{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:RBNY55GUDFX6PNLXFXHCD4772Y","short_pith_number":"pith:RBNY55GU","schema_version":"1.0","canonical_sha256":"885b8ef4d4196fe7b5772dce21f3ffd60054789e81936d02ba186ed72df07a7b","source":{"kind":"arxiv","id":"2412.16682","version":1},"attestation_state":"computed","paper":{"title":"The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anna Squicciarini, Feiran Jia, Tong Wu, Xin Qin","submitted_at":"2024-12-21T16:17:48Z","abstract_excerpt":"Large Language Model (LLM) agents are increasingly being deployed as conversational assistants capable of performing complex real-world tasks through tool integration. This enhanced ability to interact with external systems and process various data sources, while powerful, introduces significant security vulnerabilities. In particular, indirect prompt injection attacks pose a critical threat, where malicious instructions embedded within external data sources can manipulate agents to deviate from user intentions. While existing defenses based on rule constraints, source spotlighting, and authen"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2412.16682","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-12-21T16:17:48Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"4ef12c5458911573176347da69b1d60c1823635bedd5248f870c06d48fd29499","abstract_canon_sha256":"460db1b50149a45b45a644dbd206a4c5b8c2aa2dbafe6f39ca08d188039bb907"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:53:11.443824Z","signature_b64":"Kz8nr1W31DrezaISZI6qE+nkSAnNhNq1y7j8NW6yPIQbtTV3yG/eqWWPspwu3VEKW+aVfkNM6sM6O1W7LQ25AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"885b8ef4d4196fe7b5772dce21f3ffd60054789e81936d02ba186ed72df07a7b","last_reissued_at":"2026-07-05T09:53:11.443370Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:53:11.443370Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anna Squicciarini, Feiran Jia, Tong Wu, Xin Qin","submitted_at":"2024-12-21T16:17:48Z","abstract_excerpt":"Large Language Model (LLM) agents are increasingly being deployed as conversational assistants capable of performing complex real-world tasks through tool integration. This enhanced ability to interact with external systems and process various data sources, while powerful, introduces significant security vulnerabilities. In particular, indirect prompt injection attacks pose a critical threat, where malicious instructions embedded within external data sources can manipulate agents to deviate from user intentions. While existing defenses based on rule constraints, source spotlighting, and authen"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.16682","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2412.16682/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2412.16682","created_at":"2026-07-05T09:53:11.443426+00:00"},{"alias_kind":"arxiv_version","alias_value":"2412.16682v1","created_at":"2026-07-05T09:53:11.443426+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.16682","created_at":"2026-07-05T09:53:11.443426+00:00"},{"alias_kind":"pith_short_12","alias_value":"RBNY55GUDFX6","created_at":"2026-07-05T09:53:11.443426+00:00"},{"alias_kind":"pith_short_16","alias_value":"RBNY55GUDFX6PNLX","created_at":"2026-07-05T09:53:11.443426+00:00"},{"alias_kind":"pith_short_8","alias_value":"RBNY55GU","created_at":"2026-07-05T09:53:11.443426+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":8,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.14517","citing_title":"From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10322","citing_title":"Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":209,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":202,"is_internal_anchor":false},{"citing_arxiv_id":"2605.14290","citing_title":"Web Agents Should Adopt the Plan-Then-Execute Paradigm","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12233","citing_title":"No More, No Less: Task Alignment in Terminal Agents","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11026","citing_title":"AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16762","citing_title":"CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution","ref_index":15,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y","json":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y.json","graph_json":"https://pith.science/api/pith-number/RBNY55GUDFX6PNLXFXHCD4772Y/graph.json","events_json":"https://pith.science/api/pith-number/RBNY55GUDFX6PNLXFXHCD4772Y/events.json","paper":"https://pith.science/paper/RBNY55GU"},"agent_actions":{"view_html":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y","download_json":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y.json","view_paper":"https://pith.science/paper/RBNY55GU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2412.16682&json=true","fetch_graph":"https://pith.science/api/pith-number/RBNY55GUDFX6PNLXFXHCD4772Y/graph.json","fetch_events":"https://pith.science/api/pith-number/RBNY55GUDFX6PNLXFXHCD4772Y/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y/action/storage_attestation","attest_author":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y/action/author_attestation","sign_citation":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y/action/citation_signature","submit_replication":"https://pith.science/pith/RBNY55GUDFX6PNLXFXHCD4772Y/action/replication_record"}},"created_at":"2026-07-05T09:53:11.443426+00:00","updated_at":"2026-07-05T09:53:11.443426+00:00"}