Pith. sign in

Paper Citation Record · LEDGER

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

As of 17 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2608.00747.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00747 v2

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T04:17:02.594840Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-16T06:30:59.297886+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved26
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation bb170696-a993-47e8-ac53-8a7eea8e35f0 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Ignore Previous Prompt: Attack Techniques For Language Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.494770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.494770Z digest=sha256:def8829630318b28b140533484c29eab4b227da51a47de5ec31a6f3d53d6e71e

Observation e51ae8f8-dfe0-4058-aeab-bfe27432df12 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.499370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.499370Z digest=sha256:063dda2feac0e6932e9b7d13da86c22cc20ec00b15f09489427fd283846eaa3d

Observation 7c2b1b60-bd8f-485e-ba4e-d4076050b839 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.503427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.503427Z digest=sha256:6643ceec5a717a1d0669a259f4ecadc242688f9cc3d9dbe36400b9c27890c1f1

Observation ce38dc26-2af1-4fe8-ab2e-b556bf871fa2 · outbound

This paper cites A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.507970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.507970Z digest=sha256:0c23000e5c86bf16a72a7c4cf46ef485aac1864f0c336ef1df9990c48abd0e23

Observation b3b9ed97-2620-415b-96a6-711d66e37531 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt Injection Attack to Tool Selection in LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.512504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.512504Z digest=sha256:d40236b37a0d2ed0387a41a72859bc0283dd181ef2a3eadce9a93e1dfaf3b4ef

Observation 558cf644-7c68-49fd-9844-57c81c380287 · outbound

This paper cites Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.516491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.516491Z digest=sha256:66623d7603d327c2f7b2e1ac65c5ab7779bb28d3ee8131af71d8a16fafde18dd

Observation f5e615bf-34cc-4b35-992c-a4881832719f · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Memory injection attacks on llm agents via query-only interaction,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.520587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.520587Z digest=sha256:c926092d749775600724dfe664b08dfcc239e6b3f7b487bd51f9f9f57f0b490b

Observation b85e4991-a6ec-41a2-ab09-3bd45cd0dd9f · outbound

This paper cites Prompt infection: Llm-to-llm prompt injection within multi-agent systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt infection: Llm-to-llm prompt injection within multi-agent systems,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.524559Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.524559Z digest=sha256:be40800e180590897eff150a9b39e3591c8e63fcf9e8036469866e4693790b15

Observation a13f49f7-e8f2-4232-9e0b-09ee727c3222 · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.527779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.527779Z digest=sha256:37834beebedf498b985275018b4e0c7dde56d2e643d11b0ed7f56efb9becc622

Observation d1181928-a6dd-4bc4-81e2-21c2891f11cb · outbound

This paper cites IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.531826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.531826Z digest=sha256:ece9c87b39b94ad4722a93eecd51204ae4edc6af57f3dfb0f5eecb13e5db9d9c

Observation df05d453-c18f-46f1-af60-291b8c858210 · outbound

This paper cites Multi-Agent Systems Execute Arbitrary Malicious Code.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:9c24d5c5a847ab0a39293af17e467188026012f7afeb2063ae139dde726e5d21

Observation a261c141-7ae3-4579-b997-dfd297475108 · outbound

This paper cites Red-teaming llm multi-agent systems via communication attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Red-teaming llm multi-agent systems via communication attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.539306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.539306Z digest=sha256:b778e04aee1197f1cde69738cdb6c835e8fe2ab3d3929a749bcfda542a003a87

Observation 8af621a0-4dd1-4298-be2e-110119c99a48 · outbound

This paper cites Breaking agents: Compromising autonomous llm agents through malfunction amplification,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Breaking agents: Compromising autonomous llm agents through malfunction amplification,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.543199Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.543199Z digest=sha256:0b37d047eeead9c992e3451618765da456dbf87e31918fb1f816caa13abcc553

Observation 59e1107c-10eb-4979-88e4-7a47f7bb4241 · outbound

This paper cites BadRobot: Jailbreaking Embodied LLM Agents in the Physical World.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems BadRobot: Jailbreaking Embodied LLM Agents in the Physical World

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.546665Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.546665Z digest=sha256:9021ecc2f91989871099f7d847416264ebe65ff2dfba6497a9605601f3169d52

Observation 92ca83d1-8370-4254-a965-5d995bd50553 · outbound

This paper cites A study on prompt injection attack against llm-integrated mobile robotic systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A study on prompt injection attack against llm-integrated mobile robotic systems,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.550312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.550312Z digest=sha256:a961c94c976e48567eac5df1aa70ab9192ae7a0dfddfa25b96512b8893ff3c7b

Observation 780ac79f-a127-4fe2-a6d8-35f377c52541 · outbound

This paper cites Long-horizon planning for multi- agent robots in partially observable environments,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Long-horizon planning for multi- agent robots in partially observable environments,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.553854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.553854Z digest=sha256:fa21895177c925da1856ceb6d3d04b12f83b562bfaa31031fc8b810a0d481a49

Observation b770397f-38d6-4569-a686-d40e456a5ef4 · outbound

This paper cites AI2-THOR: An Interactive 3D Environment for Visual AI,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems AI2-THOR: An Interactive 3D Environment for Visual AI,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.557683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.557683Z digest=sha256:650f9f549b3e6dc778d9f32ff54b872596a33c8db973a94c89a0fe6449821c24

Observation 94a70e48-81f1-47a6-b2e5-c5d52ffe3948 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Formalizing and benchmarking prompt injection attacks and defenses,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.561146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.561146Z digest=sha256:9cf128bd03fd6c9116e13dafc1468bb5ab23ae9293b66d1bb6edc0d12caf5574

Observation 5989c688-0522-4bc9-a1f1-35dda94cdeef · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.564492Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.564492Z digest=sha256:ccc79ccccac1fe64d28fe83be98d421a6e468a4c1492687c26a01701c4a18291

Observation c55359a1-2b3c-49f6-9650-7e85313e2762 · outbound

This paper cites Jailbreaking llm-controlled robots,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking llm-controlled robots,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.568841Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.568841Z digest=sha256:fc4ca5946e1c240c95bf2874be95aa16db0c1aa6f73fa06715abeab3973b81d4

Observation f0d232bb-7615-44f2-9eb3-c775250afb6d · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking black box large language models in twenty queries,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.573034Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.573034Z digest=sha256:282ca5f71e702cbeea3ca26f28227838ff3e9ef73355b5337d2170d89ddaadc7

Observation ccb795ea-410c-463e-b843-18a3122bd09c · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.576515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.576515Z digest=sha256:78ee2897b8c21bd391b25bac278c5225c940fe80b4c1d49dde38dfd638f47528

Observation 3a84d894-086c-40ad-9149-71cfca548d58 · outbound

This paper cites Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.580448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.580448Z digest=sha256:857858f1ad85a61fe0b63f2c6abaa6a3d8cecc5a10e125eba4aab545ec9e892f

Observation f0902229-485e-4fd6-9b20-fbef892648d8 · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.584306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.584306Z digest=sha256:d5892547a19381567b85e6c3d2f8be2f9841aca7d2edea43ec5f8d5cfcc24006

Observation 3b86aa3e-7ec1-4254-bdcd-bd320813b959 · outbound

This paper cites Sentence-bert: Sentence embeddings using siamese bert-networks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Sentence-bert: Sentence embeddings using siamese bert-networks,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.587650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.587650Z digest=sha256:306a2f04c1b630f64c0daa450bccd5b200e4d12812977309bf1a7990eb9f81e6

Observation f4472c28-19f9-4a15-a6fe-6d667a43d765 · outbound

This paper cites Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.591154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.591154Z digest=sha256:11f15352a2172efc2c640b30e2992e97769a27c18e495af2513919b890a98a51

Observation 7b3561d9-29b1-40cc-91cb-e557b307c12c · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T04:17:02.594840Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.594840Z digest=sha256:429ea82051f0a1f2ebb9824499e4cc4313347e2bf1ba277625f17482e0da9167

Pith citing papers

No inbound Pith citation observations are available.