Pith. sign in

Paper Citation Record · LEDGER

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

As of 20 August 2026, this Paper Citation Record lists 58 of 58 outbound references and 37 inbound Pith citation observations for arXiv:2502.08966.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.08966 v2

Coverage vector

measured 58 of 58 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T23:09:36.738179Z

measured 95 of 95 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00

measured 37 of 37 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T00:16:52.643873Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

58 of 58 outbound references displayed

  • verified exact0
  • verified fuzzy41
  • unresolved17
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

3
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 0c74a6a3-c513-4a80-9e01-ac72c0ee4467 · outbound

This paper cites https://www.teneo.ai/solutions/ industries/airlines.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage https://www.teneo.ai/solutions/ industries/airlines

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.116530Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.379163Z digest=sha256:efefba63fba0ed96877bae2b33e6e300cb26d6fad20f72fbdd31d7bc851e3faa

Observation 9a78b874-a00d-4955-b6f6-248a1bf443e2 · outbound

This paper cites Phi-3 Technical Report: A Highly Capable Language Model Locally on Your Phone.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Phi-3 Technical Report: A Highly Capable Language Model Locally on Your Phone

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.384228Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.384228Z digest=sha256:86cd545e2a05e93fb200b0e55387d6b1fbddb87edd417fd15ed6eedc661471cc

Observation badef446-7079-4309-a97a-f59b8f752143 · outbound

This paper cites Fine-tuned deberta-v3-base for prompt in- jection detection, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Fine-tuned deberta-v3-base for prompt in- jection detection, 2024

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.104196Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.389536Z digest=sha256:5165765ed2aae36b0f57b6fd993c98dc4980b394804ce41481272c030df9f18d

Observation 07c17d0a-f9e7-4d98-af37-ccd9672a003c · outbound

This paper cites Claude: An ai assistant by anthropic, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Claude: An ai assistant by anthropic, 2023

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.093640Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.394324Z digest=sha256:193895384206b60d1c7122ca32e72332061073b6b2d54175d43573c1fdbe7f6e

Observation 78d6ffa3-d31b-43c0-9675-dd4bc0c9c2ca · outbound

This paper cites Prevent factual errors from llm hallucina- tions with mathematically sound automated reasoning checks (preview), December 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Prevent factual errors from llm hallucina- tions with mathematically sound automated reasoning checks (preview), December 2024

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.081236Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.398448Z digest=sha256:dbf09f759a92e45355ad06646aafc43aabeeb5fdaef2584f9a652bbe9e4bd29b

Observation ec5b9fbf-b8f9-41eb-8291-22c979c5a4ef · outbound

This paper cites Extracting training data from large language models.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Extracting training data from large language models

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.068418Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.402751Z digest=sha256:c5230f62d12ff6b1753de24b28590158891024b5afe253e42191d228af6eecf2

Observation ad7b8941-1eff-4f80-bd19-29e17682ddcb · outbound

This paper cites Clear: Towards contextual llm- empowered privacy policy analysis and risk generation for large language model applications, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Clear: Towards contextual llm- empowered privacy policy analysis and risk generation for large language model applications, 2024

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.056295Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.407615Z digest=sha256:120ce592f23694e0b8b0e1cc66892b790c9b41d49990e136c848bd0376742456

Observation 5edde386-6d6a-4419-a75a-284aa8de3b4d · outbound

This paper cites Struq: Defending against prompt injection with structured queries, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Struq: Defending against prompt injection with structured queries, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.412536Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.412536Z digest=sha256:ba3756faa8142efd4b228581de4ee35816a08e7ccc481bfa543d4dd1b9a9a61f

Observation 7d420f18-e0ac-4e8e-b7a0-6c8ae7460108 · outbound

This paper cites Custom gpts from your content for business, 2025.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Custom gpts from your content for business, 2025

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.037288Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.417919Z digest=sha256:ac9db793b29f3ada2dd19c00605e7468abed9bd88520928d2be316db6befcabb

Observation 2206a5b9-a1f2-4613-a8a6-f6507c9f67ca · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.424083Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.424083Z digest=sha256:f7785eff79bdb34e58ca43e52dc7b44ee1ba1dc29c350262e7209880bc720bb2

Observation 55fc7daf-a34b-4c09-b704-b355dd79bda8 · outbound

This paper cites an unresolved cited work.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Unresolved cited work

Reference 11

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:09:38.025510Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.434684Z digest=sha256:99cfc8d72a8e8232686e3369b1480ff6cd45a3dd4b1bcb95092412d444f097d4

Observation b7c7ef42-bf4c-44f9-97e5-465c25489d75 · outbound

This paper cites A survey on llm-as-a-judge, 2025.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage A survey on llm-as-a-judge, 2025

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.013773Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.444827Z digest=sha256:dfa16677ea08e211eea06c4b80e0bdca2dde3561a792eb03f356e09c696e4ba6

Observation a5772095-765a-442f-a0a3-c46664c04d03 · outbound

This paper cites Defending against indirect prompt injection attacks with spotlight- ing, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Defending against indirect prompt injection attacks with spotlight- ing, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:38.002173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.448393Z digest=sha256:a911ebe08bab2e473380238ac521b2b8ffae7b5257dec197e9f990acc3c87f7c

Observation 5e3f1e46-6c5d-419f-b688-a11f600e9ca1 · outbound

This paper cites Long short- term memory.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Long short- term memory

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.990393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.451488Z digest=sha256:c198a8f83fbe4f00295251c071b122e6b86604ac58fda4ad8a14d05a65f68c94

Observation 0aefcb79-6550-4972-8f7a-22d7e1821c09 · outbound

This paper cites Firewallm: A portable data protection and recovery framework for llm services.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Firewallm: A portable data protection and recovery framework for llm services

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.978754Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.455013Z digest=sha256:034a501f19925d0c3916ff87f79f08e6720cdf8c087645d42a6167a69f99445c

Observation 70c34846-0835-405e-8f9f-49318c2a01ff · outbound

This paper cites Language models as zero-shot plan- ners: Extracting actionable knowledge for embodied agents, 2022.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Language models as zero-shot plan- ners: Extracting actionable knowledge for embodied agents, 2022

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.957222Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.458181Z digest=sha256:842e9b1fdc89cc6033c5ea03898375f4734930f69a50ff9101f4c258b7d7b372

Observation d088d12e-97e2-4e94-84ee-a5c23731e5fa · outbound

This paper cites Hsu, and Pin-Yu Chen.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Hsu, and Pin-Yu Chen

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.912281Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.462733Z digest=sha256:8971576cbecaff6741d114aa96c8077aee383ea599755d15e3709a9a1bf93f96

Observation a93606bd-3a57-4202-8a3c-f9586bcbb707 · outbound

This paper cites Baseline defenses for adversarial attacks against aligned language models, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Baseline defenses for adversarial attacks against aligned language models, 2023

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.466778Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.466778Z digest=sha256:02456403107d8bf8b2184091cefdd1b08458f4d0554dfcdff51bdc71d65ba60a

Observation a361fb81-b883-4481-841a-5331f4807b00 · outbound

This paper cites Attention is not Explanation.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Attention is not Explanation

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.480915Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.480915Z digest=sha256:9e6ad5fa9b36204382f15b9dde152a18247e917bb035d6efa31f1536d66c6623

Observation bd732fbc-0ffa-4316-b853-56dc583b0b98 · outbound

This paper cites Iden- tifying and mitigating vulnerabilities in llm-integrated applications, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Iden- tifying and mitigating vulnerabilities in llm-integrated applications, 2023

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.893626Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.498194Z digest=sha256:876e9f972a3fcd59652fe4cbeb139798726c8f9897ab23087ec65c78cfc93cf9

Observation bd7ba25c-f073-490c-9044-a99a3b664077 · outbound

This paper cites Propile: Probing privacy leakage in large language models.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Propile: Probing privacy leakage in large language models

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.881491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.516075Z digest=sha256:2e806621f62fc6c71264d874bb836de8741cfe0908c78c985cfd5bad8ac5c022

Observation 643956ae-a16b-47d1-8ab3-d9bfa238dba2 · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Autodan: Generating stealthy jailbreak prompts on aligned large language models, 2024

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.531254Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.531254Z digest=sha256:ac008b02fd77c8cc4c78f5dd2fe038dd0e78b570cc00bab7ac536d4f52316655

Observation 669a9f26-99a7-4ff6-86c2-9d4d2ec6b6bc · outbound

This paper cites Prompt in- jection attack against llm-integrated applications, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Prompt in- jection attack against llm-integrated applications, 2024

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.778707Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.546916Z digest=sha256:8b205e4aff07648b7e376d401bd45772084cfcecafb7bb0251dc6fe709e64473

Observation 307f4e19-8225-4418-8466-48f7b2321021 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Formalizing and benchmarking prompt injection attacks and defenses

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.714493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.550686Z digest=sha256:d09fbda36d4d321101cfcf5748f4973ccf7c2df637a06e5b39952627b3bceedf

Observation 53dbaf05-7e9e-403a-9a5b-9ddb620f2a5e · outbound

This paper cites The landscape of emerging ai agent architectures for reasoning, planning, and tool calling: A survey, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage The landscape of emerging ai agent architectures for reasoning, planning, and tool calling: A survey, 2024

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.554017Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.554017Z digest=sha256:ca72aec91957b03493f47608571aae9c24b5e817dce5d7687c6a7d2a260b7a3e

Observation 7ea758ee-1485-4c2c-9752-ab094a1a0e50 · outbound

This paper cites Conversational ai in banking: Chatbots, use cases, examples, Dec 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Conversational ai in banking: Chatbots, use cases, examples, Dec 2024

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.653847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.557495Z digest=sha256:00c90412885b9624935a38929c880a4e1dbab59b33b06afb5d51824a8ce52f10

Observation 90f1339d-80ee-43f4-be19-674ef4375be7 · outbound

This paper cites Are sixteen heads really better than one? In H.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Are sixteen heads really better than one? In H

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.603146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.560880Z digest=sha256:42bc57c0aff1d8dc2c3951caa4eac106997efe459e3b01b9a70d7b5bfac4534c

Observation 99fe8290-5dea-4064-9802-2459881d5cf8 · outbound

This paper cites Myers and Barbara Liskov.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Myers and Barbara Liskov

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.591607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.564921Z digest=sha256:297c21264db23adc28178476f30c1091c16cc806664d06ad6865d6f2581fdb8c

Observation 1fc3565a-079d-473f-94fb-632786911c54 · outbound

This paper cites Dynamic taint analysis for automatic detection, analysis, and sig- naturegeneration of exploits on commodity software.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Dynamic taint analysis for automatic detection, analysis, and sig- naturegeneration of exploits on commodity software

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.580275Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.568872Z digest=sha256:c78425402a06f27c23c5b054eeac095e79e227219c3fad2516d9a014cbfe961a

Observation 14498474-5b8f-4f3e-914e-47f53dbe1b7f · outbound

This paper cites Introducing gpts, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Introducing gpts, 2023

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.569845Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.571663Z digest=sha256:3cb6ac8a4b1af88f0759cf03175505b2eec799d6031cbca8e6a97c62f12e1b90

Observation 349ac449-19b0-416e-a684-57f55961b870 · outbound

This paper cites Optimizing instructions and demonstrations for multi-stage language model programs, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Optimizing instructions and demonstrations for multi-stage language model programs, 2024

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.559001Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.574741Z digest=sha256:5f83622d5ca886a1a0c13fe0ba00bab7b76262aa2ec9bc3cceff5c6fb8586b2b

Observation fde53ec2-b66d-480a-9c86-f088b3d7905c · outbound

This paper cites an unresolved cited work.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Unresolved cited work

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.577890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.577890Z digest=sha256:2c147013ef06dd169e2658dc1b12697d3d920abe7947834869dc959a9f33a457

Observation 1e7b2b9f-4916-46ff-a82e-6cced1c144b9 · outbound

This paper cites OW ASP Top 10 for LLM Applications, 2025.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage OW ASP Top 10 for LLM Applications, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.543385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.581153Z digest=sha256:d4af2055c5b7d348fa8f01b048a4f56e03b7e5ba555143bac33f6c2fbcea533f

Observation ad33e7eb-0532-46d2-9b55-486fa2d82691 · outbound

This paper cites Jatmo: Prompt injection defense by task-specific finetuning, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Jatmo: Prompt injection defense by task-specific finetuning, 2024

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.452481Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.584073Z digest=sha256:edeccccadd6ca9683b910f4bb492f56ad482c52f12f580ca8bdd5ec76a15b0b3

Observation cf247929-b6ae-451b-926a-4b1c6a06e787 · outbound

This paper cites Fine-tuned large language mod- els (llms): Improved prompt injection attacks detection, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Fine-tuned large language mod- els (llms): Improved prompt injection attacks detection, 2024

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.341044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.587617Z digest=sha256:483922f4d11a83f987cf09c67a66caaa158b07bc663d31eb27f5936cd7e7d783

Observation 7ad20ce3-e439-4df0-9663-f1e95f898154 · outbound

This paper cites Self-reflection in llm agents: Effects on problem-solving performance, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Self-reflection in llm agents: Effects on problem-solving performance, 2024

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.292535Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.591196Z digest=sha256:5e2eb73301c299e8c443946b9237b3958315fe143ee8a4af5f024ee63cc6b9ea

Observation c5e5a337-de9d-4be1-a041-f217da88b4f9 · outbound

This paper cites Sabelfeld and A.C.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Sabelfeld and A.C

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.283008Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.594695Z digest=sha256:bcc052737c0667ff0e6bd3f8abff58f3ce32d786c8f054fa44f10feb4e35b7f6

Observation 9a974c7d-2388-4fd4-a7db-e3c039c7a488 · outbound

This paper cites Sandwitch defense.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Sandwitch defense

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.273123Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.598260Z digest=sha256:5e1f8368678a557d9e07921c2a5cd7d2c0f4891caecc34a42ec8b86a058c4546

Observation e20a033a-da37-4265-9839-4901a618ceaf · outbound

This paper cites an unresolved cited work.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Unresolved cited work

Reference 39

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:09:37.262823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.601503Z digest=sha256:5d5ace95fb4cad1d775f303f9ccd49a3d95584b8f1675308721167757ef012ea

Observation 1ba44f4c-1179-4f47-a6d7-b5f8b0a633b5 · outbound

This paper cites Permissive information-flow anal- ysis for large language models, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Permissive information-flow anal- ysis for large language models, 2024

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.251821Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.605467Z digest=sha256:e0b2eff97611107dc5a98272d25fd0558508db5b4d163647c12022ac824a3073

Observation b0d308da-186f-43d3-aa39-13593de1f67d · outbound

This paper cites Papillon: Pri- vacy preservation from internet-based and local lan- guage model ensembles, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Papillon: Pri- vacy preservation from internet-based and local lan- guage model ensembles, 2024

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.200667Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.608649Z digest=sha256:ba8b015f9797eae503ff73162ed48440c411e4f62f1f3e225011849f49d04c36

Observation fe75a609-bbf4-4a7e-889e-fa69a37c22e6 · outbound

This paper cites Policygpt: Automated analysis of privacy policies with large language models, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Policygpt: Automated analysis of privacy policies with large language models, 2023

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.139916Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.623644Z digest=sha256:bd366d0282336263cb286abd01186ad08dd81298053f986fe12ef4bb5f03e49c

Observation 407cc61a-465d-4954-8473-8973be29e2d9 · outbound

This paper cites Attention is all you need.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Attention is all you need

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.638028Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.638028Z digest=sha256:3fc4a837f0470d4bb50070cda5bcba5b88ea908b8d98ff9dc3d5257eae567d59

Observation 44232aa4-b234-4e22-9857-e43e5905b7fb · outbound

This paper cites The instruction hier- archy: Training llms to prioritize privileged instructions, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage The instruction hier- archy: Training llms to prioritize privileged instructions, 2024

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.651864Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.651864Z digest=sha256:baef3e9e80155f1f4168f31ebeafae12e1e1af480bc1846556a027a63ebc4bb0

Observation 498d6077-4228-4514-9f1d-e2780b85452a · outbound

This paper cites Label Words are Anchors: An Information Flow Perspective for Understanding In-Context Learning.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Label Words are Anchors: An Information Flow Perspective for Understanding In-Context Learning

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.663757Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.663757Z digest=sha256:516b717ff722b292938eb6a743f07eefde88c0f583e76f51f41003430c3f4285

Observation c4d3fe6f-4629-4e63-910a-d0c7f71f7b50 · outbound

This paper cites Plan-and- solve prompting: Improving zero-shot chain-of-thought reasoning by large language models, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Plan-and- solve prompting: Improving zero-shot chain-of-thought reasoning by large language models, 2023

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.097968Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.677981Z digest=sha256:fb2de8d96e450f65eef8f0ae63f0a0ebe7a248ae5a023292781135599429038d

Observation 3e1fe6b5-a453-46eb-9c66-c97ff886c663 · outbound

This paper cites Chain-of-thought prompting elicits rea- soning in large language models, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Chain-of-thought prompting elicits rea- soning in large language models, 2023

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.699896Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.699896Z digest=sha256:761aead224e243562aeddd174fe41e3b0a71bc4b3ed9108786470eaec93a6810

Observation 7c029dc4-d0f3-45ec-93cd-e3b3ab02f075 · outbound

This paper cites Llm powered autonomous agents, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Llm powered autonomous agents, 2023

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:37.029492Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.703800Z digest=sha256:42227556fa0129d0f98b4b0b1605ebf1a43dd5588acd12c855d3b98309347d1e

Observation de14e05c-11e6-4776-9b47-70b035a4f719 · outbound

This paper cites Attention is not not Explanation.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Attention is not not Explanation

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.707259Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.707259Z digest=sha256:f401fed8bbf71f23a9878c3cf678455d6ed1eed5db2412d9f98ad973608c29e1

Observation 4abe83cb-364c-4848-9173-5f675d9570c7 · outbound

This paper cites Prsa: Prompt stealing attacks against large language models, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Prsa: Prompt stealing attacks against large language models, 2024

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.978796Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.712052Z digest=sha256:cf4eb4b147d2e667312a6daac8f7c9d6d4c124c75af7ebbb7539970274895a20

Observation 69e4ade0-873f-4430-a46f-b79e7d1f3ea1 · outbound

This paper cites React: Synergizing reasoning and acting in language models, 2023.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage React: Synergizing reasoning and acting in language models, 2023

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T23:09:36.715196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:09:36.715196Z digest=sha256:6a45151a227373155dc37558aead08950ea7a54685062ba65ca1908a5dcbeee8

Observation 0d82a66b-f299-4a2f-a68a-435ad5ef2954 · outbound

This paper cites The shift from mod- els to compound ai systems — bair.berkeley.edu.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage The shift from mod- els to compound ai systems — bair.berkeley.edu

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.962194Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.718754Z digest=sha256:2b29c65897a3addc4a022ae46deb177e9c10295a09597d1209fe3c7d27b2ddf3

Observation 9a95bba1-696b-4cfb-b14d-df9b32eee4e6 · outbound

This paper cites an unresolved cited work.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Unresolved cited work

Reference 53

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:09:36.952093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.722005Z digest=sha256:5a4ffc666e5e4b76d3d77c4befc90a97c738443c460d716c88df2bd9580df22d

Observation 4c7dcd7b-c2f5-4d4e-b494-f8a4599dcc09 · outbound

This paper cites Injecagent: Benchmarking indirect prompt in- jections in tool-integrated large language model agents, 2024.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Injecagent: Benchmarking indirect prompt in- jections in tool-integrated large language model agents, 2024

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.939855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.725188Z digest=sha256:b77314a7bb2876cf3810ab4447d57d0237761f8b0bda4d6458955a7c9c902c05

Observation 510b6c59-eda5-4629-bc8c-5eb636a0c583 · outbound

This paper cites Opt: Open pre-trained transformer language models, 2022.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage Opt: Open pre-trained transformer language models, 2022

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.928583Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.728364Z digest=sha256:0e899a6a7714469d16254d7923163883b382412d8764608a852f90fce3a44895

Observation 10033dc6-dae5-411a-9264-0d8fb8245cfe · outbound

This paper cites H2o: Heavy- hitter oracle for efficient generative inference of large language models.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage H2o: Heavy- hitter oracle for efficient generative inference of large language models

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.907437Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.731581Z digest=sha256:babdbe116f876a6043b7c45ae53b572104c9c38d5f9fd7a5d7e611c233d2c075

Observation 55b202e1-e0c7-4112-96ee-815150e2b17f · outbound

This paper cites A guide to large language model ab- stractions.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage A guide to large language model ab- stractions

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.866773Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.735076Z digest=sha256:5656a980eded864074580f36eae90711d4604628dadfc4af6a9b06862c44d55c

Observation 4091f65a-3be0-467c-97ff-1dac46a2ef37 · outbound

This paper cites amount":100,date:.

RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage amount":100,date:

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:09:36.820109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-07T23:09:36.738179Z digest=sha256:f834d42d2a685eb0a9e6f8d6dd57a2969098dc87ba9c2733c1456fdc70d6c58d

Pith citing papers

Observation bb8c9278-c915-4f58-beae-9a1df8b8b52e · inbound

Large Language Model Agent: A Survey on Methodology, Applications and Challenges cites this paper.

Large Language Model Agent: A Survey on Methodology, Applications and Challenges RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 208

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:52:10.238901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-22T21:51:34.309870Z digest=sha256:0584793c9b05e701c78c26329d4434f9a45266588671d947241061b658a40bcc

Observation 3de2c449-a3f9-4009-97aa-7f6d90a333e3 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.042158Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:ed8ef0d905fd8c5ea966fbf8d38429208d2f81a06fbde7eda66b7e850a9f8968

Observation 4755f0c4-0df9-493b-bc87-041b609ba668 · inbound

LLM Agents Should Employ Security Principles cites this paper.

LLM Agents Should Employ Security Principles RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.059726Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.059726Z digest=sha256:61c9883717885b6b73e8a103dc1393f7e9882c660bcfb35ba041e56e1962a052

Observation d1a3eb34-1cae-49ac-a1e5-9a5996482d17 · inbound

Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution cites this paper.

Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T11:59:27.473122Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:59:27.473122Z digest=sha256:bb75178f0379402b53f71f2f398c7cdde9f32c703199dae7f12bf1f6ad91794a

Observation afccdfc2-6a61-4588-ae1d-7caaa7ddc689 · inbound

Quantifying Conversation Drift in MCP via Latent Polytope cites this paper.

Quantifying Conversation Drift in MCP via Latent Polytope RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-05T22:51:28.187021Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T22:51:28.187021Z digest=sha256:91c9c3c8b2448933b244081ca53ce64d0a883f3e0d8a80d70c9a646d0c5f9b48

Observation 5d2d8ec6-39d3-4c27-b4f2-b2f48f2fbdce · inbound

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents cites this paper.

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-03T10:32:33.909110Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:32:33.909110Z digest=sha256:3b6fc138987add42c7d99d3b760bcf137387800f451e3f74059f5f9152895e44

Observation cfe75a82-e001-4659-9aef-3bed1f25ec63 · inbound

AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments? cites this paper.

AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments? RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-05-16T08:17:36.456679Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-16T08:13:33.928054Z digest=sha256:0a05c7c831c0abc77bc78983c893ff7cb0dd48e203a33d513d20b151b5a037db

Observation e824a791-b449-450c-8ec3-5ebba32de1ab · inbound

Causality Laundering: Denial-Feedback Leakage in Tool-Calling LLM Agents cites this paper.

Causality Laundering: Denial-Feedback Leakage in Tool-Calling LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 32

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T17:23:02.729426Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-13T17:19:32.255377Z digest=sha256:50538ab8a8c4f96822ce9b079efa8d0fe504254f5ac5728ee97df3fb9a56dbcb

Observation 889266f4-42fe-4caf-8724-a49908aae6ba · inbound

Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents cites this paper.

Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T10:24:22.255308Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-10T10:15:27.926105Z digest=sha256:e6cde8d908c4058a419e57462f34b8be99d51ce63389551cf6465303ef55f3e7

Observation f72f3970-041a-47bd-a996-ddeec1a92ee4 · inbound

An AI Agent Execution Environment to Safeguard User Data cites this paper.

An AI Agent Execution Environment to Safeguard User Data RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 84

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T13:11:05.836253Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-10T02:14:40.639143Z digest=sha256:258cd19dc1882f1afbb6062f456bc542e6097417fa855c594a05d3d292c7d323

Observation ed8708f0-3a77-45fe-b2fa-0a8fa60a5e7d · inbound

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents cites this paper.

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 42

Resolution
metadata mismatch
arxiv_id, observed 2026-05-08T22:39:20.560351Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-08T08:08:24.524671Z digest=sha256:7601d2eb607104d8989582914a088bfbe03914f692b56cc60a1758c6d0dd98c0

Observation 2125e95c-ae4c-46ba-bd5a-5b6900e9d503 · inbound

Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis cites this paper.

Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 51

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T15:26:11.075385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-09T19:58:28.584941Z digest=sha256:40f9a1ac3d67946d6169a6b6d41e252bfed52c3b34ebf0271ff1ab66c958427e

Observation 89038650-9305-4b6f-8841-ff7a5ebcdb6b · inbound

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization cites this paper.

PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-08T17:53:53.279055Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-08T17:49:39.533090Z digest=sha256:030ffaeccb60e4451df228d2660470a9bdc81bf90248aeccb25ce16d6b8b6ef2

Observation 4d8997e7-20e6-4b4a-869a-5cc7a0faa4d7 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:46:31.618660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-07T02:12:30.086152Z digest=sha256:26f548ec29a4bb38a2cb7e1f3008fc4f7004ae008ba6377f3820b878a75aab9d

Observation c983bbf0-71f7-4455-8318-13798820fb44 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:55:44.561705Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-08T17:56:09.884837Z digest=sha256:906f829a94246819661dd7e0d10c1a5fa1e20cfec10221af505e1d0d1176f4fd

Observation 15b8949e-8444-43db-83b9-e9b6657c0e10 · inbound

Reframing LLM Agent Security as an Agent-Human Interaction Problem cites this paper.

Reframing LLM Agent Security as an Agent-Human Interaction Problem RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 66

Resolution
verified exact
arxiv_id, observed 2026-06-30T13:54:43.881131Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-30T13:52:06.272229Z digest=sha256:7d45e43ae603f8e0a67b9a1991ad665c8c4eca9a5264e06d74f37c8a9433627e

Observation f2968074-18cf-4836-b8ab-a1132d6dcb92 · inbound

Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents cites this paper.

Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-06-29T18:03:48.509291Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-29T17:36:40.290498Z digest=sha256:e7c240ee95cdbd617d0b0a17dd75c5399014bf74039722d7707efd93c1ff084d

Observation f4ee1d49-2a26-4813-891a-45aaada12f46 · inbound

AIRGuard: Guarding Agent Actions with Runtime Authority Control cites this paper.

AIRGuard: Guarding Agent Actions with Runtime Authority Control RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-06-29T12:53:27.150378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=arxiv_source observed=2026-06-29T11:27:11.944532Z digest=sha256:c1df83990ebec9d09a4b24f14abbe91dafdbef6a4075b609667aac1c47d86bea

Observation 3ff414f6-8af9-4fda-902b-c7e1d2c13121 · inbound

Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents cites this paper.

Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 37

Resolution
verified exact
arxiv_id, observed 2026-06-29T08:23:14.888499Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=arxiv_source observed=2026-06-29T08:21:44.993917Z digest=sha256:76f62f642da832b08760515b1e77f2327722a8bd265980b95544509575919541

Observation d67d0e00-d1b5-41ec-b992-02a653b76759 · inbound

Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools cites this paper.

Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 9

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T14:42:18.230738Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=arxiv_source observed=2026-06-28T13:46:11.765116Z digest=sha256:3d131a2de22a52e6a0aa3000135fcdbe3040f39d777c99ffa2f0465a79dae654

Observation 8ca0a012-5ed1-4940-8e35-707412bf006a · inbound

SecureClaw: Clawing Back Control of LLM Agents cites this paper.

SecureClaw: Clawing Back Control of LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-07-03T01:37:30.746835Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-27T16:26:01.286610Z digest=sha256:809d26d355ce757bec19c0c0d18cdabd23a978372bfd0ef0343870afa903a331

Observation 23bc665b-1513-4c67-8076-ab33edaecd18 · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 58

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T06:17:41.876038Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:3786c2c017a43a177b405aa655eb86cb2d33e078c7464389b12327d8b4f819a6

Observation 5e84c857-4e4b-4856-80bc-499d91357c64 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 255

Resolution
metadata mismatch
arxiv_id, observed 2026-06-27T13:20:56.872177Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:4f9f79e33b6ed7611b89b410a55e31f9dc6cb6edf009805df0ac84d281d900ef

Observation 4ed535c9-1144-424a-9307-3c20744aa829 · inbound

OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents cites this paper.

OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-07-03T11:58:06.930341Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-27T09:11:42.204778Z digest=sha256:3adf172aac1c270547f8e53b3cd7070b5197f8ec12fd314b3775c06091707c79

Observation 8d49e100-8e40-44b2-a0ec-152792d33054 · inbound

GIF: Locally Sound Geometric Information Flow Control for LLMs cites this paper.

GIF: Locally Sound Geometric Information Flow Control for LLMs RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:49:46.735990Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T08:24:49.908288Z digest=sha256:e323bb352db5c07999f08ace5aef8a9b9c8e764e4ff16ffc8a3cb5ba4acc188b

Observation 61facb60-add7-4507-8e20-d8a5151dbc76 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-07-04T13:39:51.335715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:a80bf550c23fe63f1e4bdbf08020b6696980136cfa5b5b622972e3d534a2db4a

Observation 68134e5b-cb3b-4981-80b9-fb64ac43457c · inbound

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents cites this paper.

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 133

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T14:09:53.128363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T04:29:16.386339Z digest=sha256:4a6f65ff717b9a07ef38be2a34e37512ca86451a9fe51d29dc8057974d593316

Observation a647f80e-0495-4430-93fa-92f54cb5c1d6 · inbound

ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents cites this paper.

ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 25

Resolution
verified exact
arxiv_id, observed 2026-07-01T17:25:51.826373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-29T03:44:48.288444Z digest=sha256:540e9cd9bc1cc38de14ae8dc2b93fa6c73aed09098923a62e191a31843d42940

Observation 38ed1a0b-f2b5-48e9-b0d9-2aa1dbaad83c · inbound

Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware cites this paper.

Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-07-03T10:37:56.234656Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-07-03T10:28:59.762796Z digest=sha256:3bdcc5b4ed6dd6b08b3dfad9ec4c1067df905d553b0e1c933f55ecc432aeaed4

Observation 92320250-441e-4518-9a1b-5240ada67f43 · inbound

Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware cites this paper.

Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 47

Resolution
unresolved
no resolver link, observed 2026-07-12T08:09:57.596812Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T08:09:57.596812Z digest=sha256:f7434f3eabdc40558f04b2c38a3fbebcdbc52d3f419cd02025f72c2759b3a8bb

Observation 6fc5b00d-74af-4ecc-8d8f-5b149157070e · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 49

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:bfda4e99c64e1252a8902bf8c96e11f91135be1ec3f967b5002ee718544b9433

Observation 0f24a9c5-0e3d-4916-b197-713dd251ebfd · inbound

Prismata: Confining Cross-Site Prompt Injection in Web Agents cites this paper.

Prismata: Confining Cross-Site Prompt Injection in Web Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 102

Resolution
metadata mismatch
local_arxiv, observed 2026-07-10T12:27:04.073825Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-07-10T12:20:03.672480Z digest=sha256:cf26deae3eccc7f99231c05ea21bc585ccaf6e2aa127852902f86cc27c629f13

Observation 086d7580-83f5-4d3e-a7f6-81fb0196c399 · inbound

From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows cites this paper.

From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-01T22:55:50.423697Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T22:55:50.423697Z digest=sha256:35228df057b746802dc5a8bc87b8bb6dae2c50794dfadae5c197d5af3fe7b61c

Observation 8c60331b-a861-4004-b04d-39c7c8aa3430 · inbound

Data Leakage Prevention in Agentic Applications via Preemptive Hardening cites this paper.

Data Leakage Prevention in Agentic Applications via Preemptive Hardening RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T14:11:22.426651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T14:11:22.426651Z digest=sha256:4792af98720a209f81b6f0973ae9b923db4fc2e4fbd33d792e44b0647b9cffe7

Observation 9261d1b0-3159-4ef0-a2b5-92b5e3377723 · inbound

Beyond Component Testing: Validating Agentic AI Systems cites this paper.

Beyond Component Testing: Validating Agentic AI Systems RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-03T07:41:24.234199Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T07:41:24.234199Z digest=sha256:50367be0bbc7e1d8d9d53a1e05e986afb130091305f2933b50a90782ec4a3af0

Observation 58746dc0-eb42-4bcf-b78f-43d7b37caef6 · inbound

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models cites this paper.

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 163

Resolution
unresolved
no resolver link, observed 2026-08-15T14:21:42.763513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T14:21:42.763513Z digest=sha256:7b7c2a5bbff36fde399dfc6b32eea8721c9e2f7a12fcda24dc048003f4e4b464

Observation 8e10ec44-80f8-4ff2-94f6-1c098895bc68 · inbound

Rethinking Agent Security as a Networking Problem cites this paper.

Rethinking Agent Security as a Networking Problem RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.643873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.643873Z digest=sha256:bf28121f320f3d450a3e6f8a3d9899c3bb79030e3b47337f0d7cd9b7ab801e24