Pith. sign in

Paper Citation Record · LEDGER

Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

As of 10 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 56 inbound Pith citation observations for arXiv:2312.14197.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2312.14197 v4

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 56 of 56 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 56 of 56 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-08T20:57:43.602204Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

9
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 97817b41-db3e-41fd-8e9d-f58974c5f7ff · inbound

Defending Against Indirect Prompt Injection Attacks With Spotlighting cites this paper.

Defending Against Indirect Prompt Injection Attacks With Spotlighting Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-14T22:28:55.424003Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-14T22:28:55.370749Z digest=sha256:1020218388c19623404517984bf302831176f9d536f9a651b0c95e45df4c9160

Observation 634df275-c0b3-42b6-993e-17572a6d9b11 · inbound

LLM Agents can Autonomously Exploit One-day Vulnerabilities cites this paper.

LLM Agents can Autonomously Exploit One-day Vulnerabilities Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-18T04:18:27.662132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-18T04:18:27.597704Z digest=sha256:01389634c2ff307b4753fb24b0f02e53d4add437be08e42fb06b5552b383b909

Observation 196cfb2e-0fa5-4054-b31e-bfa081355095 · inbound

The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions cites this paper.

The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:59:30.797232Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-12T10:59:30.728091Z digest=sha256:41de5eda4e84a741c03498a0d57614364c92ac2506997e09a521ab18eae49d5d

Observation d352e1af-4809-454a-9774-144f23f1472d · inbound

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents cites this paper.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.402235Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:58edc9dac727c616efd2dcd5c376b9ace31a752f664fd4e107ad9c1a1518b070

Observation 8e27a0e4-8b48-4c9a-999d-38612545cce3 · inbound

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents cites this paper.

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 157

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.224615Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-12T13:36:57.011451Z digest=sha256:9eaa6048dac891b9ea367208a01f44659df77f5511a758d4df0a12d74d232091

Observation 8bcc4d61-5791-4f0f-9293-c6aa22d3d377 · inbound

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search cites this paper.

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-08T20:57:43.602204Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T20:57:43.602204Z digest=sha256:ee537ad8bab56987709ce83845b9c084721db00cb3f038ad3445a0e7967fb323

Observation 41a497e6-9ae9-4b69-bfe5-5cc3204fd3a7 · inbound

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety cites this paper.

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 140

Resolution
verified exact
arxiv_id, observed 2026-05-23T04:42:34.016624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-23T04:39:04.591722Z digest=sha256:597d0d1106c3d1369485aefacbe2dffccf4c0901cf58a028c40a4f70f9d02574

Observation 1bec698a-1e6d-4541-b8ff-39f77ebb7b5b · inbound

IHEval: Evaluating Language Models on Following the Instruction Hierarchy cites this paper.

IHEval: Evaluating Language Models on Following the Instruction Hierarchy Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T23:56:00.128652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T23:56:00.128652Z digest=sha256:3619191f6e085ab30af93270103761296731a7426d21d451b3df433876721c3a

Observation 6c012428-57fa-4c01-9a96-0fe31bc4bc35 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 45

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.044991Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:05d801af327a5118f2e2e6d9065d2d8e9f262b37c1753ae1c93cebc533b9896f

Observation a00eec65-66f6-4758-a934-70a4f8216626 · inbound

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks cites this paper.

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T15:41:24.481852Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:41:24.481852Z digest=sha256:a190ca414ff764c72b99328d7f9bb6d9cf4da021fc7ad774a1b69043d66917b5

Observation ed10cf18-6a79-4b5b-bef3-d9087450a1c8 · inbound

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains cites this paper.

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T15:14:46.395816Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:14:46.395816Z digest=sha256:5ede886c80e02e77b5c293f20a4dec3076e88b9f6294173112fd05753f179beb

Observation 3f184b0b-621e-427d-97b3-bcef0124352b · inbound

Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models cites this paper.

Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T14:55:02.679214Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T14:55:02.679214Z digest=sha256:632ce789339e9a6d94b0d728d5a8ebe65a55bb7559cc0a823a46ab19114289c7

Observation f8bffdc9-cb67-4366-8440-8cd448565bba · inbound

A Critical Evaluation of Defenses against Prompt Injection Attacks cites this paper.

A Critical Evaluation of Defenses against Prompt Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T14:36:12.693088Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:36:12.693088Z digest=sha256:10f2dcc23cdcf7710d4ec907707d8cfc2d17bcf80b4502a0e2d1e09a713463ed

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · inbound

LLM Agents Should Employ Security Principles cites this paper.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:123e05aeec13f18c2afefe71b4d883a6f0986461eec5342acfe58e98b7203fed

Observation b0693264-866e-4e60-9f8e-589c4dda26a7 · inbound

JavelinGuard: Low-Cost Transformer Architectures for LLM Security cites this paper.

JavelinGuard: Low-Cost Transformer Architectures for LLM Security Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T05:41:25.529733Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T05:41:25.529733Z digest=sha256:cf568ecdc06361a1225d3e3601382441f4f37de78870910dfbdc73ec4fd7a105

Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · inbound

Context manipulation attacks : Web agents are susceptible to corrupted memory cites this paper.

Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.158675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.158675Z digest=sha256:49c288289c291af2a712cf601db2a38bf6c84b4df574972d9cbbee12fca0eb63

Observation 089d26cc-1fdc-429c-99e4-2da7b551d9a5 · inbound

BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services cites this paper.

BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T22:40:38.187097Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T22:40:38.187097Z digest=sha256:c3c317fc19057dc1384a9d3d1c0b39354fce25294eac52fdcc228a3f740fc610

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · inbound

Prompt Injection 2.0: Hybrid AI Threats cites this paper.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:7a772ed46e896130c9b3fa17cb7f6a458db0e76dd62cf64a6321cc3ca18c5af8

Observation 176dae2d-28d1-42fe-8986-b5645525b5c9 · inbound

WebGuard: Building a Generalizable Guardrail for Web Agents cites this paper.

WebGuard: Building a Generalizable Guardrail for Web Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-06T16:12:51.333428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:12:51.333428Z digest=sha256:22b86b0314e03aa5998f39d744c798b5e799ef6300deca69d9ed3c5ed72e18a9

Observation 1bc81062-1a6c-4fe0-9237-9da26b29fbe2 · inbound

Lexical Hints of Accuracy in LLM Reasoning Chains cites this paper.

Lexical Hints of Accuracy in LLM Reasoning Chains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T18:48:50.863975Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:48:50.863975Z digest=sha256:21041c893ec4cc7dcae425c1bc78975724bb2d205d9be0d60825214f4f667743

Observation f3cba737-1295-4552-94ac-1eadc91f1413 · inbound

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior cites this paper.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.954752Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.954752Z digest=sha256:3730749143aaa41dc2974ac56b2e151701af3d37b131c8a62208713916d0f1e6

Observation 538c7225-0d0a-4c6b-ac48-d2634878d9c3 · inbound

When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift cites this paper.

When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T23:22:38.844788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T23:22:38.844788Z digest=sha256:c02062cfbfc04dd9d580f69f2c3bd85f7462ca100db87b44c278a6cd62bd44a5

Observation 35a8932a-22a3-494c-81c9-d86984fec96d · inbound

Many-Tier Instruction Hierarchy in LLM Agents cites this paper.

Many-Tier Instruction Hierarchy in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T07:16:01.976213Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-10T17:15:10.392678Z digest=sha256:4e36e8c5bb4e23c053d94899d9a695583fcf5fa54daa0d5e87fe58e40fdc588f

Observation 21110f35-c167-4750-b0ab-02728ebe78ad · inbound

An AI Agent Execution Environment to Safeguard User Data cites this paper.

An AI Agent Execution Environment to Safeguard User Data Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 82

Resolution
verified exact
arxiv_id, observed 2026-05-11T13:11:05.750535Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-10T02:14:40.639143Z digest=sha256:df6578250fd0b9b6f99a59c4b38b5bd06d51daf606fac9018bac875fae87c46b

Observation ddf3556a-3549-46ad-a5f2-bdcf15b60da8 · inbound

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents cites this paper.

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-05-08T22:39:20.577096Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-08T08:08:24.524671Z digest=sha256:a237501d9ee5a6c0cceba6d81ad7ec4dacdb83c3233eb01f1c9adc395468ab2e

Observation 6f2a28f4-9667-48d1-9ac0-280daa79c69f · inbound

Evaluation of Prompt Injection Defenses in Large Language Models cites this paper.

Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-11T21:21:12.079621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-08T05:50:20.608166Z digest=sha256:34b5d0a94fcd28ceaefc8343082310f2055d5208c72bcf9d066073eb02e3d67e

Observation 5cea8fcf-d59d-48f1-89e0-2a4697a3e2a9 · inbound

Evaluation of Prompt Injection Defenses in Large Language Models cites this paper.

Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:19:28.460702Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-14T21:05:23.800356Z digest=sha256:93ba1294aad125a482e37a1a63cbd7b0bd396a61a67986245715c195ad3adfba

Observation 5deca162-d313-4484-9760-fe45fbd8fd38 · inbound

Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills cites this paper.

Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:46:15.850426Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-07T16:22:49.737626Z digest=sha256:33f37a1abcb254e3236baf6521480ac4b35f0d5f446393b6d688686e65bc0764

Observation 4df578a0-c781-4de1-b581-4a218ecc0751 · inbound

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates cites this paper.

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-09T05:55:31.844341Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-08T19:17:06.375875Z digest=sha256:4b9b46b99a795353d3c150357fd6c6e68d0c28c7e8488506f608647c3df92ddf

Observation 5ed01e6b-6fc6-47c6-a027-c680e263f2dc · inbound

MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning cites this paper.

MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T02:30:55.043183Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-11T02:29:13.992357Z digest=sha256:00d16b9d9fdc13aa9bdbfdc49122e865e699710acab8b9ae5c41608f38c906da

Observation 94dece42-48ac-4aa4-9809-3eabdf2dff25 · inbound

Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture cites this paper.

Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-12T07:56:31.056812Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-12T01:28:08.332456Z digest=sha256:056ea0c93ea0815cc4fa7d2e5f671741cc9f4a120b3158412faef1f8676b5c3c

Observation 9ecdb9c3-bf96-487c-82c8-3cb9a3d65a2a · inbound

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection cites this paper.

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-13T05:47:21.316847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-13T05:46:07.132408Z digest=sha256:f7b261ad6cfa9967f639aa964793654e1aec854d1e30ee84847e2a21997484d9

Observation d7ea9cee-c29a-424c-a1fc-95159a7899e7 · inbound

Web Agents Should Adopt the Plan-Then-Execute Paradigm cites this paper.

Web Agents Should Adopt the Plan-Then-Execute Paradigm Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:49:41.559958Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-15T02:42:05.644536Z digest=sha256:83ae30d71ffd04b75a3c7530bdca6c52dc044f8e1f8b29eea39cb41138f98a08

Observation 6d920e85-e211-42f2-9b1c-b84621608982 · inbound

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments cites this paper.

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:58:10.879410Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-20T09:58:05.349147Z digest=sha256:2d217517004f47221045e4a24dd443b8b217cc262aa7b65864be768f26f34a70

Observation 96d1112b-1e1f-4495-906d-adc3117086d0 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-20T09:48:11.595740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-20T09:46:42.413501Z digest=sha256:0781ca7d66597223ca6322c05b3d55a684a3e1d5f0ab286b0b8754da33b792e2

Observation 9ba8124f-19fb-4857-8068-ac007779b074 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-22T09:01:20.110761Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-22T08:57:29.491043Z digest=sha256:3f9f59b2f8306675227baf91fea8afddfcb3a09a11547f79528eb4505e91c79f

Observation f181d1bb-35c0-4a36-a207-e8d540d349f4 · inbound

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors cites this paper.

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-06-28T22:12:41.463500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-06-28T22:06:41.245543Z digest=sha256:95fe1e77817bc475b116d25cb99101cf0b8167cb04989e416ada18379f2a315b

Observation 555d4ea9-e22d-4319-b0a9-e4c6f1242427 · inbound

Gate AI: LLM Security Benchmark Evaluation Methodology and Results cites this paper.

Gate AI: LLM Security Benchmark Evaluation Methodology and Results Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-01T22:46:19.188961Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-28T15:05:08.411286Z digest=sha256:3e4b8eaf822d59b7bdcee82f7b7b9a96d69800967feb4386f10c2e617f3189b2

Observation 3e4c895e-cfc9-4a55-9b54-7af85df3f8db · inbound

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models cites this paper.

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T03:16:33.675784Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-28T10:13:48.860754Z digest=sha256:e3805e58ca6f0114d7e3a5826f630812348d48776e8cfbad57c07148f7f07e04

Observation 38171ffc-1869-4d10-8738-4d7cc4d694bb · inbound

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents cites this paper.

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-07-02T04:16:36.037768Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-28T09:15:57.044886Z digest=sha256:a28318fdb9c55380ee6c7f6f0ac24ae2d2c9ba9272c2193b0bd7707c2d81af34

Observation b33c16d6-51a3-4269-abf3-cd2c764d9730 · inbound

Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure cites this paper.

Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-07-02T20:47:22.530818Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-27T20:15:56.875933Z digest=sha256:30945f6e8441d48442774e93eb95270ef435b6381e39836c59ab2f0248c5f1d6

Observation 39a76038-c48d-4c09-89e8-23658ccc3593 · inbound

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents cites this paper.

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-07-03T01:47:31.928375Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-06-27T16:15:47.454172Z digest=sha256:dfd683098da7b250cd87430e71f0dcd0323a80bbc1cb433174d6c2c69606437d

Observation a20cd9a1-eef5-4e8f-8222-55fe1691cca6 · inbound

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents cites this paper.

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T04:57:38.192366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-06-27T13:33:24.087333Z digest=sha256:4d9d17dd034145a109366a3f3059473d3c30cef805f921d91965dc6dbe1721ad

Observation 8d9d6654-035b-4a06-81d5-39432b32e719 · inbound

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs cites this paper.

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-07-03T05:47:41.229355Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-27T13:05:57.618969Z digest=sha256:e102336a7138ecbbe29926344ff18f082212b7ab899a1287e05ba2aa584646c2

Observation 317cc991-7106-429f-8973-67bdeb1617af · inbound

PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents cites this paper.

PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T11:07:07.442032Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T11:07:07.442032Z digest=sha256:82115c568b024429c7211d09d4bac79c36a48d6150405f5c38c6ed24cb53d666

Observation 33fe266d-6331-498b-95b6-950f61ab31a0 · inbound

Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks cites this paper.

Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-07-03T22:08:59.310448Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-06-26T23:45:25.770548Z digest=sha256:c7047aafa0433ebf62ee21702f3335a2f8af4b1e9e74a2141e051fc08cba2562

Observation 850b25ab-2f1e-4164-817f-87a33240546e · inbound

A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots cites this paper.

A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-04T02:09:22.497299Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-26T20:00:14.036515Z digest=sha256:18cb8f139e96114686b4ef036b91eb74f0a8345a43dc9da08eabedcd94f3dc9b

Observation c2abf31c-073e-42f1-a60a-a9089c3a6ac8 · inbound

Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift cites this paper.

Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-07-04T09:29:44.070733Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-26T09:55:08.178751Z digest=sha256:874cd0342bf704b9090fa5a119df7d0ec519216396bdf96221d72f4471363b33

Observation a47829da-290b-4947-a457-56cd4adcb915 · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 78

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.893169Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:ec33ba456fb2f02f79fa87797670f4f2c59ec39c679b1f3f20a9bbf121157a04

Observation 882da221-d8ed-4050-bd80-7898a459ec4b · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:70958e64c7c183642d943ad818d492eca1cc81aa9605e5e262095cbb477b9a3c

Observation 322d5c44-c7ab-417d-9221-8c2d96b559fe · inbound

Information Discernment in Large Language Models cites this paper.

Information Discernment in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T13:26:27.643188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:26:27.643188Z digest=sha256:ce3b4ee2f7c928fb6739e4403e5e59cdd962c31ba6aa6d64bf5d5b1da2951227

Observation db4457de-bbd2-4963-a793-ecef3e38fac2 · inbound

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents cites this paper.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.576853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.576853Z digest=sha256:c05cd5493ebcf6c1d21da3030975a7ae1142c85f9bbff8f407f29d40e588a785

Observation 755f590a-9840-4bb8-8040-56b56c73a6aa · inbound

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls cites this paper.

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-03T01:25:30.766287Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T01:25:30.766287Z digest=sha256:752da9a4727dfaec6ddcd704662ebe26aa58939b3e8bfc2b53b84b920f3689e1

Observation 6e8d9b35-c683-43d6-a186-a5732b86ad10 · inbound

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges cites this paper.

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-03T00:55:23.831248Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T00:55:23.831248Z digest=sha256:ccc08ee7267d9f6b7c38266ed3cf7a65869e0863e10c93eaf8a731e8ecaaf463

Observation 4e0f8e47-dc08-487c-af06-d08f1e1e2669 · inbound

MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication cites this paper.

MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T22:13:21.497262Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T22:13:21.497262Z digest=sha256:748dded0fbf9978c161f0cc72f6acbabe04d0002c819bd5718bee2175ce2f098

Observation 6bc4f208-44ae-4ffd-991b-98915cc36574 · inbound

Robust Context-Aware Detection of Malicious Instructions in Text cites this paper.

Robust Context-Aware Detection of Malicious Instructions in Text Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-08T13:19:01.961178Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T13:19:01.961178Z digest=sha256:60c8a54ac9663d2aa7c09ec93f8372376678ff238ba7837dae8679d70541aba0