{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:EQUXEPUATW242OVT2YZHRWR4PU","short_pith_number":"pith:EQUXEPUA","schema_version":"1.0","canonical_sha256":"2429723e809db5cd3ab3d63278da3c7d23631b14e6dcd8c0664ddb6f5b39171f","source":{"kind":"arxiv","id":"2508.15310","version":1},"attestation_state":"computed","paper":{"title":"IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Chunyi Zhou, Hengyu An, Jinghuai Zhang, Qingming Li, Shouling Ji, Tao Lin, Tianyu Du","submitted_at":"2025-08-21T07:08:16Z","abstract_excerpt":"Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks. However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool responses may contain injected instructions that covertly influence agent behaviors and lead to malicious outcomes, a threat referred to as Indirect Prompt Injection (IPI). Existing defenses typically rely on advanced prompting strategies or auxiliary detection models. While these methods have demonstrated some effective"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.15310","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-08-21T07:08:16Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"caa8645de6b6cadcdc5d2b075825a49d5193dd515939a1b588ea4efa677fa3a7","abstract_canon_sha256":"190cb0d90f4d7f7e8098f0a6e25a0a63ff4650ee756a7f917ed37108d63162d8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:57:09.998410Z","signature_b64":"lm9Rt9+ZUhCrD+7CejHnYhqu5ZkaRGJ3E/zG8g2Igkz3nD8C2WIRG+sKYP+c25IP4Kp5INNeqWP6gkXpCQlcAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2429723e809db5cd3ab3d63278da3c7d23631b14e6dcd8c0664ddb6f5b39171f","last_reissued_at":"2026-07-05T11:57:09.997969Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:57:09.997969Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Chunyi Zhou, Hengyu An, Jinghuai Zhang, Qingming Li, Shouling Ji, Tao Lin, Tianyu Du","submitted_at":"2025-08-21T07:08:16Z","abstract_excerpt":"Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks. However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool responses may contain injected instructions that covertly influence agent behaviors and lead to malicious outcomes, a threat referred to as Indirect Prompt Injection (IPI). Existing defenses typically rely on advanced prompting strategies or auxiliary detection models. While these methods have demonstrated some effective"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.15310","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.15310/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.15310","created_at":"2026-07-05T11:57:09.998025+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.15310v1","created_at":"2026-07-05T11:57:09.998025+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.15310","created_at":"2026-07-05T11:57:09.998025+00:00"},{"alias_kind":"pith_short_12","alias_value":"EQUXEPUATW24","created_at":"2026-07-05T11:57:09.998025+00:00"},{"alias_kind":"pith_short_16","alias_value":"EQUXEPUATW242OVT","created_at":"2026-07-05T11:57:09.998025+00:00"},{"alias_kind":"pith_short_8","alias_value":"EQUXEPUA","created_at":"2026-07-05T11:57:09.998025+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.14290","citing_title":"Web Agents Should Adopt the Plan-Then-Execute Paradigm","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2604.25109","citing_title":"Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16543","citing_title":"Conjunctive Prompt Attacks in Multi-Agent LLM Systems","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16762","citing_title":"CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.17562","citing_title":"SafeAgent: A Runtime Protection Architecture for Agentic Systems","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU","json":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU.json","graph_json":"https://pith.science/api/pith-number/EQUXEPUATW242OVT2YZHRWR4PU/graph.json","events_json":"https://pith.science/api/pith-number/EQUXEPUATW242OVT2YZHRWR4PU/events.json","paper":"https://pith.science/paper/EQUXEPUA"},"agent_actions":{"view_html":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU","download_json":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU.json","view_paper":"https://pith.science/paper/EQUXEPUA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.15310&json=true","fetch_graph":"https://pith.science/api/pith-number/EQUXEPUATW242OVT2YZHRWR4PU/graph.json","fetch_events":"https://pith.science/api/pith-number/EQUXEPUATW242OVT2YZHRWR4PU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU/action/storage_attestation","attest_author":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU/action/author_attestation","sign_citation":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU/action/citation_signature","submit_replication":"https://pith.science/pith/EQUXEPUATW242OVT2YZHRWR4PU/action/replication_record"}},"created_at":"2026-07-05T11:57:09.998025+00:00","updated_at":"2026-07-05T11:57:09.998025+00:00"}