Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T17:42:06.624702Z
Paper Citation Record · LEDGER
As of 20 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.04741.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T17:42:06.624702Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
55 of 55 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 0c06a9e7-cc4a-41a3-a311-3acce751fa83 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents A {Large-Scale} measurement of website login policies
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation bbb70c9c-5074-4cb9-bcee-d43731f71a45 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agentharm: A benchmark for measuring harmfulness of llm agents
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 5acbad47-b0d5-4a06-b076-814729825694 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Phishing activity trends report, 1st quarter 2025
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 9d1c3dc1-7c75-4bf6-978e-34199d0c4a96 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Car- bon: domain-independent automatic web form filling
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 0e5f3b4a-478e-4910-af57-2627c85cf3ea · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Vpi-bench: Visual prompt injection attacks for computer-use agents.arXiv preprint arXiv:2506.02456(2025)
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ad6420f2-2139-4eaf-8765-ce1ef1f72e86 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Real: Benchmarking autonomous agents on deterministic simu- lations of real websites.Advances in Neural Information Processing Systems 38(2026)
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation f158a4ea-de03-4ef6-8d65-19e03acd5f2c · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Efficient selectivity and backup operators in monte-carlo tree search
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 1cd58b4e-a788-4296-a713-be06b18d6f92 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Decepticon: How dark patterns manipulate web agents.arXiv preprint arXiv:2512.22894(2025)
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cbfe2e78-bc94-496f-9be8-286b4bc748dc · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems 37 (2024), 82895–82920
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 98041349-4e5f-4039-b7e2-cabbc9b00a79 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Mind2web: Towards a generalist agent for the web
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 64fb2902-695f-4237-8479-033aa5276a20 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents User-driven automation of web form filling
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation bd13c105-9972-4f45-b0a2-4cdc8ba26691 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 88690090-5ea0-4a8d-b968-6d9ab6149e87 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems 38(2026)
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 9169ba28-1482-4e7d-bd6c-f70d72dd0ce4 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Passwords Are Meant to Be Secret: A Practical Secure Password Entry Channel for Web Browsers
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation b1b54759-65dc-4a4c-9bf3-ca097555ecea · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents {Topic-FlipRAG}:{Topic-Orientated} adversarial opinion manipulation attacks to {Retrieval-Augmented} generation models
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation d0d057d8-569d-4618-9b7b-f4b5d13eabc5 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 4e81c17a-611d-46bc-b011-853535dba31d · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Learning to Navigate the Web
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f556136c-c0d8-4694-a7e7-9f8e43e436bf · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Webvoyager: Building an end-to-end web agent with large multimodal models
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 3eb38f5c-10a0-4197-b87e-aa1006979022 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dd0301f5-87cb-46c7-a1cb-4ceebaac7e8c · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Y., LO, R., JANG, L., DUVVUR, V., LIM, M
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation f0f1bff5-1ea6-4d55-9d69-8a5293ff150e · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered llm agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 74fdf42b-fffa-4042-b859-5b2a870ec5c0 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Eia: Environmental injection attack on generalist web agents for privacy leakage
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation db134c8c-9f2a-4ad0-8a8f-da11c4adf9af · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Fill in the blanks: Empirical anal- ysis of the privacy threats of browser form autofill
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation fd2f45a7-0f85-4c9b-92ff-8bf5727f6610 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Reinforcement Learning on Web Interfaces Using Workflow-Guided Exploration
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5ce63290-07de-4085-bc42-dd938674c723 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents H., DIVAKARAN, D
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 8f183b19-d169-487c-b4ff-4c3b85ae76ee · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 80c3476e-d826-414c-b6c1-e9fb32e540c1 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4cb0301f-ca33-4426-90d1-f27180b5cee9 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Microsoft digital defense report 2025
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 99be01bd-bb5f-4fe6-8c90-94cc13c7d254 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents SpatialJB: How Text Distribution Art Becomes the "Jailbreak Key" for LLM Guardrails
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 252ceac1-2319-47d1-90c0-8e32e40bd09d · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Browser use: Enable ai to control your browser
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 88004904-6b3a-4ba3-a68b-df5e5e96f444 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Gui agents: A survey
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 1779d405-86c0-4cf4-b900-29843d6c9c87 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents End-to-end goal-driven web navigation
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation dbc0865c-1e7f-4cc5-9122-d2e1bfb0ddde · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents What happens after you leak your password: Understanding cre- dential sharing on phishing sites
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 12a1ef06-0e46-4973-a765-3626768f5672 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents How americans protect their online data
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation c06644a6-cc01-4d17-a71d-64035d285fb8 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents "I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 980ac03b-fc92-405a-b24a-5bb18d7e2641 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Z.,ANDSUN, L
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 3e00ce7f-bae1-498d-be9c-9ce6750c1174 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents World of bits: An open-domain platform for web-based agents
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 07fd7f01-41c4-4f9a-b5f7-00583a0d33eb · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Password managers: Attacks and defenses
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 04f8fd7c-377f-4e73-99be-7a66ead02a61 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Skyvern: Automate browser-based workflows with ai
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 0fcea2bc-3e8e-4d16-8cd4-fa9888a91f5e · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Muzzle: Adap- tive agentic red-teaming of web agents against indirect prompt injection attacks.arXiv preprint arXiv:2602.09222(2026)
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9af78636-577a-4b5a-8f48-6062d9f584e7 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents G., SZALACHOWSKI, P.,ANDZHOU, J
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation c8c6b994-563d-4f5b-bc15-b86eb36bd7e6 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Digital iden- tity guidelines: Authentication and authenticator management
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 1142396f-0fe4-428f-bee7-3bece7f94629 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 83b5c4e0-e0bd-4249-9a3d-fe8153ca95b0 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Manipulating multimodal agents via cross- modal prompt injection
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 338f8c91-f9aa-4c65-a91f-fe7a5c9d29c9 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 179b35f2-f90c-41d4-a017-2343d6a87226 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents When bots take the bait: Exposing and mitigating the emerging social engineering attack in web automation agent.arXiv preprint arXiv:2601.07263(2026)
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d3e666f8-28a9-48fe-9248-200d80e88cf5 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents H., GOU, B., SONG, D., SUN, H.,ANDSU, Y
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 19ac1970-eca5-43c4-88ee-1e11290094cc · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Set-of-Mark Prompting Unleashes Extraordinary Visual Grounding in GPT-4V
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 567715ce-6635-461d-a14c-4e476672590f · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Litewebagent: The open-source suite for vlm-based web-agent applications
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 01ceb5ba-e222-49c5-ab72-31ab857d465a · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation 28fdadac-9531-407c-aafd-87a204207c0f · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Browsesafe: Understanding and preventing prompt in- jection within ai browser agents.arXiv preprint arXiv:2511.20597 (2025)
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aad90a79-e894-460f-aeac-fe09729d0771 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Attacking vision-language com- puter agents via pop-ups
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
Observation f076ef29-57d8-48f7-8b1a-316dd3d74edc · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Genesis: Evolving attack strategies for llm web agent red-teaming.arXiv preprint arXiv:2510.18314(2025)
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 234e6629-8eba-4481-9c64-4bcaa4b15888 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 39ceafb1-fa49-4336-94f0-dd0c54496b15 · outbound
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents {PoisonedRAG}: Knowl- edge corruption attacks to {Retrieval-Augmented} generation of large language models
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.
No inbound Pith citation observations are available.