Pith. sign in

Paper Citation Record · LEDGER

Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 22 inbound Pith citation observations for arXiv:2407.20859.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2407.20859 v1

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 22 of 22 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 22 of 22 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.833682Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-19T11:32:17.399819Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 70567d79-fc90-402b-9b4a-faed101ddead · inbound

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems cites this paper.

Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 92

Resolution
verified exact
arxiv_id, observed 2026-05-15T19:32:19.842883Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-15T19:32:19.405615Z digest=sha256:3ff44888afa4b5776b31b2b6d2780d032ca8c887ce17ae8f4557f01a1c96e63e

Observation 27868dea-37aa-466f-a614-86f0fb11dd28 · inbound

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents cites this paper.

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-14T01:35:51.157627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-14T01:35:50.992477Z digest=sha256:630775b6c78aba0c057744be548d81298b6c3d8535e1d50188f928c8cc1902fe

Observation 75e283ae-38ba-4953-92f4-67cd737699ad · inbound

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks cites this paper.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.833682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.833682Z digest=sha256:9a838d5753435208f9b4ce3867d59c488242f842d91d963f53ba13af231d6dc3

Observation af22e5bb-013d-460b-bc09-2dcc13193c75 · inbound

AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents cites this paper.

AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:24:32.653182Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-14T21:24:32.615129Z digest=sha256:3e277c708f09c25eb913cbf32f3baf23e6de0a88b0c250ed82e8286c402afeab

Observation c50de765-5309-4a6b-8205-e12fb77fb6e4 · inbound

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI cites this paper.

Vibe Coding vs. Agentic Coding: Fundamentals and Practical Implications of Agentic AI Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 180

Resolution
unresolved
no resolver link, observed 2026-08-07T14:15:48.765487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:15:48.765487Z digest=sha256:d1b169bdeb7f1c1821b4b84c7936dfdad087b685511e4f7ffea23e367cfca91b

Observation cc26684a-32d6-4848-8283-16a8a2deb2ae · inbound

Exploring Consciousness in LLMs: A Systematic Survey of Theories, Implementations, and Frontier Risks cites this paper.

Exploring Consciousness in LLMs: A Systematic Survey of Theories, Implementations, and Frontier Risks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T14:09:51.938976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:09:51.938976Z digest=sha256:615445820128ee151875d575dfdd783c78a7ef8416abd6b027acb814b1c9221b

Observation 739051ed-4776-46f1-ae67-d86a2954aa29 · inbound

MermaidFlow: Redefining Agentic Workflow Generation via Safety-Constrained Evolutionary Programming cites this paper.

MermaidFlow: Redefining Agentic Workflow Generation via Safety-Constrained Evolutionary Programming Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T13:00:09.290039Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:00:09.290039Z digest=sha256:12150294309a54d316ee0958f68c8a8a1140d3e24dfbcf522d5ca7286df5ec89

Observation e2be02a1-f2f4-4f0b-9fdf-db486a9d0823 · inbound

When GPT Spills the Tea: Comprehensive Assessment of Knowledge File Leakage in GPTs cites this paper.

When GPT Spills the Tea: Comprehensive Assessment of Knowledge File Leakage in GPTs Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T12:14:28.219807Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:14:28.219807Z digest=sha256:851fa50c7ee293d36c12753d797e22c24c9c124703b4dccf3f6e92dd3ba17d26

Observation 4bc17a46-d09e-42ef-a4c5-2982947c98c6 · inbound

To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems cites this paper.

To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-19T11:32:17.403211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-19T11:30:47.877793Z digest=sha256:5a3d7ca1b23d7e4f35d1dd37391c7f9849f86064aa7dfc7dbbb82a4f8317acab

Observation 5d661501-7bea-4e38-8ac4-eefd7427adba · inbound

Misalignment or misuse? The AGI alignment tradeoff cites this paper.

Misalignment or misuse? The AGI alignment tradeoff Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 104

Resolution
unresolved
no resolver link, observed 2026-08-07T11:00:30.044332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:00:30.044332Z digest=sha256:4f91c7c88a19ad9c20b84129b73a052cf0104d271354e9a8e541229a61096639

Observation 4063b574-a780-46db-9b09-9c93bf741cc7 · inbound

AgentMisalignment: Measuring the Propensity for Misaligned Behaviour in LLM-Based Agents cites this paper.

AgentMisalignment: Measuring the Propensity for Misaligned Behaviour in LLM-Based Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T10:54:58.042421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T10:54:58.042421Z digest=sha256:361a9b59e41fd511cad817dd533897a232973b58d025ba9a2199e21a30da4c6b

Observation 618e3f50-7bab-4b7b-b2ce-45a9ff0281b3 · inbound

Oversight Structures for Agentic AI in Public-Sector Organizations cites this paper.

Oversight Structures for Agentic AI in Public-Sector Organizations Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T10:35:52.641114Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T10:35:52.641114Z digest=sha256:772aea6a51445deccb28572de367a13f224398e1a72d9e19bebdcc53886bd042

Observation f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3 · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.737890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.737890Z digest=sha256:8dc7d975cdca75435c824b78c3a3287aa6a9802b35f531eaccb17a0deb8ce2f6

Observation 38da46af-33d6-4c90-9f1c-191963725db3 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:40.846006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:40.846006Z digest=sha256:1b22e4950c79b30aef8ec4dcb41b53e97d5b25f50476765270a183ce51ae989d

Observation 86350cec-1f15-431b-8e67-fda1be52837f · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 156

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:46.996573Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:46.996573Z digest=sha256:d006276761ffafe2cecb46c2769d59be896abd772e7624a7efe274313282d132

Observation a8258143-3763-4f6f-a648-1c37df5f0ba3 · inbound

Free-MAD: Consensus-Free Multi-Agent Debate cites this paper.

Free-MAD: Consensus-Free Multi-Agent Debate Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T17:15:01.750168Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T17:15:01.750168Z digest=sha256:d67b7e237a25a9873bf8b18634c57391dc15cbc103aa3d8128557d7aa8141fd9

Observation 6235fe9d-4c70-442a-a49b-4f8aac21bf5c · inbound

Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence cites this paper.

Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-04T14:42:51.152563Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T14:42:51.152563Z digest=sha256:24213b033d6380cbfc8e631a0e9356b89affd6c5f0cbb95ae196dcca1c3f8bb1

Observation 5398029e-fde9-42d1-bbc1-d7858ae7264f · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.436204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:cec35adf25beda7743aabe87cc27d1c2a20e3e2e6b564fc034bb130b6ab5aeda

Observation 00c339ae-648a-41f4-b060-8eb944fbb130 · inbound

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models cites this paper.

Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 27

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T00:29:47.748410Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T00:02:35.167281Z digest=sha256:0bf7ec48710b4a390c479577a136bf5d663e9d3d36b1f250d1af205eca3525e1

Observation 042a5f95-437d-4c84-a286-a8309732ced0 · inbound

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework cites this paper.

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 112

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:51:09.070148Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T07:53:13.746141Z digest=sha256:7290db640335f9a003424b071d98acefff2f307274f537e1b7e8c1b931306f63

Observation 0c171232-24de-4559-b3d3-322879d57af4 · inbound

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios cites this paper.

Enhancing Agent Safety Judgment: Controlled Benchmark Rewriting and Analogical Reasoning for Deceptive Out-of-Distribution Scenarios Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-11T23:31:13.133715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-07T16:57:28.155229Z digest=sha256:12446058c0de7748d7b51c4df601b7ed99d31efe5bf70d48543c53d1b1ab2548

Observation 5c8ccc6b-5e33-40ad-82af-f054abba4f2d · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 271

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.616748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.616748Z digest=sha256:ca04c94e2579498ba86af47dd9cf1e2059240bd9a84a166070321449d7ea77fa