications
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 46e94282-c291-43c0-9f6e-3e25aec7761d · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models PromptAgent: Strategic Planning with Language Models Enables Expert-level Prompt Optimization
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8b21fa52-71b6-4c68-adae-8f664e50b043 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Jailbroken: How does LLM safety training fail? Advances in Neural Information Processing Systems, 36:80079–80110, 2023
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0ab4e036-2bb9-4db0-9aea-4e8a469bce3f · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Chi, Quoc V
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e5db517b-63b3-4ad3-afef-fe7ff873368e · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models PRSA: Prompt Stealing Attacks against Real-World Prompt Services
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 124fb2d1-84b4-4e2c-85d1-5f8a13c7549b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Assessing Prompt Injection Risks in 200+ Custom GPTs
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 781d88b3-dd71-4560-9cef-d771f702c936 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Effective Prompt Extraction from Language Models
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 96a6d877-eb7d-4835-b925-670b7a99df8b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ad724349-2791-4445-a72a-bba6b4973ef2 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4b7f047d-32cb-4252-b07d-17108b202edd · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation f1d80ebf-f31f-4434-9239-cda6326d87f2 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation e5efa0c1-a192-4d91-9ca1-b2c4bdcea925 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 112a6624-9438-4064-9c8d-1242c9606e33 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0e24d379-fe6c-4048-8617-3882ca4d789a · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 05b4b0ec-1184-4dbe-a6e6-16df576fa242 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 67
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4636bb8f-0887-4d16-b81b-7481343fe74b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0f419749-771d-4eb5-88b1-45a926006581 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 206ea9a2-8a80-4f34-8ce8-f9a2219720f3 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation e2d401d4-ed19-4ca2-b78f-c2ba443c1373 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 71
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 9db4b0c9-d81d-43a2-b158-2ce8661f3a8b · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation fec12599-a0f0-42d3-8239-3ff42fe44287 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 75
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 26ae3c3f-e162-4bf5-8978-e41add032e12 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 38312853-8305-4986-adf4-2b02e19d0cff · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2217e8b5-27fa-4bc7-a6b4-75dea27232f5 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 80
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4901a84e-f253-4d88-8547-5d1f6f88807f · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models I am a travel assistant, I share travel tips, destination ………
Reference 81
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 690fcd5e-5a83-476e-82ac-e922141c337c · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models I am a travel assistant, I share travel tips, destination ………
Reference 85
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 6701a554-ac23-4d94-ad4b-aee539d2b8b9 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models I am a travel assistant, I share travel tips, destination ………
Reference 89
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 6f5257d0-2f65-4810-a6e7-52e4ab7c0740 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 90
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 8dca8632-4df4-4356-b763-d7e41c1a45dd · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 91
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 2fc0da6c-d258-43ce-ab8c-6d84c8c6faa8 · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models Unresolved cited work
Reference 92
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 50491108-12ad-4053-90d3-10d70fe146bb · outbound
System Prompt Extraction Attacks and Defenses in Large Language Models I am a travel assistant, I share travel tips, destination ………
Reference 93
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 251d89f7-920e-41a7-afd9-9004fc6ad39a · inbound
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening System Prompt Extraction Attacks and Defenses in Large Language Models
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation ca5f4bdd-cfe1-4b76-bd04-129b61282dfa · inbound
Prompt Governance? On Governing Technologies Governed by Natural Language System Prompt Extraction Attacks and Defenses in Large Language Models
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.