{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:GKZNGXLX5QJLN6FL5H77PXWDXJ","short_pith_number":"pith:GKZNGXLX","schema_version":"1.0","canonical_sha256":"32b2d35d77ec12b6f8abe9fff7dec3ba7e1244f2c8cc55ea907b725f5ad8d31d","source":{"kind":"arxiv","id":"2407.12784","version":1},"attestation_state":"computed","paper":{"title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.IR"],"primary_cat":"cs.LG","authors_text":"Bo Li, Chaowei Xiao, Dawn Song, Zhaorun Chen, Zhen Xiang","submitted_at":"2024-07-17T17:59:47Z","abstract_excerpt":"LLM agents have demonstrated remarkable performance across various applications, primarily due to their advanced capabilities in reasoning, utilizing external knowledge and tools, calling APIs, and executing actions to interact with environments. Current agents typically utilize a memory module or a retrieval-augmented generation (RAG) mechanism, retrieving past knowledge and instances with similar embeddings from knowledge bases to inform task planning and execution. However, the reliance on unverified knowledge bases raises significant concerns about their safety and trustworthiness. To unco"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.12784","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-07-17T17:59:47Z","cross_cats_sorted":["cs.CR","cs.IR"],"title_canon_sha256":"db8808231dbe592493cc959aa1b6b5ce98470ddc5e22ac9448293491adc9aea7","abstract_canon_sha256":"a721306d4c6b659ec2ce11dfffe49bb6fe9fe66bed5bd6833c27665183bf0e74"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:45:10.243299Z","signature_b64":"9Zdi1cZ4BJOj0peM94b34zA53JIyq7r8iEobTkKOmQVwQ4u2CtLSTODeJbJOHjMbYpuicI8l1UFagkz0MXSmDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"32b2d35d77ec12b6f8abe9fff7dec3ba7e1244f2c8cc55ea907b725f5ad8d31d","last_reissued_at":"2026-07-05T08:45:10.242835Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:45:10.242835Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.IR"],"primary_cat":"cs.LG","authors_text":"Bo Li, Chaowei Xiao, Dawn Song, Zhaorun Chen, Zhen Xiang","submitted_at":"2024-07-17T17:59:47Z","abstract_excerpt":"LLM agents have demonstrated remarkable performance across various applications, primarily due to their advanced capabilities in reasoning, utilizing external knowledge and tools, calling APIs, and executing actions to interact with environments. Current agents typically utilize a memory module or a retrieval-augmented generation (RAG) mechanism, retrieving past knowledge and instances with similar embeddings from knowledge bases to inform task planning and execution. However, the reliance on unverified knowledge bases raises significant concerns about their safety and trustworthiness. To unco"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.12784","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.12784/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.12784","created_at":"2026-07-05T08:45:10.242890+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.12784v1","created_at":"2026-07-05T08:45:10.242890+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.12784","created_at":"2026-07-05T08:45:10.242890+00:00"},{"alias_kind":"pith_short_12","alias_value":"GKZNGXLX5QJL","created_at":"2026-07-05T08:45:10.242890+00:00"},{"alias_kind":"pith_short_16","alias_value":"GKZNGXLX5QJLN6FL","created_at":"2026-07-05T08:45:10.242890+00:00"},{"alias_kind":"pith_short_8","alias_value":"GKZNGXLX","created_at":"2026-07-05T08:45:10.242890+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":32,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08032","citing_title":"What to Keep, What to Forget: A Rate--Distortion View of Memory Compaction in LLMs and Agents","ref_index":18,"is_internal_anchor":true},{"citing_arxiv_id":"2606.24322","citing_title":"Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12703","citing_title":"SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12290","citing_title":"Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09038","citing_title":"Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2606.07805","citing_title":"Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30306","citing_title":"Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23951","citing_title":"Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30602","citing_title":"MESA: Prioritizing Vulnerable Communication Channels for Securing Multi-Agent Systems","ref_index":37,"is_internal_anchor":false},{"citing_arxiv_id":"2605.27825","citing_title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2605.31042","citing_title":"From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22643","citing_title":"Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22643","citing_title":"Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16282","citing_title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18133","citing_title":"An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":88,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.14421","citing_title":"MemLineage: Lineage-Guided Enforcement for LLM Agent Memory","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2410.09024","citing_title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2410.02644","citing_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","ref_index":91,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03482","citing_title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03242","citing_title":"Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios","ref_index":31,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ","json":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ.json","graph_json":"https://pith.science/api/pith-number/GKZNGXLX5QJLN6FL5H77PXWDXJ/graph.json","events_json":"https://pith.science/api/pith-number/GKZNGXLX5QJLN6FL5H77PXWDXJ/events.json","paper":"https://pith.science/paper/GKZNGXLX"},"agent_actions":{"view_html":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ","download_json":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ.json","view_paper":"https://pith.science/paper/GKZNGXLX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.12784&json=true","fetch_graph":"https://pith.science/api/pith-number/GKZNGXLX5QJLN6FL5H77PXWDXJ/graph.json","fetch_events":"https://pith.science/api/pith-number/GKZNGXLX5QJLN6FL5H77PXWDXJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ/action/storage_attestation","attest_author":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ/action/author_attestation","sign_citation":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ/action/citation_signature","submit_replication":"https://pith.science/pith/GKZNGXLX5QJLN6FL5H77PXWDXJ/action/replication_record"}},"created_at":"2026-07-05T08:45:10.242890+00:00","updated_at":"2026-07-05T08:45:10.242890+00:00"}