Pith. sign in

Paper Citation Record · LEDGER

LLM Agents Should Employ Security Principles

As of 20 August 2026, this Paper Citation Record lists 90 of 90 outbound references and 19 inbound Pith citation observations for arXiv:2505.24019.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.24019 v1

Coverage vector

measured 90 of 90 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T12:42:18.393562Z

measured 109 of 109 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 19 of 19 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T14:21:42.738610Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

90 of 90 outbound references displayed

  • verified exact0
  • verified fuzzy23
  • unresolved67
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bd985b7c-b0df-459b-8000-298db5310957 · outbound

This paper cites Firewalls to Secure Dynamic LLM Agentic Networks.

LLM Agents Should Employ Security Principles Firewalls to Secure Dynamic LLM Agentic Networks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.530457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.530457Z digest=sha256:ff960a044e4db6778067ce0fd806b00dbddae77aa776bbf7f3baffc06c166e26

Observation d5d6c0d8-f456-42ec-a9f2-834243d80537 · outbound

This paper cites Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press.

LLM Agents Should Employ Security Principles Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.608335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.608335Z digest=sha256:7e02b29a6e4eee8fc0239807fb39f3cf03cdd0c5760a49157167643fab5ce396

Observation cdec2bb5-bbf7-450e-a9ff-048260c07d27 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

LLM Agents Should Employ Security Principles Detecting Language Model Attacks with Perplexity

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.698195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.698195Z digest=sha256:c25ed143a2c421aed649697ce3f80ea845198e0d200866225fa7941731e4e40f

Observation d05109fa-289d-4952-ad75-ecd264b038e0 · outbound

This paper cites Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/.

LLM Agents Should Employ Security Principles Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.809393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.809393Z digest=sha256:8194fc0344a5aa398d3ec65522a1abe69e90e3dc1e2e5d28f0d818e260709c37

Observation 089e5c0d-478b-43ef-bfa3-b3b54410e83b · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

LLM Agents Should Employ Security Principles AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.942106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.942106Z digest=sha256:0906d9c034ee62b6cf412a9e7ba112df0c1113560b9575006ff7bc08bafd913b

Observation dd089303-22eb-46fd-9132-1b9724232760 · outbound

This paper cites Monitoring computer use via hierarchical summarization.

LLM Agents Should Employ Security Principles Monitoring computer use via hierarchical summarization

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.032707Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.032707Z digest=sha256:9f2a7f15552f84193591ebee69a6be628f41f282f8fe01fef3c93b489278d6d5

Observation 9ff1aaba-0123-4546-9680-1d68c64f885f · outbound

This paper cites Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol.

LLM Agents Should Employ Security Principles Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.133502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.133502Z digest=sha256:1d66eb958acf0f787c60d43f2b46b8f5e9e38425f6b151aefb58f9d1c245c974

Observation be791b63-2bd7-4f41-afd4-8331c45673cb · outbound

This paper cites https://github.com/microsoft/autogen/.

LLM Agents Should Employ Security Principles https://github.com/microsoft/autogen/

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.217203Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.217203Z digest=sha256:380534f699bcad0cc4e7630e626fadddc094b9fc0737f554c2875d18f1ce52c2

Observation d65cd2b0-10c3-4be9-bb2e-824e744adbb6 · outbound

This paper cites AirGapAgent: Protecting privacy-conscious conversational agents.

LLM Agents Should Employ Security Principles AirGapAgent: Protecting privacy-conscious conversational agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.321358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.321358Z digest=sha256:afd7017c818781d7914c489444463d4b72a60da34718ba2709e072d74627b891

Observation d64ee457-9957-4055-8516-91b05dfbe8bd · outbound

This paper cites International AI Safety Report.

LLM Agents Should Employ Security Principles International AI Safety Report

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.396694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.396694Z digest=sha256:5b364ab34ac3ef624955ffac3a2ecbdf315ae03bc062c12f860acbf60a61f7ab

Observation dbcb2b21-ad46-4d62-a163-76dcfe37b233 · outbound

This paper cites Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment.

LLM Agents Should Employ Security Principles Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.476447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.476447Z digest=sha256:e67148591e6dbf5cda0841926ea4942c4a179899872997b6e61c4cb6e3edda84

Observation bd117973-b3e8-4121-a09d-423378211520 · outbound

This paper cites Computer Security: Art and Science.

LLM Agents Should Employ Security Principles Computer Security: Art and Science

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.571062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.571062Z digest=sha256:f2c6570e7a8f9a806715eba1d180e1beedd9e57c409606df920aede30c02404a

Observation 8d9940fd-8a91-4caa-9895-691e6f6f76d3 · outbound

This paper cites Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020.

LLM Agents Should Employ Security Principles Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.674312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.674312Z digest=sha256:7f0559a494d8a9f05250b9de13a22b2ce9117b7de3baba331b3119e63f3e4324

Observation d347328e-ca07-425f-b855-b3af2492b132 · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

LLM Agents Should Employ Security Principles Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.749191Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.749191Z digest=sha256:a7c64238ffa80d8e7cf5a277207bf764dd4a1979f63f379c9afe67ada058c646

Observation 867af2a8-de4d-4a33-8869-65aa2047e972 · outbound

This paper cites Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

LLM Agents Should Employ Security Principles Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.823955Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.823955Z digest=sha256:cc6b7f538945d2c6dfc6a82cc8d59e7fc87bcd653d0c8918b8af9b4e32c983ed

Observation 596ee284-0ea0-4129-8f46-0a457afe19d0 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

LLM Agents Should Employ Security Principles LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.956892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.956892Z digest=sha256:ac1284257eb5ec872433d0c97f2e5504a83a24b71e8e299d9baedc41708ca357

Observation 2892f98d-6ca6-4c1c-a487-fc9581d063d9 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

LLM Agents Should Employ Security Principles Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.078265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.078265Z digest=sha256:da398ea4aa34ff649adc2a6c91b5aa598254e9a5010ff8a8da3a179476bd7c3d

Observation 4fcb89fa-0184-401d-bb07-7ef9b69a6a92 · outbound

This paper cites LLMs for Customer Service and Support.

LLM Agents Should Employ Security Principles LLMs for Customer Service and Support

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.185759Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.185759Z digest=sha256:887aa086e943f1c6a6d940b69a89f3aad88be975eaea8d77406c8d902d1dd85e

Observation ceb442c8-68b9-40a3-8631-22abaefc089f · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

LLM Agents Should Employ Security Principles AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.263611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.263611Z digest=sha256:67c25b3827b99dd806c50cc710c7d9442775fccdf1eab1b33cf591a6dbc8a546

Observation 25525d58-b3c5-4ba9-805e-03c7bf4cf5dc · outbound

This paper cites A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025.

LLM Agents Should Employ Security Principles A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.351103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.351103Z digest=sha256:93075b0e737b5f09d5a7b5c59535f9a7f49544e507816b12a002d7e90d54322c

Observation daed623c-b688-44db-a438-1e84c1d74c33 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

LLM Agents Should Employ Security Principles LLM Agents can Autonomously Hack Websites

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.460789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.460789Z digest=sha256:8c9664f65558be81198e3bd4366ce784bab2469780bc02f5f3c7e07af358c561

Observation b98b3fef-4049-4ffc-ac4c-0154f96d31d3 · outbound

This paper cites Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms.

LLM Agents Should Employ Security Principles Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.991712Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:12.564782Z digest=sha256:ec801d852a3fedd81d184e0e98beac96489dcae6d93f07ec65f9efb1308754ea

Observation 59849ad6-626a-4837-baa2-6e83386a7dcd · outbound

This paper cites Announcing the Agent2Agent Protocol (A2A), 2025.

LLM Agents Should Employ Security Principles Announcing the Agent2Agent Protocol (A2A), 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.889907Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:12.637148Z digest=sha256:87096f66969e442d39ea91876a3c364737e7f2e151f5a55957b5acde226056fe

Observation eef13c70-b45a-442e-ae02-560f42321cae · outbound

This paper cites Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024.

LLM Agents Should Employ Security Principles Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.790524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:12.733210Z digest=sha256:26b1325baa73d37a884917b47886444d8f82c4df37eedd623c3531a1018a7c76

Observation 96993d6c-dce1-4cbf-b163-c9a0afd3c2b9 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

LLM Agents Should Employ Security Principles Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.836704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.836704Z digest=sha256:4d680c17fb45e684847c457df0dd0f35699e67d4e40b05874ca71408895270d2

Observation 83cb01ea-f7e7-4ada-a985-5faed646f991 · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

LLM Agents Should Employ Security Principles TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.942186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.942186Z digest=sha256:747cf70bc7e242fcfc122567d2b87780784e1721287257d089f1c922cdeb3c4e

Observation 1c1f3d12-d2ea-4e88-a032-f246d074d031 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

LLM Agents Should Employ Security Principles Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.041837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.041837Z digest=sha256:d58c11b3c1a5bd5f90055420d7d077776bd0c539718c1c1a93a9db402ac99c67

Observation e070e8a2-7038-46cc-8d1e-ec256ef640c2 · outbound

This paper cites DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines.

LLM Agents Should Employ Security Principles DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.159532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.159532Z digest=sha256:a2622e22d39bb3748a11415bf04499764ef8cd6134687286ac556349fee73c5b

Observation 30dc0c33-a749-4094-8680-eaa2a1479476 · outbound

This paper cites https://github.com/langchain-ai/langchain.

LLM Agents Should Employ Security Principles https://github.com/langchain-ai/langchain

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.630328Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:13.243542Z digest=sha256:d7503e1d2bcf866ec3e281a1240697fa00d3f9b4c0bc558c79a9aebc8f5e2e5f

Observation 03efd940-4c6a-4584-833c-436b070c380c · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

LLM Agents Should Employ Security Principles Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.333338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.333338Z digest=sha256:1e9764996d9257e61390fa8df20f835897544a97745f266174a4b3fd270a30b3

Observation 9961eabc-da01-4075-8d8c-7ca6e07d3d7a · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

LLM Agents Should Employ Security Principles DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.406934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.406934Z digest=sha256:b942274398c349f074857530a71ca95dac60ee9134e0e0b99e6a019eb31610ac

Observation 9efe313b-f1dc-4273-a168-662a114e3017 · outbound

This paper cites RAIN: Your language models can align themselves without finetuning.

LLM Agents Should Employ Security Principles RAIN: Your language models can align themselves without finetuning

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.448589Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:13.445643Z digest=sha256:17d4945aeacc807e5f6ac4af8d3010aac9a2041491eb5a2cafc936e4cba70979

Observation ef746f30-99ce-46c0-b78d-883f9882a0a9 · outbound

This paper cites Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025.

LLM Agents Should Employ Security Principles Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.310516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:13.503135Z digest=sha256:8a8e8162fbc9e8e552ec2e841453a04fb57fcb9191da6130de1825c7f7b4673e

Observation c56f5cee-ca82-4ebd-9976-a68fe5bcdde3 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

LLM Agents Should Employ Security Principles AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.581416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.581416Z digest=sha256:4e1a8bfae19d1bfea07d12d57ba92f2d13363f1b635660c6d177a5d13b42a57d

Observation 4ba3acef-79e5-48ee-86b5-c7196eac569b · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

LLM Agents Should Employ Security Principles Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.656779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.656779Z digest=sha256:22666775818e6a898f759f0c29022c55bcb21bd7f410b7eafdde283b0dca84a8

Observation 94717349-e1fe-4ad4-a098-bb4a1eefcca5 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

LLM Agents Should Employ Security Principles Prompt Injection attack against LLM-integrated Applications

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.736788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.736788Z digest=sha256:aae86b4a5ab6865a583d7debd64f76098f35804298d6c767dfb6a09c92bd6b99

Observation 4076bcf0-2259-46ef-b7b3-4336c42dee73 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

LLM Agents Should Employ Security Principles Formalizing and benchmarking prompt injection attacks and defenses

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.810103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.810103Z digest=sha256:fd74cbad7a2dae855547da91f828f3d77a55f704893f6f97bd5924099282ebe7

Observation 63ce2e3b-8681-4ef4-932a-ae59ee8ac81d · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024.

LLM Agents Should Employ Security Principles Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.058794Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:13.859636Z digest=sha256:3308ed6f3ec7402bf5f27e20c405fe20fb725063d304cfbf9cbe609913a0dca2

Observation 58de7286-4c36-43da-907b-85ec38fcfd78 · outbound

This paper cites Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data.

LLM Agents Should Employ Security Principles Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.926146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:13.934623Z digest=sha256:8bd6a624f616ced7d1dff91d1c20c4f48075782debd658c5fa575fc2bac25683

Observation 01f8cddd-f5a4-45f6-9135-eaae55082fa6 · outbound

This paper cites GPT-4 technical report, 2023.

LLM Agents Should Employ Security Principles GPT-4 technical report, 2023

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.016657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.016657Z digest=sha256:fdeeac45b22c901e6279b4f82174974b4c93820c07f965c56eab0faf7a2c1b4f

Observation b3203619-4d85-4a8c-ab2a-f8420dd879cf · outbound

This paper cites Optimizing instructions and demonstrations for multi-stage language model programs.

LLM Agents Should Employ Security Principles Optimizing instructions and demonstrations for multi-stage language model programs

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.731074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.102885Z digest=sha256:a29ae162aba1ef4c5c20a448eb74008aa943400237de1f289236aabe23f4ef22

Observation b6d67e25-53c6-461b-aa1d-e997e1b703d6 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

LLM Agents Should Employ Security Principles Ignore Previous Prompt: Attack Techniques For Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.183326Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.183326Z digest=sha256:c2ad800a59512bba9b7c91cc589a83389cce1ccdd6077e5b98b91745541dd393

Observation 8526a788-4653-4897-8018-f8bda732c331 · outbound

This paper cites The sandwich defense, 2024.

LLM Agents Should Employ Security Principles The sandwich defense, 2024

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.609888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.231663Z digest=sha256:ff7d74f31a8c562b0caa90c23ae690e2fee72785623980feb9e22bd34f448bc0

Observation 6a19f497-1e9f-4732-8da4-fc51e0ab031d · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

LLM Agents Should Employ Security Principles Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.391206Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.309044Z digest=sha256:32aa7c96d42dd9cd98c2a8d74475936bd58b1b5041444b861a0acaa878f14a73

Observation 39a7815c-9f5a-4977-b7ee-6fcf06d14461 · outbound

This paper cites Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024.

LLM Agents Should Employ Security Principles Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.349072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.349072Z digest=sha256:8ba6a6b3940d1a9fc0a7f27186f68d344c099e6812d2a55577537e7891a7ae14

Observation cf62a05f-e636-4597-af89-a63000ad4fd1 · outbound

This paper cites Improving language understanding by generative pre-training.

LLM Agents Should Employ Security Principles Improving language understanding by generative pre-training

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.458743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.458743Z digest=sha256:018886bf506fc31d021a6585b342cabfdd90c0fe2f63d435d1212d77f786430b

Observation b095827c-cbd0-499c-9369-795dbcd17625 · outbound

This paper cites Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019.

LLM Agents Should Employ Security Principles Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.067470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.532396Z digest=sha256:c5de3e32d351adce8ad633cc41c4fda2350e15da5ba95a9fac8653317dd69451

Observation e92c744a-dbb5-4a26-ab6a-45083317a23a · outbound

This paper cites Identifying the risks of lm agents with an lm-emulated sandbox.

LLM Agents Should Employ Security Principles Identifying the risks of lm agents with an lm-emulated sandbox

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.597041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.597041Z digest=sha256:9d57e739c67d504983e09ffb644d0da93fc4bf990588cbe13b147fe11dd44177

Observation 5ea5a6d0-fd10-4acd-97a8-9e32e13e4d39 · outbound

This paper cites Saltzer and Michael D.

LLM Agents Should Employ Security Principles Saltzer and Michael D

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.926538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.704723Z digest=sha256:54c23afe6f3e6bf435bfaac43cc96c3b9299451aeec11d11beefaba400bd0cb2

Observation 12f99703-4403-4662-8a8c-f52513336761 · outbound

This paper cites Scalable and transferable black-box jailbreaks for language models via persona modulation.

LLM Agents Should Employ Security Principles Scalable and transferable black-box jailbreaks for language models via persona modulation

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.847173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.809955Z digest=sha256:4b7caea12b8f10b17253c7b6073c48420ee37234e98cc359265c376580ac54b0

Observation 2c2bde08-6264-4a0e-8f08-47e16c10a20c · outbound

This paper cites PrivacyLens: Evaluating privacy norm awareness of language models in action.

LLM Agents Should Employ Security Principles PrivacyLens: Evaluating privacy norm awareness of language models in action

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.711449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:14.862141Z digest=sha256:268cb2cb89b2cac835b9df676dce344cb831a8473457876eb99393687b08c903

Observation ed2e0c91-b822-4f97-aeaf-90334fe082a8 · outbound

This paper cites Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024.

LLM Agents Should Employ Security Principles Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.965587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.965587Z digest=sha256:d066d3f2496a1499cc68f5eab3d4df94d7e2195589cf869bbc4c385c6eff1f51

Observation 490b3d32-0aaf-4692-91a5-47f4cf418e97 · outbound

This paper cites "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.

LLM Agents Should Employ Security Principles "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.041346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.041346Z digest=sha256:ff23e4576319d5030b3e1d2125d06926b8ee193bb59e1af43c4e699e4324d8f0

Observation 7913acda-421d-4cda-b47a-e7e91e03b39d · outbound

This paper cites Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn.

LLM Agents Should Employ Security Principles Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.568018Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:15.133715Z digest=sha256:b3d5991bc785d55fe53fbae659f32ec338b7dd26de236a46dcdf17c432ebb357

Observation 62a2d446-309d-4e3a-bdec-858410c0b0e0 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

LLM Agents Should Employ Security Principles Progent: Securing AI Agents with Privilege Control

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.258181Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.258181Z digest=sha256:7b364856132240e955a9ffb285c4df9f3025b6723174ab7f48ebd7f99a062a29

Observation 66496283-4700-425d-8a6a-d96b84f88a3d · outbound

This paper cites Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles.

LLM Agents Should Employ Security Principles Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.340645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.340645Z digest=sha256:839cac724eab9ade61bf83d3a293f95d74d323dfb24701beca4e61005f983ab6

Observation 7e370c83-7e1d-49cb-bf5a-fd9b142233aa · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

LLM Agents Should Employ Security Principles LLaMA: Open and Efficient Foundation Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.374992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.374992Z digest=sha256:da368b67c92cc8cc5d0d89eb7a90d6d5545b2abad8cd62d67ac334da8030013d

Observation 49bcb3ce-1f1a-4aa2-b8ed-f22c0a351464 · outbound

This paper cites Contextual Agent Security: A Policy for Every Purpose.

LLM Agents Should Employ Security Principles Contextual Agent Security: A Policy for Every Purpose

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.456892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.456892Z digest=sha256:722710a3d22d60c6f5bbf4bd09ba7c2b826b6ff78fb243a217939d3fb90dd8a8

Observation ccc84b4b-c405-43f6-a854-5b58edeb97bc · outbound

This paper cites Unveiling Privacy Risks in LLM Agent Memory.

LLM Agents Should Employ Security Principles Unveiling Privacy Risks in LLM Agent Memory

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.532647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.532647Z digest=sha256:c39bcd066cf3cfcb54cfcb58b6b4c91efedb3eaaca36df4bcdf90ecf36902554

Observation b2416549-9e07-4fe0-a7c2-c50da359fe7e · outbound

This paper cites Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models.

LLM Agents Should Employ Security Principles Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.631370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.631370Z digest=sha256:c4061761fa96aff7e3cc3b2939ef2e7496dd7bf4bcccc62c9f70659ffeb2b568

Observation 6e96c548-5365-4c4e-a1c9-ae934e9cf4fd · outbound

This paper cites Jailbroken: How does LLM safety training fail? InNeurIPS, 2023.

LLM Agents Should Employ Security Principles Jailbroken: How does LLM safety training fail? InNeurIPS, 2023

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.471413Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:15.706109Z digest=sha256:305a7da6bc409100917e081f63c4814453dda66d9ec88773bd5721f649169883

Observation 002ddea9-086d-45ec-b623-7ae8f92a9849 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

LLM Agents Should Employ Security Principles IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.770833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.770833Z digest=sha256:d4e7c3ea094778088e5f3c142f87a2529684c6ae820fe6edbb954447abc77712

Observation 501d3fa2-9165-4f6f-9a3a-612981623685 · outbound

This paper cites Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023.

LLM Agents Should Employ Security Principles Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.297070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:15.848097Z digest=sha256:802d31a645b963743255e5f6fc2a031e4d4d59d98f7e97de9df173adc69956fc

Observation 33867e88-cbca-4552-8a3e-9e4b7474d0df · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024.

LLM Agents Should Employ Security Principles Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.919093Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.919093Z digest=sha256:847c5d15e26f1c2182ce986aadef77876613de88053e285c794becacd368bdb6

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:7a5ecfd427c99de0df78b9894ce24c4702af58dd97f67b0c763d333711793363

Observation ba5b2bdf-6dcb-42ea-9e6d-51a56a1db8fc · outbound

This paper cites GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts.

LLM Agents Should Employ Security Principles GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.057577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.057577Z digest=sha256:9e0b9740f884261885ade7c406cc6942c03e0048dd60e3e2ccac4ce3ec2570d3

Observation a35ad4c9-6bde-41a7-aa1a-c4a918fbf45e · outbound

This paper cites LLM-Fuzzer: Scaling assessment of large language model jailbreaks.

LLM Agents Should Employ Security Principles LLM-Fuzzer: Scaling assessment of large language model jailbreaks

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.038320Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:16.121597Z digest=sha256:2a0545a9cc3dc2b12c39873ee1e8da90661e23ce9e3ed35aeb345f7623c46b25

Observation 9ecd6738-1a77-4f90-b57a-10e3daf71070 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 68

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.780421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:16.201346Z digest=sha256:9ecaeb0be203e70ebba5f720aa71f06e4c980413e307303ee4163860b7f6f51e

Observation 8971b96f-62de-484e-9f31-5cfc8ebf7e08 · outbound

This paper cites R-Judge: Benchmarking Safety Risk Awareness for LLM Agents.

LLM Agents Should Employ Security Principles R-Judge: Benchmarking Safety Risk Awareness for LLM Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.267748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.267748Z digest=sha256:0e7a86422ea8e2cafb15b76068cbb43ffd8addb48ee80042fedaad88b9bc41a5

Observation b55ef027-4d4d-46ce-81ce-066aa0603d52 · outbound

This paper cites GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher.

LLM Agents Should Employ Security Principles GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.601536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:16.345626Z digest=sha256:ef7bb23aac3bd11ac81f75cec8cac9258328515c038372c1e9126d0b2415e44e

Observation 5dc51e68-0ae0-474a-82ae-456547c0ebde · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

LLM Agents Should Employ Security Principles InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.461006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.461006Z digest=sha256:56f2de2b0f25d8b602079a8098a2be3c98647ad9ea3ce0c9f3bd54b63c9ec1e9

Observation 8ac99a43-caa9-4b74-a84e-8675f8bc3679 · outbound

This paper cites Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y.

LLM Agents Should Employ Security Principles Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.440904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:16.557915Z digest=sha256:aec606999ae596ab5aa5bd29655b9ab4fb997519636988290edee1ec21e1a605

Observation 4adf505c-776b-47ab-bae3-822d609394ca · outbound

This paper cites Goal-guided Generative Prompt Injection Attack on Large Language Models.

LLM Agents Should Employ Security Principles Goal-guided Generative Prompt Injection Attack on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.635079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.635079Z digest=sha256:097e0d3c29707b27cf15094c28cf5bd15c9bdb2dadc7ea605c30185885f70c5a

Observation b10c2da8-b53b-4941-aedf-cac699e19392 · outbound

This paper cites Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents.

LLM Agents Should Employ Security Principles Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.322556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:16.733672Z digest=sha256:681fabdcc72d7821f0dfe0f6b1c84c387218ef71c96f7132570f9cf004d81c8b

Observation 6bd88959-2a42-4211-9da3-316e90d52851 · outbound

This paper cites Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction.

LLM Agents Should Employ Security Principles Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.802912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.802912Z digest=sha256:6e12d533dc706638ac99e19afc43af6b5c88a62df5c4fc093700cc1f6374f34e

Observation 9c4055af-829d-4ce2-946d-b7ff3dcb3103 · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

LLM Agents Should Employ Security Principles Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.878014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.878014Z digest=sha256:2d274432159c9109befad1d74ac0ef01f3f6dd34f3c575589b11685bb873f4d7

Observation b4aec45b-fb05-4462-b4da-1ef170ba4aa4 · outbound

This paper cites Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025.

LLM Agents Should Employ Security Principles Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.979796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.979796Z digest=sha256:25f72cf08a98447a040ae37c37836ff236b91fe8688f38a2bf31530d7254c771

Observation 4755f0c4-0df9-493b-bc87-041b609ba668 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

LLM Agents Should Employ Security Principles RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.059726Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.059726Z digest=sha256:c18c4f0caa34333095b57108c6b1ba42a549f02395868a133d886bdb87577012

Observation f9c6f5a0-b45e-4e3f-b09c-c24ef5337624 · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

LLM Agents Should Employ Security Principles WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.145765Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.145765Z digest=sha256:b7db1227988ecdbc5cfbfed4db5e8b37d4b1c1a41bff9ac3281830452bb64c3d

Observation 4e6c1294-ed3f-4e98-9bd1-d33b70975e5f · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

LLM Agents Should Employ Security Principles Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.234871Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.234871Z digest=sha256:21dbaab43d98fc4b622f7355b58e854fe2f5696dfc4337ecb89c8812fcd62d86

Observation af664236-e50d-4876-a479-04426623bb7f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 81

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.222084Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:17.371158Z digest=sha256:f7a61b98acef3d8c0100c02cff70bfdfca0ff2d4c5601d2fb694955aa016c260

Observation d893c327-457a-43bb-a07b-23da90095d20 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 82

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.117728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:17.414088Z digest=sha256:50397b8c5ab0102f04fd86f9a4eda99da99f18d59b218a715ab5f904def82fd0

Observation 6d981ffe-26a1-4e16-a9c6-f9bd07cd4b93 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 83

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.981233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:17.513349Z digest=sha256:8ad04c4ceaa4e2067bcfe8840e1599fb22b96d1e35830c05f2c2d85d5b6b845e

Observation 068bf66b-2211-4c74-a8f3-0b52c326865f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 84

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.877047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:17.692770Z digest=sha256:2a871ecea39ba3ca4e9171b76a5811d154aba865f2d4d08afff5c7db23b39d07

Observation d0b69c9e-f71d-4e53-8e62-b9548e2a0acd · outbound

This paper cites Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning.

LLM Agents Should Employ Security Principles Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:21.708644Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:17.877754Z digest=sha256:261097c6ec71f8dbd59b998c3ed32c8ecedfc2cf870aab2285dd005cd6bce587

Observation 3379054e-420d-48f9-b4ee-1498a4230ae7 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 86

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.492939Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:18.044792Z digest=sha256:0514535a89c3efae900c3b4eaaf7feac7c9967b46c94aeac823b9824c24ecea4

Observation fabc4ed9-d310-4eb0-a9bc-e162304cd1c5 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 87

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.276654Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:18.209326Z digest=sha256:c70e8bd04c8d09faad24dbedb8aa779c504dfa8653c425091987c98fdb6b4845

Observation a23379ba-d10b-4a84-8488-6a14c06a5562 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 88

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.946610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:18.275656Z digest=sha256:c6a0009152da95bf12996a327cf167191a10f6382cc8811f881c655450c08e82

Observation 3bd0b09a-4f36-4946-aad4-d0ec73c114de · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 89

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.646846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:18.334643Z digest=sha256:7b7280d127c31128c2b9c17cd34259e2feedc3f4b341e1729bf262771248a699

Observation 3586a497-e439-41c5-bcb5-2bfc07e1b6ca · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 90

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.381960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-07T12:42:18.393562Z digest=sha256:634f4942ee2a6ebd50a0ee21023d3cd0b453ff6bf32593ecdfbb31472520a0a8

Pith citing papers

Observation 16f8fd0f-70db-4624-818d-15468c6f285e · inbound

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks cites this paper.

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks LLM Agents Should Employ Security Principles

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T04:33:17.074410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:33:17.074410Z digest=sha256:776c3370bd3e6ff86037ba0e87c184ad7b7466cd8b1898b21104d300430e6748

Observation ac2932f3-7626-4f90-8d04-0933120e2807 · inbound

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance cites this paper.

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance LLM Agents Should Employ Security Principles

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T21:22:59.187197Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:22:59.187197Z digest=sha256:54aed7aceb42f90ac504c98d28207f08f9a0bacc7fba98923335321919b32068

Observation 7c43d2ea-12ac-4812-93c2-e9bc600e31ab · inbound

Security Considerations for Artificial Intelligence Agents cites this paper.

Security Considerations for Artificial Intelligence Agents LLM Agents Should Employ Security Principles

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-15T12:40:00.295146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-15T12:37:27.153365Z digest=sha256:7e4a829fbcdf7f319773c3dfa5f71b22946331bc35ce60d6f5e2b08ce326fd4d

Observation 10df942f-6b11-48c7-a27b-d46eaacc960b · inbound

Parallax: Why AI Agents That Think Must Never Act cites this paper.

Parallax: Why AI Agents That Think Must Never Act LLM Agents Should Employ Security Principles

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:01:04.817173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T15:13:07.178551Z digest=sha256:0bf9e7e93b8e95c6e8d4a469f4780f4b792c52031642311f636b35617453955e

Observation a4819020-cad8-41ab-9560-085e22e71429 · inbound

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents cites this paper.

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents LLM Agents Should Employ Security Principles

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:01:14.315710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-09T18:56:12.400565Z digest=sha256:5d293b346257f30f3eab0ac2f59307dc60a298c4693ece93d494b1cd177f0710

Observation e4e679a8-f1a2-420d-a7ab-a670893e7829 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:46:31.792945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-07T02:12:30.086152Z digest=sha256:aeaace2cccd28884251044d23236fa76b65cff13ec9d30b7fd1d8f1a8be95539

Observation cb51a1bf-cc9b-4d9b-b170-fe13e60abd32 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:55:44.451126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-08T17:56:09.884837Z digest=sha256:1d88b6ad9b4daa2ccf966f81ecdf41ac6af5452f6397925edb5e93bbaebf6fd9

Observation e4d2c026-00c6-45b8-b140-e16f5678ab00 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks LLM Agents Should Employ Security Principles

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.084545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:04183b6771405cac0ca4d49a789a371966fe477e2f19230882a5f4ae4dd41937

Observation 65f35965-3cb2-4e70-9c1f-4339f87c9b74 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:28:00.169507Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-14T21:23:48.061702Z digest=sha256:db8c5d689fe813766947101e7dcc9ba32c02106ca58ed4bee85c68d6d0669891

Observation f948f307-afc6-420e-b662-4c12c1ff14cc · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-20T23:29:12.644850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-20T23:28:47.424991Z digest=sha256:b60a2101bb38abd4fefe2a039a5b3e70dd5bbf62d7651c0c2f17197caceff03c

Observation 0d2ef391-5e3f-409c-b30e-6059138001f7 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-03T00:07:27.596565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-07-02T23:59:14.667099Z digest=sha256:3889eeae7d92a06e7fe02708dbf72194ef0344dad07518f926ea456170c9b747

Observation 7c7b7853-fdc2-4fea-8023-43dc2990d156 · inbound

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI cites this paper.

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI LLM Agents Should Employ Security Principles

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-02T03:26:29.052170Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T10:04:44.962968Z digest=sha256:ff52f594fc85315f58b0695d78e0bf5f19add78b8d50b758537a1d1b84d67f62

Observation 71e6500c-65af-4abf-8e9d-d28e894d7da6 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation LLM Agents Should Employ Security Principles

Reference 244

Resolution
verified exact
arxiv_id, observed 2026-06-27T13:20:57.050204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:63424404e365b83ed9022d7ce631c9eabfea37aafeca4593ec0b04ac68a4c36f

Observation 90a16c7c-2cd5-4ae4-86c9-ef72ddf6ee7f · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-07-04T18:00:00.381118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-25T23:17:58.968269Z digest=sha256:47415c6e76f7e21028444c7398609f9364f696dfb701258c0e5eefa1c1310cb8

Observation 32bf28b6-f117-4c6b-8aa9-951c366ffe89 · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-12T12:34:58.460933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T12:34:58.460933Z digest=sha256:de6ceb1fd140ec3d850d6c894a3035b0f9232e2a82e10911bd72c8c3ea64521a

Observation c8d7d5bb-4367-4626-a82c-7e3f4a68c151 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents LLM Agents Should Employ Security Principles

Reference 44

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T13:39:51.356324Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:55b2f49a3df59090a122118e3760cc88454574531c22142978762c3beffe579c

Observation 58d014e1-8893-40b7-9413-4900eec7ff11 · inbound

Safeguarding LLM Agents from Misalignment through Provenance Analysis cites this paper.

Safeguarding LLM Agents from Misalignment through Provenance Analysis LLM Agents Should Employ Security Principles

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-07-04T01:29:22.001648Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-07-04T01:26:25.858521Z digest=sha256:215fdf67eb0e93f13053d97a695027c81f75aa39fa16d1cf707e36dfc8a7f905

Observation 2cc1333c-e2fb-42b6-9c5b-f243dd227d9f · inbound

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents cites this paper.

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents LLM Agents Should Employ Security Principles

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T13:11:53.371921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:11:53.371921Z digest=sha256:0a88dc5b43a25a371111aef483647b2aeb14fbac8d8b8431663a319c19d3e59d

Observation f6617bf0-6581-4e63-883a-c305c2d3f1b8 · inbound

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models cites this paper.

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models LLM Agents Should Employ Security Principles

Reference 159

Resolution
unresolved
no resolver link, observed 2026-08-15T14:21:42.738610Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T14:21:42.738610Z digest=sha256:d234ae91904ee759eec5c3b1bfd1725a057f7c24a5bf6ca65b166d0eebbf6bc5