Pith. sign in

Paper Citation Record · LEDGER

DualView: Preventing Indirect Prompt Injection in Personal AI Agents

As of 19 August 2026, this Paper Citation Record lists 68 of 68 outbound references and 0 inbound Pith citation observations for arXiv:2607.03821.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.03821 v1

Coverage vector

measured 68 of 68 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-11T23:43:28.649948Z

measured 68 of 68 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

68 of 68 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved68
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation dca2c3c6-1186-4ef0-a358-88a3e2d19e33 · outbound

This paper cites React: Synergizing reasoning and acting in language models,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents React: Synergizing reasoning and acting in language models,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:4edc17fc5324d4b737236a927c9a4103dfd85d30befa4700f41b6e1e69c2a416

Observation f3df4cbe-6537-4127-942f-ed0f89a3d12b · outbound

This paper cites Toolformer: Language models can teach themselves to use tools,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Toolformer: Language models can teach themselves to use tools,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:47cedc36f575f96dc3a7ca4171cf43f6392dd4ba82454523985396f288c228fa

Observation 434c079f-6475-441c-a699-2cbe8987a82f · outbound

This paper cites Chatgpt plugins,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Chatgpt plugins,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:fa59c85d3cded9b71aa551c3ca44951d8c81ed42636da56c6812700b63fb7d14

Observation fa066d97-c493-496f-9d38-ce2f24e60067 · outbound

This paper cites What is microsoft 365 copilot?.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents What is microsoft 365 copilot?

Reference 4

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:505791fc77ae99e3f6ef55713838df4f5c9191a136fe2bc253c49d38dfc40716

Observation 9879d03f-dc8f-4606-a15a-8b8f2f7c63f9 · outbound

This paper cites Model context protocol,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Model context protocol,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:0c0b4b1d70cf0e7dc40796f3aec407d8a46b9fd51e4f428ccf52c19185afa864

Observation ead459a0-2ad3-4d4a-8e37-0cb00c4a2fde · outbound

This paper cites OpenClaw,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents OpenClaw,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:e3aa4a2b8e89c8ac5af447eaa4676d783bc5d182ee1789e81c5a017764ba0707

Observation 26126fcb-a15b-4847-83e1-def2d2878b26 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:a6c039e05868a3741f449832559d7f9710ff24c6648f5722e9eddbd35da0111d

Observation d773cc28-72dc-49d7-ad30-e32eb3087cdf · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Formalizing and benchmarking prompt injection attacks and defenses,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:f4fc7b55cc06f28e9e3b4b2816540104a7d05376cd132675b5d2184a1bbf17f5

Observation fff67a2c-b9bf-4c3f-bfd6-99c019a402a8 · outbound

This paper cites InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:75486d9d40c723b6e6682ced4d53e313f07d0220a13315039c0e0a269474dc41

Observation 8d91d6c0-f02f-4ed7-a99c-811fb6efcc2b · outbound

This paper cites The dual llm pattern for building ai assistants that can resist prompt injection,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents The dual llm pattern for building ai assistants that can resist prompt injection,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:6236d8de334e9762c523e0d14a2a84aae5bc716b2a26aae4a88d75d7036a88da

Observation fb69f65f-e882-4682-a943-47ac5c597be1 · outbound

This paper cites Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents

Reference 11

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:d0e2173498c0a0bf54fbf89424597248117585f919332fee559bdc64ec8980b2

Observation 285c5605-fad3-49bf-a22a-ee7a420b26e3 · outbound

This paper cites Defeating Prompt Injections by Design.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Defeating Prompt Injections by Design

Reference 12

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:749bbf2dd2385b552fa87d7d379ed88c145198e2f1f94c69182468cb29561064

Observation ceaed338-de00-46f2-8064-13fc404bdf2f · outbound

This paper cites Securing AI Agents with Information-Flow Control.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Securing AI Agents with Information-Flow Control

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:c0affdaac6e495a97c9a2de8f1277c139d6da77d0f6751b60c1ac562588bfa06

Observation 5b3d927d-6f33-4b1a-bc75-2ee3e65bea9c · outbound

This paper cites PinchBench,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents PinchBench,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:088fcd04fd72a2b82aa69e0d22f2ff5f9884763ecf38881af6c899e9a1006402

Observation 9de6ba4a-ebbc-4602-aaf6-104919081a38 · outbound

This paper cites Demystifying RCE vulnerabilities in LLM-integrated apps,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Demystifying RCE vulnerabilities in LLM-integrated apps,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:cb53e2a34bcb55f9341ca94bfb51cf7493e269d62e0cf74ddfaf26f0594f0651

Observation c6aca727-7578-49d2-9ab4-51ae5ef4f0f8 · outbound

This paper cites Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:8dbdf39b40c620541e2fad25f33ce28bd01631651be417a8ca8fe9cb8e76f8dd

Observation cf24e6b1-21f0-4818-8fea-888e4bea5f7f · outbound

This paper cites AGENTVIGIL: Automatic black- box red-teaming for indirect prompt injection against LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents AGENTVIGIL: Automatic black- box red-teaming for indirect prompt injection against LLM agents,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:7c4b84fe3e3b328a89f0aa1dcdfeedf413bf2e2cb0f8a4dfccca1373437eac32

Observation 882da221-d8ed-4050-bd80-7898a459ec4b · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:9091c4ed560662e4cb55a6991f67f52426c8a6076ec66ee06dd7a3577bd05887

Observation f174e6b4-bfa6-450a-9827-d0adc68dbdaa · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:c7934f51cd6c3a00df092879c10103dcabea3075a4212e0c6a6d74cc185ec2ee

Observation 7c95462f-3b54-482b-b0bc-636a2eca3ec3 · outbound

This paper cites Overcoming the retrieval barrier: Indirect prompt injection in the wild for LLM systems,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Overcoming the retrieval barrier: Indirect prompt injection in the wild for LLM systems,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:86f892329a5b317c43a5d37fb5e5ee2bad25eeb25a387bfea87f4138cc4f526d

Observation 6e35e460-a5a2-4942-b7f3-4ca0e8c0aea4 · outbound

This paper cites ObliInjection: Order-oblivious prompt injection attack to LLM agents with multi-source data,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents ObliInjection: Order-oblivious prompt injection attack to LLM agents with multi-source data,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:aa49f623a846748d2a2abf2f070ddb62eb5338a44b26b895414eab04e3e96fe2

Observation 882e2567-952c-4882-928f-b03f29063928 · outbound

This paper cites Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered LLM agents,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:0c2ab3442d3f35210478c619a151134cd2a9a4d8bf0f9794eec2e0cac89c0ba2

Observation 4b80a929-e222-4a6c-955f-7360eef6b3f3 · outbound

This paper cites Prompt injection attack to tool selection in LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt injection attack to tool selection in LLM agents,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:558ff503a2475d266589b7516c5e1e3a3a2595fe146a2bf7aa48e29c2e1a9ae9

Observation 5b945dab-86de-41f1-96b2-ec684a6a57f4 · outbound

This paper cites Available: https://www.ndss-symposium.org/ndss- paper/prompt-injection-attack-to-tool-selection-in-llm-agents/.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Available: https://www.ndss-symposium.org/ndss- paper/prompt-injection-attack-to-tool-selection-in-llm-agents/

Reference 24

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:42e7209365aa435a5a4c64fb128c22e35575c55bf8259904cabaf9219dbdc40a

Observation 707ad5aa-4db5-4f6b-b2c0-4196f9d91028 · outbound

This paper cites SpAIware: Uncovering a novel artificial intelligence attack vector through persistent memory in LLM applications and agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents SpAIware: Uncovering a novel artificial intelligence attack vector through persistent memory in LLM applications and agents,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:ee4c052e6a25e14aead67c3c932e0a5cfded35fbba95747e2b19ae5a913aaed3

Observation ae153de8-5f30-405f-820d-7432d7acf9c5 · outbound

This paper cites Memory injection attacks on LLM agents via query-only interaction,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Memory injection attacks on LLM agents via query-only interaction,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:76538e492d5e2cbdfda7196a77d6b42b500cacb87dd7c3359e4261ed05adf11c

Observation c5e7cd97-a3b9-4f4a-81e2-0ecb909374ef · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 28

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:45837196a762682e9dfef58a2323adba4f5e519a7cc36f9ada7d80aa25135a88

Observation 95266bf2-06bb-47ca-9c77-f4ae6bd75ff0 · outbound

This paper cites AirGapAgent: Protecting privacy-conscious conversational agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents AirGapAgent: Protecting privacy-conscious conversational agents,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:bea5536e51030ae8de2abc316c7324eb2a44ee42efc83ad66eb9e33a3e216925

Observation d7fed1e6-e116-497d-bf6d-2365e4c49738 · outbound

This paper cites System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:49419c9fcca351debcf211216945e883bd1f4bc61173b7412c5222ac4c950f57

Observation 8c59a475-771f-49d2-810a-9549a5b4cd9f · outbound

This paper cites ACE: A security architecture for LLM-integrated app systems,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents ACE: A security architecture for LLM-integrated app systems,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:fafa9e1107e76d25400d37871847b1b514bbd6b7e3195be3991d9129ec4fd160

Observation c92e960b-82e4-47d8-80d9-bb68f10c45a3 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Ignore Previous Prompt: Attack Techniques For Language Models

Reference 32

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:c9c7b9188e83ef6d86d6d87cb87631bec0f53ddee2f4e8aae904ef9322683cb0

Observation ec6240b4-9108-4cff-a289-c1be0999ecda · outbound

This paper cites Jailbroken: How Does LLM Safety Training Fail?.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Jailbroken: How Does LLM Safety Training Fail?

Reference 33

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:f67abede2d38e91e46de0deda5e578d976ea5deb6994f4f82d2747e88fdf71e9

Observation 4c46affd-ac84-44db-9733-cc5622be7f73 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:1efd26f7cfd4139e6b04ed999797e3c95810d5a878efa63f3c8cd2ca50e18569

Observation 7249f692-e771-40e3-9be6-ae7690e9d25c · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 35

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:fdfc32238b426c08995fcd7d345c3bfc8ff714e5f6ae337c74f76c5f51cdc3a0

Observation cc8c9450-ca6d-4062-b6bc-fd841cec45ce · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents StruQ: Defending Against Prompt Injection with Structured Queries

Reference 36

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:2a1b4f82253df07a36a5c3709110c05148438d098cecca2efb03a7e0c1135e3b

Observation 48306b39-cf50-4f26-a56f-c4788fb4604e · outbound

This paper cites SecAlign: Defending against prompt injection with preference optimization,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents SecAlign: Defending against prompt injection with preference optimization,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:11c068b028fcafb58e1d9ecdd232bf4fff60f369b3b02d7bc420774463a55965

Observation 618748e7-8306-4956-9a7c-a5ab2d650a3e · outbound

This paper cites Llama Prompt Guard 2,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Llama Prompt Guard 2,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:08e25aa625271dcad18dc16f6fbd4216bffe882e6e3d3bb75c666f61b1008bf1

Observation 52445bad-392b-4d91-ba0f-481e686e6f3e · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 39

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:29654ec43e4af26c1c8462a73b2e61bedbbd813697e5794e9d870f79e4817f17

Observation 17091683-d763-4054-a35a-96ecbc467d19 · outbound

This paper cites DataSentinel: A game-theoretic detection of prompt injection attacks,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents DataSentinel: A game-theoretic detection of prompt injection attacks,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:c7264e78c82dccd65a9afe79267e240704e85a15bf9b71a3a3947a0d3cc6bd15

Observation 42c9e19f-6ee2-42ba-a3e7-7a02360d692e · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:237ce961e299f9e9593a8ab69bebf88ff71f3ffc77b0b918c9ec192758ff652e

Observation bd9e7f4e-d0a8-4f3d-8535-63d5d01ef2ca · outbound

This paper cites Attention is all you need to defend against indirect prompt injection attacks in LLMs,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Attention is all you need to defend against indirect prompt injection attacks in LLMs,

Reference 42

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:38c7d1f07e6ba8558badea925fcd962242f35faacb08691cb37f07d79a7e3e3c

Observation fa054f62-2795-4ad7-98c8-6a2a4f9a53cc · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 43

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:7e89cc40ddc6acc7d802f84940f0ebfe7848c57a25c6c16f23a9382ca7d7eb0e

Observation a5a2d4c3-80de-4f1d-a254-4f1d356c252e · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:5ec39219557c59705f6ab232b80c7671429f83f3740effdb48b80d3fd80b3c1d

Observation d0a1c60e-41b9-4762-a575-6d9a2457a781 · outbound

This paper cites DRIFT: Dynamic rule-based defense with injection isolation for securing LLM agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents DRIFT: Dynamic rule-based defense with injection isolation for securing LLM agents,

Reference 45

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:a4fe658c55345b7f21528c4c602b9030f7d4a61dd96b49c1c92a0e79b9de01e4

Observation 759734b3-9ed2-43c2-ac3d-c918a3d29ada · outbound

This paper cites ShieldAgent: Shielding agents via verifiable safety policy reasoning,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents ShieldAgent: Shielding agents via verifiable safety policy reasoning,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:6b2566f84b9e3a1eba57552c5e7e4f9858970236716f468f9e2cb349c7be798b

Observation d20f98ca-a415-40ce-93d9-2e11d463a69f · outbound

This paper cites GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning

Reference 47

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:32e0903905e6c5888af8516756c1a3565c9adddb0f7754e1c8a463ffce4dba99

Observation dcbd94a6-d90b-4cb3-8eee-1c3c723c46bf · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 48

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:8950c3184aaa979179c756760f3e5ac7693a9a57ac397e90a95371a7b695c53e

Observation 6fc5b00d-74af-4ecc-8d8f-5b149157070e · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 49

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:161894fc317ba86f810e9892f846c54dcf6b735d3b3ff98f98cdfcbeab7dbf27

Observation 2041e5f4-7221-4875-b358-6eff8b6afffe · outbound

This paper cites Permissive information-flow analysis for large language models,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Permissive information-flow analysis for large language models,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:17132cb96792e737f342d6454fafb2edebcbfdc55629dfd0beebeeae6be15245

Observation db07bc48-7ebe-4ebe-bc99-76253403e426 · outbound

This paper cites Optimization-based prompt injection attack to LLM-as-a-judge,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Optimization-based prompt injection attack to LLM-as-a-judge,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:0171647c1e90df18f5cb35e1c27b5c6ca62719ca1a9e1719f3cff4934a18b2e9

Observation 59e95052-ea3e-4f48-9713-2a54f41b84dc · outbound

This paper cites OpenShell: A safe, private runtime for autonomous AI agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents OpenShell: A safe, private runtime for autonomous AI agents,

Reference 52

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:6e51a392ebe154dd36bc65f6564bde1d69d57dfd82fb14deb26ecb291af88b72

Observation 37419af9-99c8-45a0-be4c-ba9465a6fde7 · outbound

This paper cites Webhooks,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Webhooks,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:c7747af5c02a7076b992f89515a1c3bce66e862f8d67025b42d5d80ba0b9599c

Observation f781b8ee-0b2a-4233-ad64-777a60019a19 · outbound

This paper cites Configuration,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Configuration,

Reference 54

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:1b10d0650016fece26cecab9925030693277b70bf097f7ff5c7365d9e42c732f

Observation c76b4449-a21d-4b33-b24d-1e9dcf3bcdc0 · outbound

This paper cites an unresolved cited work.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Unresolved cited work

Reference 55

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:111bbeba7f4b36c52bf282de85e15cf8585dfbb524af87ecb0f1946b04ae1983

Observation 7bb34070-789e-490d-8c82-77e285f646f2 · outbound

This paper cites gws: Google Workspace CLI,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents gws: Google Workspace CLI,

Reference 56

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:709074d84a4086a6616f7cce25c7d45d8d74f18f7bc548195bf874b9a5979ab8

Observation 040810cc-e61f-42db-a35a-2eb2519ed57b · outbound

This paper cites GitHub CLI,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents GitHub CLI,

Reference 57

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:7d1b3358bb7bfbfe2747f318227dc5fd4506ce6ab71328d4e7b4e2b92ee8c75b

Observation c52f5f5f-d966-4c28-9e05-07c50195f8c3 · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 58

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:603753e6b26319d770a3a70fdd277ff2561544b0bacc7c13ae286fb7f937a04d

Observation 67683645-9ea2-4f0d-ba4b-14659bbfbac6 · outbound

This paper cites Great, now write an article about that: The crescendo multi-turn LLM jailbreak attack,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Great, now write an article about that: The crescendo multi-turn LLM jailbreak attack,

Reference 59

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:a280288837c22d5c9b933952054fc22b1fc6b3f25ccad5f06435998f4a6b4d75

Observation f82c38fb-2c7f-4e1f-b78c-42d6d185762f · outbound

This paper cites PoisonedRAG: Knowledge corruption attacks to retrieval-augmented generation of large language models,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents PoisonedRAG: Knowledge corruption attacks to retrieval-augmented generation of large language models,

Reference 60

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:b33a398f1e5eab6c0b8e869491ddad015cedb1945a5cce5aa3f8be87fa3004bd

Observation b6bcc6d7-2155-4201-8c3c-759ac403c9b1 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 61

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:2228803170e833afce64cb6804c3ab646589af83d3b25d08b2af5f24539af30b

Observation f082d9f9-40a2-4a0a-86e3-7febf098484c · outbound

This paper cites Optimizing agent planning for security and autonomy,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Optimizing agent planning for security and autonomy,

Reference 62

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:5fa4861efe4272919892994c89e38b72db81657bb3157f4fefc29ce37c3151be

Observation a214d93e-87bd-495f-ac05-416f1694e95b · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Progent: Securing AI Agents with Privilege Control

Reference 63

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:4b322072a6cc28652bef48588e762a67836e5c7a3d56a32db50e1b620bcba9ac

Observation b31e0bc6-77f8-4d07-a83e-586c8767cefd · outbound

This paper cites Contextual Agent Security: A Policy for Every Purpose.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Contextual Agent Security: A Policy for Every Purpose

Reference 64

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:a2c3924e5bc51afc1c6b25a2f74c9a03a77beb2946d7e555b6a6eadc42dc7c45

Observation 1092bb99-0554-414c-88d7-2399c63618c8 · outbound

This paper cites SAGA: A security architecture for governing AI agentic systems,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents SAGA: A security architecture for governing AI agentic systems,

Reference 65

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:0ad3669bf821d910ba6bad2f0d2a33f356ee3afd128abe5ae7e02695e0882f0b

Observation cf914bd3-be8f-489b-9fce-d95e06632c34 · outbound

This paper cites Claude Code hooks reference,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Claude Code hooks reference,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:f1807b01e513c95090b457b511553a8575a808de629eecc0a8db2b4288943ebb

Observation cabf711b-7a39-40a9-87f7-6d5411bce605 · outbound

This paper cites Hermes Agent: Hooks,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Hermes Agent: Hooks,

Reference 67

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:19bf2d86c91b4c9e70917805797fc765b9de5815d863f1e7843dfc1ddc6ab730

Observation 66a8c0fe-fb11-487b-a116-ba50bb894277 · outbound

This paper cites Make agent defeat agent: Automatic detection of Taint-Style vulnerabilities in LLM-based agents,.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Make agent defeat agent: Automatic detection of Taint-Style vulnerabilities in LLM-based agents,

Reference 68

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:cea115049cf4cb941ad8f81dd754ac6e864aca954bc4409bc0bac364dfdc1bb6

Observation a0779c28-2aac-4ee1-9332-1943b60d6d4e · outbound

This paper cites Quarterly report.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Quarterly report

Reference 69

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:1d344aef9ca5967996fa2cce4759407cf9728c0c52a9d7acd6a9faaa224fab44

Pith citing papers

No inbound Pith citation observations are available.