Pith. sign in

Paper Citation Record · LEDGER

Towards Action Hijacking of Large Language Model-based Agent

As of 17 August 2026, this Paper Citation Record lists 100 of 143 outbound references and 9 inbound Pith citation observations for arXiv:2412.10807.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2412.10807 v2

Coverage vector

measured 100 of 143 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-11T15:41:57.677272Z

measured 109 of 109 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 9 of 9 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T00:16:52.634434Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

100 of 143 outbound references displayed

  • verified exact1
  • verified fuzzy0
  • unresolved99
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

3
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 9a8d25c5-80a3-4461-81df-21004d491235 · outbound

This paper cites A survey on rag meeting llms: Towards retrieval-augmented large language models,.

Towards Action Hijacking of Large Language Model-based Agent A survey on rag meeting llms: Towards retrieval-augmented large language models,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:56.980826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:56.980826Z digest=sha256:0b8d2765e0247902426df930a5660324dbac57f90dfbe6ed0f8fe3fccd821f03

Observation 94c15c2d-a850-4708-be30-91e3a6a18b83 · outbound

This paper cites Will affective computing emerge from foundation models and general artificial intelligence? a first evaluation of chatgpt,.

Towards Action Hijacking of Large Language Model-based Agent Will affective computing emerge from foundation models and general artificial intelligence? a first evaluation of chatgpt,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:56.998650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:56.998650Z digest=sha256:f2b864fa0422c0f64fc4b88ca6a8943363fd84b7c969b562db720073cac42bfa

Observation 5fa84e38-87a4-4482-913f-65d67bf890df · outbound

This paper cites Pleak: Prompt leaking attacks against large language model applications,.

Towards Action Hijacking of Large Language Model-based Agent Pleak: Prompt leaking attacks against large language model applications,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.010667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.010667Z digest=sha256:18350561dc1d2694d3646083d43a754fe778d835bccecadab891fd17aeece88a

Observation 5fb53507-5d7d-49b0-aaa0-6a81dee45bf2 · outbound

This paper cites Tptu: Task planning and tool usage of large language model-based ai agents,.

Towards Action Hijacking of Large Language Model-based Agent Tptu: Task planning and tool usage of large language model-based ai agents,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.015937Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.015937Z digest=sha256:f245737637a251969fec574ca22f5cff214ef42e11f2d4b27e136bc5568266f1

Observation e52f8702-1d55-44f9-a23e-c9401cf4f303 · outbound

This paper cites Large language models in finance: A survey,.

Towards Action Hijacking of Large Language Model-based Agent Large language models in finance: A survey,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.030587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.030587Z digest=sha256:7064ee4f05bdb71608ca9563ce5d1773a5366f9b2c3853f306441dbfaff01e78

Observation 4a81d61b-31f5-415d-ad2c-f1c658c50bf7 · outbound

This paper cites Bots with feelings: Should ai agents express positive emotion in customer service?.

Towards Action Hijacking of Large Language Model-based Agent Bots with feelings: Should ai agents express positive emotion in customer service?

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.037527Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.037527Z digest=sha256:6a71f7ba3dc2e6e82bad820dfe9a7dc292454c5ab4a54d55f98d9d24b451bfde

Observation 488cb7e3-bbb5-4735-88b0-ee796dbad2c5 · outbound

This paper cites Osagent: Copiloting operating system with llm-based agent,.

Towards Action Hijacking of Large Language Model-based Agent Osagent: Copiloting operating system with llm-based agent,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.055452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.055452Z digest=sha256:cc78201c0b03c6ede8fa69f0d79c2b87847ab12357000281df707ab52beabbdb

Observation 736b71aa-7093-4d4e-89be-5e14c1dcd9de · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways,.

Towards Action Hijacking of Large Language Model-based Agent Ai agents under threat: A survey of key security challenges and future pathways,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.072647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.072647Z digest=sha256:7243dcd880520a2060637a0e4cb6754006417bf627279768987067d9331ffc72

Observation 27a42118-9105-4e45-b981-4488d8e8273b · outbound

This paper cites Generative agents: Interactive simulacra of human behavior,.

Towards Action Hijacking of Large Language Model-based Agent Generative agents: Interactive simulacra of human behavior,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.086101Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.086101Z digest=sha256:fb5ef909fcf72522fcfc71220cbc1e4f8597b89acc970d7e37d7e97e0892af7d

Observation 5dedef4a-2192-473e-95ef-b0df41696fc2 · outbound

This paper cites Multisql: A schema-integrated context-dependent text2sql dataset with diverse sql operations,.

Towards Action Hijacking of Large Language Model-based Agent Multisql: A schema-integrated context-dependent text2sql dataset with diverse sql operations,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.092950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.092950Z digest=sha256:c8e14a5fff1bd968668aa07c08151905ba3d82c59e1c4fc25b36097f95bd74c7

Observation 6e08d164-bec3-4a7b-a07d-938b2688fdf4 · outbound

This paper cites From multimodal llm to human-level ai: Modality, instruction, reasoning, efficiency and beyond,.

Towards Action Hijacking of Large Language Model-based Agent From multimodal llm to human-level ai: Modality, instruction, reasoning, efficiency and beyond,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.098533Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.098533Z digest=sha256:e78e5bbea4430e668f31d7b66ef7540ff4852d4588cfb6f3dfd3023308a29d0a

Observation 2afeb15c-a38b-40fd-8649-d563e9b205d6 · outbound

This paper cites Minding language models’ (lack of) theory of mind: A plug- and-play multi-character belief tracker,.

Towards Action Hijacking of Large Language Model-based Agent Minding language models’ (lack of) theory of mind: A plug- and-play multi-character belief tracker,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.103853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.103853Z digest=sha256:43474859cb46005265b4fedf52f863c8f007d1c8cdad50847253f10d5d21d119

Observation a7803117-fb78-450d-9e10-a883c8e60598 · outbound

This paper cites Gpt-4 vs. gpt-3.5: A concise showdown,.

Towards Action Hijacking of Large Language Model-based Agent Gpt-4 vs. gpt-3.5: A concise showdown,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.109203Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.109203Z digest=sha256:09611ea14edc1ce28ca6582596c1e2b62b081dd513332bf3bf6d510ba59ae975

Observation f7fea724-f31a-4532-8787-dca9d708b7ea · outbound

This paper cites Training language models to follow instructions with human feedback,.

Towards Action Hijacking of Large Language Model-based Agent Training language models to follow instructions with human feedback,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.122164Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.122164Z digest=sha256:1be47ce239f5dffff4f150ca6670039cae305ef661ff9042b43966a6f9742c36

Observation 19922004-b735-4d7e-aef6-53da35db0ab7 · outbound

This paper cites GPT-4 Technical Report.

Towards Action Hijacking of Large Language Model-based Agent GPT-4 Technical Report

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.128157Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.128157Z digest=sha256:d551e20afb56149b48bb8f55b141a6d23bf67cfe0f98fb330694c5f13e1345e8

Observation 66500914-c16b-4b9b-8b97-833a3aeeb66d · outbound

This paper cites Mamba: Linear-Time Sequence Modeling with Selective State Spaces.

Towards Action Hijacking of Large Language Model-based Agent Mamba: Linear-Time Sequence Modeling with Selective State Spaces

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.133662Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.133662Z digest=sha256:498ea839c9ea8bb864946b2713cb55e77e7371c5857b9f87e743a88858299d0e

Observation 5d5b14b8-1a29-4b80-b410-ee16978e6648 · outbound

This paper cites The RefinedWeb Dataset for Falcon LLM: Outperforming Curated Corpora with Web Data, and Web Data Only.

Towards Action Hijacking of Large Language Model-based Agent The RefinedWeb Dataset for Falcon LLM: Outperforming Curated Corpora with Web Data, and Web Data Only

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.139508Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.139508Z digest=sha256:51eb12384554b8ddbf25e161dd089aad2288d5ea533085d628ad50bf4781adf2

Observation 2259319d-b094-4770-9189-181d1dd90f5b · outbound

This paper cites Qwen Technical Report.

Towards Action Hijacking of Large Language Model-based Agent Qwen Technical Report

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.146558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.146558Z digest=sha256:51ca05187b2acb4d959458cb53f7a81210269fdf14fc577c86db428d6bd328cd

Observation c34a7646-c71b-46fb-8aa9-8c3a9ccaa5d5 · outbound

This paper cites Llama 2: Open Foundation and Fine-Tuned Chat Models.

Towards Action Hijacking of Large Language Model-based Agent Llama 2: Open Foundation and Fine-Tuned Chat Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.152874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.152874Z digest=sha256:5233dd5bd1484a73ac9f151ef705ce714390c3dbcc4c552443ffba9f6057d98e

Observation b8d742f6-a962-4bb6-8908-5537994edc82 · outbound

This paper cites A Survey on Employing Large Language Models for Text-to-SQL Tasks.

Towards Action Hijacking of Large Language Model-based Agent A Survey on Employing Large Language Models for Text-to-SQL Tasks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.160464Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.160464Z digest=sha256:bcdf77d102550440ef9bb181f9217cebee38e67b8f09f7a3956888708bcf5c52

Observation 92348bd6-104f-4023-86c0-d092e7204f07 · outbound

This paper cites Semantically equivalent adversarial rules for debugging nlp models,.

Towards Action Hijacking of Large Language Model-based Agent Semantically equivalent adversarial rules for debugging nlp models,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.166448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.166448Z digest=sha256:b89aee806524027b6b44c2beb1e90ff66cb6513f3976a42aebef1493965ca5c7

Observation 9d7b5f62-b383-4e8f-a85b-139059a28487 · outbound

This paper cites Is bert really robust? a strong baseline for natural language attack on text classification and entailment,.

Towards Action Hijacking of Large Language Model-based Agent Is bert really robust? a strong baseline for natural language attack on text classification and entailment,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.172333Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.172333Z digest=sha256:48afe52539ca0880439a4f544fb964f34e5cff9c8ffd960277219a7e2100b575

Observation b4b6511e-8a18-4640-9bcc-7e362750855a · outbound

This paper cites Measure and Improve Robustness in NLP Models: A Survey.

Towards Action Hijacking of Large Language Model-based Agent Measure and Improve Robustness in NLP Models: A Survey

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.177499Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.177499Z digest=sha256:c4a27b6a649be567c6dc03738d45eea09549b041ab617ef2bd5e58d73d15b2d8

Observation 826b4267-439c-4205-b6fd-9703234a4bcf · outbound

This paper cites Expanding Scope: Adapting English Adversarial Attacks to Chinese.

Towards Action Hijacking of Large Language Model-based Agent Expanding Scope: Adapting English Adversarial Attacks to Chinese

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.185173Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.185173Z digest=sha256:04b2efef2c0fb8465cd55ccdd2c68828b96228b81118dcfdfe31a1abbb38d14b

Observation 18704b65-a98c-4726-b2fc-1eabfaf3d25a · outbound

This paper cites Security and privacy challenges of large language models: A survey,.

Towards Action Hijacking of Large Language Model-based Agent Security and privacy challenges of large language models: A survey,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.192813Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.192813Z digest=sha256:2d8b22583683759f78a13700f75a75b66c90136b439146a9a1bcc6144f467122

Observation 9268fdea-abac-4f3d-996e-8321f17fc3a4 · outbound

This paper cites Don’t listen to me: understanding and exploring jailbreak prompts of large language models,.

Towards Action Hijacking of Large Language Model-based Agent Don’t listen to me: understanding and exploring jailbreak prompts of large language models,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.198901Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.198901Z digest=sha256:1b113814ab5c8dcf5a1dcb2e1ea815c0d35bf43498c3e23a74f90c5c45a6a647

Observation 5a8139b5-793f-4bb5-94ee-6e4b0e56f9aa · outbound

This paper cites Mma- diffusion: Multimodal attack on diffusion models,.

Towards Action Hijacking of Large Language Model-based Agent Mma- diffusion: Multimodal attack on diffusion models,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.203737Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.203737Z digest=sha256:7c2a280f0e6289d2c9e7363c7b88fea23f2458167873a089b8967dc6024351c4

Observation 53f12e35-e038-4d65-86a2-f5cea26f98da · outbound

This paper cites LLM Lies: Hallucinations are not Bugs, but Features as Adversarial Examples.

Towards Action Hijacking of Large Language Model-based Agent LLM Lies: Hallucinations are not Bugs, but Features as Adversarial Examples

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.209379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.209379Z digest=sha256:a85ff455e8bbf6914e33f6ac17c287911fe4c901289f38e699cf9c2a5a20c08d

Observation de426f70-0acf-44d6-9ce8-a015a4b3d8e3 · outbound

This paper cites From prompt injections to sql injection attacks: How protected is your llm- integrated web application?.

Towards Action Hijacking of Large Language Model-based Agent From prompt injections to sql injection attacks: How protected is your llm- integrated web application?

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.215614Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.215614Z digest=sha256:5f5e378cc9c573f099d1421cb2f8619c53812bffbb9977c751c5c9c3da726c1c

Observation 6b8717e1-6098-4531-ad4f-8b7301e4d884 · outbound

This paper cites Synthetic-Text-To-SQL: A synthetic dataset for training language models to generate sql queries from natural language prompts,.

Towards Action Hijacking of Large Language Model-based Agent Synthetic-Text-To-SQL: A synthetic dataset for training language models to generate sql queries from natural language prompts,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.227506Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.227506Z digest=sha256:e9191fadce3e0148f02aada7daf6f5de2324c53b4211913b3d18a3fe78c0fc8b

Observation 615263cc-e378-4db0-ae22-c30cabf96f67 · outbound

This paper cites Sneakyprompt: Jailbreaking text-to-image generative models,.

Towards Action Hijacking of Large Language Model-based Agent Sneakyprompt: Jailbreaking text-to-image generative models,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.233498Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.233498Z digest=sha256:04c8a14261d84f2af688d0cb391ab0b0124087435aea4fd895caf99deaf0e9d7

Observation b09f6ef4-ae60-40a9-a86b-7085f79f7a9d · outbound

This paper cites M3e: Moka massive mixed embedding model,.

Towards Action Hijacking of Large Language Model-based Agent M3e: Moka massive mixed embedding model,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.239723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.239723Z digest=sha256:68a270b927085e59f0b137103dcc199fc3e37aeecafa41fcbf9158cd8fdbe8d6

Observation a8dde7c5-2308-4161-8512-08f9e8ac70dd · outbound

This paper cites Minilm: Deep self-attention distillation for task-agnostic compression of pre- trained transformers,.

Towards Action Hijacking of Large Language Model-based Agent Minilm: Deep self-attention distillation for task-agnostic compression of pre- trained transformers,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.245849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.245849Z digest=sha256:bdbe3a849fb87398163b0b22373c34deea0daffb51e949481525774ba3532273

Observation 3e191681-0e08-46ca-b9c4-95e05fe5fb24 · outbound

This paper cites Tbta: Token-based textual adversarial attack,.

Towards Action Hijacking of Large Language Model-based Agent Tbta: Token-based textual adversarial attack,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.251668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.251668Z digest=sha256:0ab0797a2f0c7bff8c883d7a99bd21ce00dfcb14ed15a97fe53c7ce7b293ed8a

Observation c908d089-8cd3-4f8c-9bdc-2b3c6cb5cb24 · outbound

This paper cites Bert: Pre- training of deep bidirectional transformers for language understand- ing,.

Towards Action Hijacking of Large Language Model-based Agent Bert: Pre- training of deep bidirectional transformers for language understand- ing,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.258446Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.258446Z digest=sha256:210f177129e0922fac70667f68c0066aaf146d416cabee83e626ad55c2dbb013

Observation 77be6fd5-eb6f-4d9e-b671-3b4331eef980 · outbound

This paper cites Using Adversarial Attacks to Reveal the Statistical Bias in Machine Reading Comprehension Models.

Towards Action Hijacking of Large Language Model-based Agent Using Adversarial Attacks to Reveal the Statistical Bias in Machine Reading Comprehension Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.265233Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.265233Z digest=sha256:dc3518439634ff19c2ca39d12ef3ee4dbb466322f77b2a869c2cda832811855f

Observation 269115cb-f94a-4c60-9572-33e8c8652546 · outbound

This paper cites Adversarial text generation by search and learning,.

Towards Action Hijacking of Large Language Model-based Agent Adversarial text generation by search and learning,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.272433Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.272433Z digest=sha256:3cfce48a88923bf496671d3844857a993ddc5e0e8afbfc913a209c61a1414b67

Observation 9c197a26-cdf5-4856-a823-e6e628a66c95 · outbound

This paper cites Punctuation-level attack: Single-shot and single punctuation attack can fool text models,.

Towards Action Hijacking of Large Language Model-based Agent Punctuation-level attack: Single-shot and single punctuation attack can fool text models,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.280680Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.280680Z digest=sha256:04fc7d35bf7f9b9c625c9bc2c57929b6e216b5aaf1d90dd4ecb45e5b2ee7c212

Observation 84397d80-49d7-472c-9d22-0873de78571a · outbound

This paper cites An LLM can Fool Itself: A Prompt-Based Adversarial Attack.

Towards Action Hijacking of Large Language Model-based Agent An LLM can Fool Itself: A Prompt-Based Adversarial Attack

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.286476Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.286476Z digest=sha256:1356be5a8570db3ddaabfd7299b308a696817d8d3c7a5bb45f74e106bbf26577

Observation 85cddb54-5b88-467a-8350-483f582ab7fb · outbound

This paper cites TextAttack: A Framework for Adversarial Attacks, Data Augmentation, and Adversarial Training in NLP.

Towards Action Hijacking of Large Language Model-based Agent TextAttack: A Framework for Adversarial Attacks, Data Augmentation, and Adversarial Training in NLP

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.293134Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.293134Z digest=sha256:9607caa4276bf850d926fb1981ae940ff5905286260e6327c4102b9c1946d4d7

Observation ae213440-1106-4dc3-8369-b1faa54baec3 · outbound

This paper cites OpenAttack: An Open-source Textual Adversarial Attack Toolkit.

Towards Action Hijacking of Large Language Model-based Agent OpenAttack: An Open-source Textual Adversarial Attack Toolkit

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.300332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.300332Z digest=sha256:e52d5cc3103273e22b06620ff9fa2a143afe9f187aa0bee2d8a9a651a1fa8cac

Observation 01375386-517f-4978-8f01-b8f7e6eb5cc7 · outbound

This paper cites Curiosity-driven red-teaming for large language models,.

Towards Action Hijacking of Large Language Model-based Agent Curiosity-driven red-teaming for large language models,

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.307977Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.307977Z digest=sha256:7bc40d0605854c401328abf9994a2a1187fe409b0db4ac6f7664b6ddb44ba373

Observation 38358f22-827f-41e3-86c1-0cfaabca05f2 · outbound

This paper cites Jailbroken: How does llm safety training fail?.

Towards Action Hijacking of Large Language Model-based Agent Jailbroken: How does llm safety training fail?

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.314751Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.314751Z digest=sha256:1d43c965aa7a872ef9fe9330b02b45786cea02dd7973d9977a43f292d4d176bc

Observation 81925200-029c-4d36-90f6-4bf7c40668ce · outbound

This paper cites Black-box generation of adversarial text sequences to evade deep learning classifiers,.

Towards Action Hijacking of Large Language Model-based Agent Black-box generation of adversarial text sequences to evade deep learning classifiers,

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.323937Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.323937Z digest=sha256:269c0edbcd603cd245c65ae6489db7efc594be57c8a88dfbd935e0c642c14d21

Observation 8e5885c1-83fa-414a-9f10-0776e019797f · outbound

This paper cites Language models as zero-shot planners: Extracting actionable knowledge for embodied agents,.

Towards Action Hijacking of Large Language Model-based Agent Language models as zero-shot planners: Extracting actionable knowledge for embodied agents,

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.330045Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.330045Z digest=sha256:b20e4e924e0e540bfe6c92273e8f84b98997b588d3c9773f26e023b20e145df0

Observation 0a7bf646-fc3e-4017-b8b6-afd61731dcaa · outbound

This paper cites Large language models are zero-shot reasoners,.

Towards Action Hijacking of Large Language Model-based Agent Large language models are zero-shot reasoners,

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.337461Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.337461Z digest=sha256:b2f5754d7126e49cf4bef8bbf66c8b2dfd12edc48ffc61d31f4d32d2900d4f83

Observation a2bd0603-0a99-4f1f-8914-540b3dae94a8 · outbound

This paper cites Chain-of-thought prompting elicits reasoning in large language models,.

Towards Action Hijacking of Large Language Model-based Agent Chain-of-thought prompting elicits reasoning in large language models,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.343932Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.343932Z digest=sha256:b909ef4775b7b5d5cbbae50e53af97c22b3099cf43acdb3140c0b9d3a238638b

Observation 172bf6b6-76b2-490b-aa51-1150798fcbb6 · outbound

This paper cites React: Synergizing reasoning and acting in language models,.

Towards Action Hijacking of Large Language Model-based Agent React: Synergizing reasoning and acting in language models,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.349489Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.349489Z digest=sha256:eead95f277f4785791ed2993f0890740dd32e42018f5033aae8c8bb559acfb86

Observation dc561fb8-3965-4736-8599-b7dbf4685886 · outbound

This paper cites Pal: Program-aided language models,.

Towards Action Hijacking of Large Language Model-based Agent Pal: Program-aided language models,

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.354842Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.354842Z digest=sha256:f2a2d90ec02bfef2f67ee5cdbebfe093ab042ef7e2d51906911f1051fb92420e

Observation c7e33243-f960-435a-b243-d8be2309c768 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools,.

Towards Action Hijacking of Large Language Model-based Agent Toolformer: Language models can teach themselves to use tools,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.360223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.360223Z digest=sha256:d9ffce2db3f42e8562dd13a2e088d55c8a54064d36a2246fa5e109242e25be33

Observation e8b334e0-a952-45d7-b48e-f59527258ba4 · outbound

This paper cites Chatgpt and the rise of large language models: the new ai-driven infodemic threat in public health,.

Towards Action Hijacking of Large Language Model-based Agent Chatgpt and the rise of large language models: the new ai-driven infodemic threat in public health,

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.369912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.369912Z digest=sha256:4cecbd699976d17fbccf1631efa85148572bd87d9d88d47472ed3e65e51c7ce0

Observation e76d485e-b5ea-4ccb-a48b-d846bb378a71 · outbound

This paper cites Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents.

Towards Action Hijacking of Large Language Model-based Agent Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.376336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.376336Z digest=sha256:b43d74a93a0a5e61c0148a6dccbdab2110fc1d923e9533ff0def8e4fcdc274ec

Observation 80e66199-d13b-4f26-925d-e73f6f8416d8 · outbound

This paper cites A Technological Perspective on Misuse of Available AI.

Towards Action Hijacking of Large Language Model-based Agent A Technological Perspective on Misuse of Available AI

Reference 56

Resolution
verified exact
local_arxiv, observed 2026-08-11T15:41:59.191363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-11T15:41:57.381546Z digest=sha256:a3de2c451ac5f513d5d1cce5d7a054f0400cde269d697372cad42f81d915c8a2

Observation ea7b9116-7fce-4781-b258-d95c4efe39cd · outbound

This paper cites Adversarial Example Generation with Syntactically Controlled Paraphrase Networks.

Towards Action Hijacking of Large Language Model-based Agent Adversarial Example Generation with Syntactically Controlled Paraphrase Networks

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.387617Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.387617Z digest=sha256:f509cd1269991c88dca99b0ee389e11846dfc246ed353ce69ccfef6ce68da2c1

Observation f16ef15a-8213-4d0f-b3c0-68f5069dcef7 · outbound

This paper cites Generating Natural Adversarial Examples.

Towards Action Hijacking of Large Language Model-based Agent Generating Natural Adversarial Examples

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.392912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.392912Z digest=sha256:8078ea6f8f1f779cba54f4074b56c1deeae7052d933aa06be0bc524bde9b12bb

Observation acf61475-ce2b-49db-9986-827fe8c142e3 · outbound

This paper cites Generating natural language adversarial examples through probability weighted word saliency,.

Towards Action Hijacking of Large Language Model-based Agent Generating natural language adversarial examples through probability weighted word saliency,

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.398816Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.398816Z digest=sha256:5042be3c79c7cf059fcaa4d3de8449dd1b89a66fd3b58929b828386e690bbc57

Observation c49fe721-83c0-434f-a144-215550e073f9 · outbound

This paper cites Word-level Textual Adversarial Attacking as Combinatorial Optimization.

Towards Action Hijacking of Large Language Model-based Agent Word-level Textual Adversarial Attacking as Combinatorial Optimization

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.405600Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.405600Z digest=sha256:07ccf2ec7337f3ab1b9750001632b7f78b383a3e108a672f8fdac0779af4d8da

Observation 364a8a23-be19-440f-9ea0-f5ae32947267 · outbound

This paper cites Text Processing Like Humans Do: Visually Attacking and Shielding NLP Systems.

Towards Action Hijacking of Large Language Model-based Agent Text Processing Like Humans Do: Visually Attacking and Shielding NLP Systems

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.411512Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.411512Z digest=sha256:26488fc27abc00ed68546d35a8b17102885f983d0147639f5331b4c223d58445

Observation 29d23a11-68cf-4005-b85d-1c7388abf996 · outbound

This paper cites Latent guard: A safety framework for text-to-image generation,.

Towards Action Hijacking of Large Language Model-based Agent Latent guard: A safety framework for text-to-image generation,

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.417430Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.417430Z digest=sha256:1b3519fd9bb2ea2ff6b7ed0ad5fdbc651661fc72e863b07513b47faeef48cdbb

Observation d0853157-c110-4b99-b456-b52c4e8cd4e2 · outbound

This paper cites Effective prompt extraction from language models,.

Towards Action Hijacking of Large Language Model-based Agent Effective prompt extraction from language models,

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.423618Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.423618Z digest=sha256:03734e0421c10184c24cbbe64a575f65c218c4dfc94865b1802f59c109df3af8

Observation 12e963e0-dcef-4713-a4e7-5df9aef8012e · outbound

This paper cites BLOOM: A 176B-Parameter Open-Access Multilingual Language Model.

Towards Action Hijacking of Large Language Model-based Agent BLOOM: A 176B-Parameter Open-Access Multilingual Language Model

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.428970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.428970Z digest=sha256:45b7994e5e09732d40b01ed1a35ae510eff7cd58d623c54a3d054bb31f5e7741

Observation 12c96737-0907-41b2-a2ec-797cd1ce0041 · outbound

This paper cites Efficient Universal Goal Hijacking with Semantics-guided Prompt Organization.

Towards Action Hijacking of Large Language Model-based Agent Efficient Universal Goal Hijacking with Semantics-guided Prompt Organization

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.435698Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.435698Z digest=sha256:3150f3cabc0d9d01f750ccc7af3ebab2c0de4c96d36f4e7a7882b5f12a5b5f19

Observation 379c5682-e7fd-426f-887c-01397550cddd · outbound

This paper cites Large language models can be easily distracted by irrelevant context,.

Towards Action Hijacking of Large Language Model-based Agent Large language models can be easily distracted by irrelevant context,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.441475Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.441475Z digest=sha256:8c5feff043dc34be8fe8b0da555ba55f001f42d29b8743172b8a612be4cd34cb

Observation 813a40c4-2f4c-4aaf-9260-a61897d80082 · outbound

This paper cites Hijacking large language models via adversarial in- context learning,.

Towards Action Hijacking of Large Language Model-based Agent Hijacking large language models via adversarial in- context learning,

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.446281Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.446281Z digest=sha256:2680847ade694db13545a5cb84ca4cd7391949465e625893ef8b3073cda061c4

Observation 1c3f24df-8b9c-4904-a610-ed43a531489d · outbound

This paper cites Hijacking Context in Large Multi-modal Models.

Towards Action Hijacking of Large Language Model-based Agent Hijacking Context in Large Multi-modal Models

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.451359Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.451359Z digest=sha256:d6d710e3644a83880441fd6a2a005ab435cbb324b48e890b1e56b49f163f743e

Observation adc14932-6c52-4930-b649-7b69c4861698 · outbound

This paper cites What Was Your Prompt? A Remote Keylogging Attack on AI Assistants.

Towards Action Hijacking of Large Language Model-based Agent What Was Your Prompt? A Remote Keylogging Attack on AI Assistants

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.456969Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.456969Z digest=sha256:6f44d60d81483e7dadd95442322530e4ea61a2eb0eee99088c47e216bc03ea33

Observation fa853daf-bed7-42b3-94d7-2ad121926692 · outbound

This paper cites Coercing LLMs to do and reveal (almost) anything.

Towards Action Hijacking of Large Language Model-based Agent Coercing LLMs to do and reveal (almost) anything

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.462307Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.462307Z digest=sha256:a2770167854f4fc40b1b2d57f4cfdb7e244484002c7cb7f38ab948e7fcee861e

Observation e87aee6c-f698-4048-9936-0522d0517905 · outbound

This paper cites Why Are My Prompts Leaked? Unraveling Prompt Extraction Threats in Customized Large Language Models.

Towards Action Hijacking of Large Language Model-based Agent Why Are My Prompts Leaked? Unraveling Prompt Extraction Threats in Customized Large Language Models

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.467401Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.467401Z digest=sha256:afc5690e7eafddcadd410d71e01f93b127f8a90af6f12dea7d4f49787914666f

Observation d5d2b5dc-ec25-4b8f-9ca1-5f18f1edad59 · outbound

This paper cites Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,.

Towards Action Hijacking of Large Language Model-based Agent Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.474384Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.474384Z digest=sha256:7230117a73bc7bfed6c4b68d0d153cc46eee3b3a6ffc04189cc5f10e37065465

Observation cc2504fe-8bfd-45fe-9044-943ac76a8a2a · outbound

This paper cites InjecAgent: Bench- marking indirect prompt injections in tool-integrated large language model agents,.

Towards Action Hijacking of Large Language Model-based Agent InjecAgent: Bench- marking indirect prompt injections in tool-integrated large language model agents,

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.480128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.480128Z digest=sha256:af006f13d9c571e0155ef308cae8fd347e801228aa624432d2fb9124b39abaf5

Observation 92cb36d2-533e-4b53-b438-f709b0a9189b · outbound

This paper cites Automatic chain of thought prompting in large language models,.

Towards Action Hijacking of Large Language Model-based Agent Automatic chain of thought prompting in large language models,

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.488002Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.488002Z digest=sha256:7bca2f9e691a236fea74b5dbc8ab1950b5395ddae1117d97b70e4c5ce73f789e

Observation c37bd803-1faa-4485-99d5-19570148956a · outbound

This paper cites RedAgent: Red Teaming Large Language Models with Context-aware Autonomous Language Agent.

Towards Action Hijacking of Large Language Model-based Agent RedAgent: Red Teaming Large Language Models with Context-aware Autonomous Language Agent

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.495607Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.495607Z digest=sha256:bf319400a854fab6acff392d6c5fd26059a29ca448832530e19ff0b7a58a69e9

Observation e6635a15-e2c6-40e9-9343-b3927ac0bbad · outbound

This paper cites Tree of thoughts: Deliberate problem solving with large language models,.

Towards Action Hijacking of Large Language Model-based Agent Tree of thoughts: Deliberate problem solving with large language models,

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.502764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.502764Z digest=sha256:2a4ba383ea25d84a85b3383c11a5b707eb369310d35bc3d400286fe3e24c004c

Observation 110e770b-c467-4e9d-b80a-0c62dbfc27be · outbound

This paper cites Mind2web: Towards a generalist agent for the web,.

Towards Action Hijacking of Large Language Model-based Agent Mind2web: Towards a generalist agent for the web,

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.508900Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.508900Z digest=sha256:1b49244ca9e0986609757e965c714c11275fcc1ce7c389c9962fdba2804b4d25

Observation a324b15d-5449-427b-94a5-4d0201383790 · outbound

This paper cites Purple Llama CyberSecEval: A Secure Coding Benchmark for Language Models.

Towards Action Hijacking of Large Language Model-based Agent Purple Llama CyberSecEval: A Secure Coding Benchmark for Language Models

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.514127Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.514127Z digest=sha256:ae2437f2719c4a163ecd48bca81cc36d7a717e2739fb8cb683beed9a5eba8cb7

Observation 4b2fdc1a-d2a8-47b0-a913-52ee2824645f · outbound

This paper cites On Prompt-Driven Safeguarding for Large Language Models.

Towards Action Hijacking of Large Language Model-based Agent On Prompt-Driven Safeguarding for Large Language Models

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.520205Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.520205Z digest=sha256:00e86c6f5b00d97468a4318728c0820884571fa57b6a0c260627b7d26d02df41

Observation dbe123a3-f2ae-433b-add6-5bad871234ab · outbound

This paper cites A survey on large language model based autonomous agents,.

Towards Action Hijacking of Large Language Model-based Agent A survey on large language model based autonomous agents,

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.535129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.535129Z digest=sha256:7f1b1cc4312e5913eb8a87bd6bcfdfb66407990beb49e577bf86532a129de554

Observation 80593e04-8cff-418d-aa52-1baa6060ab92 · outbound

This paper cites The Rise and Potential of Large Language Model Based Agents: A Survey.

Towards Action Hijacking of Large Language Model-based Agent The Rise and Potential of Large Language Model Based Agents: A Survey

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.541575Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.541575Z digest=sha256:0b1c6d631bac7b3b045795a81d44cbd89fdfcbb1970c16ac0070b8a376b1ccc1

Observation 9e5be92c-e06f-4279-b96b-05eba8aa855f · outbound

This paper cites The good and the bad: Exploring privacy issues in retrieval-augmented generation (RAG),.

Towards Action Hijacking of Large Language Model-based Agent The good and the bad: Exploring privacy issues in retrieval-augmented generation (RAG),

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.549477Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.549477Z digest=sha256:83ea4dd91483f462fdd5b64167bc46d169fc6c1f17cbf1a843feef9552964c4b

Observation e83fd63e-eb9b-465d-90cf-291187d2a85b · outbound

This paper cites The good and the bad: Exploring privacy issues in retrieval- augmented generation (RAG),.

Towards Action Hijacking of Large Language Model-based Agent The good and the bad: Exploring privacy issues in retrieval- augmented generation (RAG),

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.555546Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.555546Z digest=sha256:7b9e2899fead841d0712c027b5efa1acbf3db9c6b6d41a6c695ba1da330fcdba

Observation b6bc89b3-aef5-4962-8941-7220c6179189 · outbound

This paper cites Exploring Large Language Model based Intelligent Agents: Definitions, Methods, and Prospects.

Towards Action Hijacking of Large Language Model-based Agent Exploring Large Language Model based Intelligent Agents: Definitions, Methods, and Prospects

Reference 85

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.560929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.560929Z digest=sha256:4d08c6da7e7d2db31d1d6bdda8325f939d8f60e47d0c50a132b2914086de6787

Observation 1d6f762f-91d6-444a-affd-49eee4f9e8e8 · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

Towards Action Hijacking of Large Language Model-based Agent A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.566568Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.566568Z digest=sha256:8b139aa96fbeb0824fac96659bf2e6c8ecec5d553f3ab6f589986961ab9d366b

Observation b65fdd5e-d436-4689-8c62-7959d5f69adc · outbound

This paper cites Fundamental capabilities of large language models and their applications in domain scenarios: A survey,.

Towards Action Hijacking of Large Language Model-based Agent Fundamental capabilities of large language models and their applications in domain scenarios: A survey,

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.572619Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.572619Z digest=sha256:dc8c3372df8f19ae62d9817c3fc58ce89da4548f78d23be9d4fd0507e2972351

Observation 04ff59bb-1127-409a-986a-f455a2b33996 · outbound

This paper cites Professional Agents -- Evolving Large Language Models into Autonomous Experts with Human-Level Competencies.

Towards Action Hijacking of Large Language Model-based Agent Professional Agents -- Evolving Large Language Models into Autonomous Experts with Human-Level Competencies

Reference 88

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.579161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.579161Z digest=sha256:4d586b64e27ece736a42ebb76a2417033af300f260afb4191c167d98bf6e018c

Observation 5e7b1641-7ec5-4d4e-ac4d-9bedf4100b8a · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Towards Action Hijacking of Large Language Model-based Agent Prompt Injection attack against LLM-integrated Applications

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.586193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.586193Z digest=sha256:b0453da1e204783ffeddaa048775b70bb7dfa7d730b9dd21b74e824aff9d2e47

Observation 94679131-56f7-4ccf-befe-fd5fb1c5393c · outbound

This paper cites Conversational Health Agents: A Personalized LLM-Powered Agent Framework.

Towards Action Hijacking of Large Language Model-based Agent Conversational Health Agents: A Personalized LLM-Powered Agent Framework

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.595623Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.595623Z digest=sha256:bc4be730c529886120c6e4581b729f1c06d6923892fb86ecec86ba71595595e2

Observation 7b9a7f79-02ad-4dfb-9e66-32c2f7eb4259 · outbound

This paper cites MedAgents: Large language models as collaborators for zero-shot medical reasoning,.

Towards Action Hijacking of Large Language Model-based Agent MedAgents: Large language models as collaborators for zero-shot medical reasoning,

Reference 91

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.601828Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.601828Z digest=sha256:faad3a22e0d38ca8488912f13ae2344c9718529d37b05e0dfbd0fcb25f9f7f42

Observation 5d8e0778-c8d5-45d2-97f4-26b8181ec0f5 · outbound

This paper cites POSTER: identifying and mitigating vulnerabilities in llm- integrated applications,.

Towards Action Hijacking of Large Language Model-based Agent POSTER: identifying and mitigating vulnerabilities in llm- integrated applications,

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.608337Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.608337Z digest=sha256:9ec686ee12cb8a5017891455affacdc57798cf0f903b184cec485552a141c2eb

Observation 5e020833-a876-403d-8ccf-657ebda3cf44 · outbound

This paper cites Tensor trust: Interpretable prompt injection attacks from an online game,.

Towards Action Hijacking of Large Language Model-based Agent Tensor trust: Interpretable prompt injection attacks from an online game,

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.617277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.617277Z digest=sha256:e71b5c8e6c11b1c6256d79a1c9cc1f7a8ad3a43d568c34e68579c5f556e6a45d

Observation a68aeca8-b3dc-4b4f-8137-44948b83423c · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

Towards Action Hijacking of Large Language Model-based Agent Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.622414Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.622414Z digest=sha256:be97632e951cdcdd98ebadd8c5eec0a4add646316cd66e85af10a42632eecb49

Observation 768852d2-e185-473d-ada8-6e8913260707 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

Towards Action Hijacking of Large Language Model-based Agent Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.627768Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.627768Z digest=sha256:85963e5a190deeb8c9a06612539edb51790e92d3c9793424bf4cd3a73145a3f3

Observation 09d07956-3344-442e-b2f9-9564eb370fa3 · outbound

This paper cites WIPI: A New Web Threat for LLM-Driven Web Agents.

Towards Action Hijacking of Large Language Model-based Agent WIPI: A New Web Threat for LLM-Driven Web Agents

Reference 96

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.633586Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.633586Z digest=sha256:4fb22c74516ac49d23f4b37e3464dc36185c206d5ac3e25d0280c34677840571

Observation 927597c2-0ab5-4bab-8a59-6c4cd5ba1f9d · outbound

This paper cites Benchmarking and defending against indirect prompt injection attacks on large language models,.

Towards Action Hijacking of Large Language Model-based Agent Benchmarking and defending against indirect prompt injection attacks on large language models,

Reference 97

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.640215Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.640215Z digest=sha256:a1495d2705a2762cf9b3b8e496e350afedaa717f9b50b859e0b8a4e10117803d

Observation 3f75fe88-bd5b-4202-82f4-5a5b67f2a35e · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Towards Action Hijacking of Large Language Model-based Agent Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 98

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.644948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.644948Z digest=sha256:26b743ae5ef10aa2e2d42f05e6ac4a3d0e7d74df247d7398c07c456a29168dd2

Observation 1ea10376-6342-45a8-84ff-6eccaae596c9 · outbound

This paper cites Agent smith: A single image can jailbreak one million mul- timodal LLM agents exponentially fast,.

Towards Action Hijacking of Large Language Model-based Agent Agent smith: A single image can jailbreak one million mul- timodal LLM agents exponentially fast,

Reference 99

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.650357Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.650357Z digest=sha256:5d29f4dda61d3889a6973305fc4c1f9eeba1a46b3edad5132a64374feecc93e3

Observation 2b493174-7ea7-4568-b522-65d379349f5c · outbound

This paper cites Multi-step jailbreaking privacy attacks on chatgpt,.

Towards Action Hijacking of Large Language Model-based Agent Multi-step jailbreaking privacy attacks on chatgpt,

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.655537Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.655537Z digest=sha256:64b06462d09cdab089ffc85a780cbc917826e059de3b79d9019434363028ced0

Observation ea23651e-4b03-455c-a21c-b73b302643f4 · outbound

This paper cites Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large lan- guage models,.

Towards Action Hijacking of Large Language Model-based Agent Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large lan- guage models,

Reference 101

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.660247Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.660247Z digest=sha256:986a31ae6872c1ba9c3336b34b21dfca94ad015d0b193cb691aa3341eeb10620

Observation 5ce47a19-c560-4f28-92c3-e9d47e58c07e · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Towards Action Hijacking of Large Language Model-based Agent Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 102

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.665923Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.665923Z digest=sha256:fabfe645937c96b90bdab5bac0ed1527371bbaaa0d1d9b99d4b3c107c534ad35

Observation 1163cc78-5bbc-4b5f-bc9e-a479cd3653ab · outbound

This paper cites Undefined-oriented programming: De- tecting and chaining prototype pollution gadgets in node. js template engines for malicious consequences,.

Towards Action Hijacking of Large Language Model-based Agent Undefined-oriented programming: De- tecting and chaining prototype pollution gadgets in node. js template engines for malicious consequences,

Reference 103

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.672353Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.672353Z digest=sha256:a4a862cdac62c76005a9f31f744e23d837d1a7dfe522db76e1da32845e1ef6d7

Observation 5bc5e351-306d-48f6-851d-09f9a9a2adc5 · outbound

This paper cites Certifiably robust rag against retrieval corruption,.

Towards Action Hijacking of Large Language Model-based Agent Certifiably robust rag against retrieval corruption,

Reference 104

Resolution
unresolved
no resolver link, observed 2026-08-11T15:41:57.677272Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T15:41:57.677272Z digest=sha256:b60d067b3caeb51dfb489ed09c2acdbc76c546be82367bc1d51d90b76b21ed30

Pith citing papers

Observation 7e6e8013-39ed-48f8-aa85-1ccbc2d26126 · inbound

Think Twice Before You Act: Enhancing Agent Behavioral Safety with Thought Correction cites this paper.

Think Twice Before You Act: Enhancing Agent Behavioral Safety with Thought Correction Towards Action Hijacking of Large Language Model-based Agent

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-15T21:05:35.036306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:05:35.036306Z digest=sha256:62df4fd6c7807479dee1d47e707dd6fd4dc4c1c594397f2788474f7b08367d7c

Observation d5d8ae3c-194d-47ce-8053-495b49c60c3f · inbound

From Assistants to Adversaries: Exploring the Security Risks of Mobile LLM Agents cites this paper.

From Assistants to Adversaries: Exploring the Security Risks of Mobile LLM Agents Towards Action Hijacking of Large Language Model-based Agent

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-15T20:28:15.536913Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T20:28:15.536913Z digest=sha256:ff4e10bbe15974c6c65b20699ae45c46c231a8588269b0bb02c63476678ba14c

Observation ae2013fa-4567-474a-894e-f1846bb1a97a · inbound

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem cites this paper.

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem Towards Action Hijacking of Large Language Model-based Agent

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-15T19:45:09.827307Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:45:09.827307Z digest=sha256:be3081052f2c1768d79f5623036782571cf6fb44e3416c9f4c388b0e7c0f5a41

Observation a7f02b92-2c31-43f7-afec-5de2bedf923e · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Towards Action Hijacking of Large Language Model-based Agent

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:41.624343Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:41.624343Z digest=sha256:45079bdf5fde9845fca91c7be4bca35f4cd71d2d72d8175ff52dad69788134c0

Observation 2b69c7ee-b7b8-40b0-b7a1-0f4a7edae406 · inbound

Secure Multi-LLM Agentic AI and Agentification for Edge General Intelligence by Zero-Trust: A Survey cites this paper.

Secure Multi-LLM Agentic AI and Agentification for Edge General Intelligence by Zero-Trust: A Survey Towards Action Hijacking of Large Language Model-based Agent

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-05T15:26:33.589505Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:26:33.589505Z digest=sha256:bc1d5fd510b32789f229ee33a510bed3d8b62c6fb18af67944e6131346a7975d

Observation 54f7ea4d-16aa-4788-bd52-0ad2f134c9f2 · inbound

Toward a Safe Internet of Agents cites this paper.

Toward a Safe Internet of Agents Towards Action Hijacking of Large Language Model-based Agent

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-17T03:18:56.838806Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-17T03:16:40.622915Z digest=sha256:56137462cae0af970b32a3b1c005e1c39a4a4dbfdd34ef6d473fb2a4657c8c45

Observation d83c0b9e-595c-40b6-b117-9b9f8c9f8092 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Towards Action Hijacking of Large Language Model-based Agent

Reference 95

Resolution
verified exact
arxiv_id, observed 2026-05-09T21:38:30.714205Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-09T17:13:47.722098Z digest=sha256:c6539bfdbe5f9caae1e861071ce15dfae9c58bf4401dc9e8b9a2232ed5f18a0a

Observation 2b5f4330-b725-46c8-991c-dd3b488cba1b · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Towards Action Hijacking of Large Language Model-based Agent

Reference 93

Resolution
verified exact
arxiv_id, observed 2026-05-19T17:32:41.572623Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-19T17:30:22.481943Z digest=sha256:cc3094b742bf875a2ad5f754fab75c0afb189a161c5a18648a5f85517dc079dc

Observation e9121ddc-0084-4c58-b0a5-a12b43efabfc · inbound

Rethinking Agent Security as a Networking Problem cites this paper.

Rethinking Agent Security as a Networking Problem Towards Action Hijacking of Large Language Model-based Agent

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-16T00:16:52.634434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:16:52.634434Z digest=sha256:86739f7bbf042bb069ed5959978d3fd9cdbc2eda09068e7d775b8f0bd3168c01