Pith. sign in

Paper Citation Record · LEDGER

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents

As of 21 August 2026, this Paper Citation Record lists 18 of 18 outbound references and 2 inbound Pith citation observations for arXiv:2605.26269.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.26269 v1

Coverage vector

measured 18 of 18 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-06-29T21:16:48.677159Z

measured 20 of 20 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00

measured 2 of 2 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T22:04:21.540541Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-04T14:09:53.283015Z

Reference resolution

18 of 18 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved18
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 72b62889-3a51-4557-a736-87959e31ac3c · outbound

This paper cites Tensor Trust: Interpretable prompt injection attacks from an online game,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Tensor Trust: Interpretable prompt injection attacks from an online game,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:25227d2fced12bcd64a5812a349df3a70ca68532a09b8515ca6f3918c06698a9

Observation f1d684b3-ff6f-45da-9fa1-3efc333aa256 · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection at- tacks and defenses for LLM agents,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents AgentDojo: A dynamic environment to evaluate prompt injection at- tacks and defenses for LLM agents,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:b09f9e06d8c40967c7883227bc69d0c9b15d3e5570e58a46967a00ee942f8569

Observation 3975ac22-6c29-4888-a344-8290da4fc525 · outbound

This paper cites Retrieval-augmented generation for knowledge-intensive NLP tasks,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Retrieval-augmented generation for knowledge-intensive NLP tasks,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:aaf7f7d6b32672aaa5cc15ba2c3b6c672425eab50599ce2c775358cccb026d64

Observation 3fa95d3e-3aa2-47a8-a837-7e5eb2826c52 · outbound

This paper cites Dense passage retrieval for open-domain question answering,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Dense passage retrieval for open-domain question answering,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:0ccf47cf74ce326fda80aa03909e894484b12283717a04b8b4f070250a983e0c

Observation ba7c5521-56d3-4223-b1e1-fdef7ca3e7bd · outbound

This paper cites Extracting training data from large language models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Extracting training data from large language models,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:917e6edc3a48b06d116f5fed1a675bd569beb4c3898e0c4ccffee1d8d3ce5dd3

Observation a7f658cd-2c68-4b6d-a6e9-389750daa030 · outbound

This paper cites ReAct: Synergizing reasoning and acting in language models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents ReAct: Synergizing reasoning and acting in language models,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:7f258c61e9e5bc8c4e2d4037bf2df9fe0252bb51a3f1671f31eb5fb05bb015b1

Observation e57f61ee-7138-477f-b2c5-7621c50bba50 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Toolformer: Language models can teach themselves to use tools,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:405fc57a87726d259d68b17914a3ed6806883400b8f46018c0d0a7652539345a

Observation 7e3b1c49-756f-4c7f-bc1d-7f3763901688 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Not what you’ve signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:564d59279278e908533b2cdaaa16d7eb90325311a4656514fe2381285181a784

Observation 4730b1fe-5a19-43f9-b2a5-42b3ac01d75e · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Formalizing and benchmarking prompt injection attacks and defenses,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:52ad37b818dee7f488fcbfcd63669e6b98df7107d5669469ba01140a2b3d7d75

Observation 601e5bf5-1fa1-4fbc-ba71-c35c6d366634 · outbound

This paper cites InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:e5c9535abe838dedbbb125c779a3abccf8305d5426f25513b33cc44fe963048a

Observation 8253c0bd-53d1-45c6-9e61-58270ede9c5f · outbound

This paper cites Security policies and security models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Security policies and security models,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:b8d3e92e1bd672e55518d4860b818a5cb24f7faf6214b4bfffd588970db81900

Observation 35a6cd26-9e68-4dab-aace-1f410191ba1c · outbound

This paper cites Language-based information-flow security,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Language-based information-flow security,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:e83a3c6c6024a664c3d4105c009a167741d3ef37c2d4b964bf9d476b19f0b7b9

Observation e1b540df-fe38-471e-9500-b732d30d7cf7 · outbound

This paper cites Universally composable security: A new paradigm for cryptographic protocols,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Universally composable security: A new paradigm for cryptographic protocols,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:9674c98a4ad274574181269cc417b6a3a10e83e2aa472a0043bc0665707e76ce

Observation 33bc4937-7f92-45ae-ab9c-0c8904a95629 · outbound

This paper cites Universal adversarial triggers for attacking and analyzing NLP,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Universal adversarial triggers for attacking and analyzing NLP,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:441c0bfe34bb439b7bb09554bd397d5088fe0297c3f5faa36c40234d91207143

Observation e9bb1629-2aca-4b79-b6a3-c86ce8e9c520 · outbound

This paper cites Universal and transferable ad- versarial attacks on aligned language models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Universal and transferable ad- versarial attacks on aligned language models,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:c62c97756f03686038bfc651a8c61d8460935c117194b1c8fbf94cb9aaee2023

Observation f17b21ec-8260-49d2-9b9f-ea7eff8a7ad7 · outbound

This paper cites Quantifying memorization across neural language models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Quantifying memorization across neural language models,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:7e8273ca830a14eee034990853613fde80f6b23d38ad6a99a6147e6e05192d39

Observation 81fe9754-35d7-467b-bddc-b31e57a79621 · outbound

This paper cites Deduplicating training data mitigates privacy risks in language models,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Deduplicating training data mitigates privacy risks in language models,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:9353d43ce54bbd9551f9532446e3d62ac751fa2414f5c3f8993c699499b4e5fd

Observation 83303f67-6044-4557-bbc1-a789279c0763 · outbound

This paper cites Training language models to follow instructions with human feedback,.

AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents Training language models to follow instructions with human feedback,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-06-29T21:16:48.677159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-29T21:16:48.677159Z digest=sha256:2e2ea638e27aca7dc750f9413bd9315f368cc74449bd3cba427d126ee1baddcb

Pith citing papers

Observation 7fa13487-93ae-4a6e-a7c4-08c76100a160 · inbound

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents cites this paper.

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents

Reference 5

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:09:53.284810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T04:29:16.386339Z digest=sha256:7a3c146e686d50462e9a7479b0760681b161b850ce84da77cd9abc5f5687c17c

Observation 9be6a542-8daa-471e-8f38-2277f3d7ba5f · inbound

Practice Makes Unsafe: Skill Misevolution in Self-Improving LLM Agents cites this paper.

Practice Makes Unsafe: Skill Misevolution in Self-Improving LLM Agents AgentSecBench: Measuring Prompt Injection, Privacy Leakage, and Tool-Use Integrity in LLM Agents

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-15T22:04:21.540541Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-15T22:04:21.540541Z digest=sha256:eb92685448f1c8fd03daf5702286fd1cc6c92ba70faced95e8ff746e988042a7