{"as_of":"2026-08-11T12:25:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:bc577f3dcaa8fa5cf30f59ff10c1dbbb4776c9fac601262e7584d8626d33013c","coverage":[{"denominator":43,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":43,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-10T14:38:10.831214Z","state":"measured"},{"denominator":46,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":46,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-11T06:34:44.6726+00:00","state":"measured"},{"denominator":3,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":3,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-06T15:42:00.944376Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-05T22:51:28.498764Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-06T15:42:00.944376Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.15219","last_updated":"2025-07-21T03:41:44Z","snapshot_observed_at":"2026-08-06T15:35:31.690602Z","submitted_at":"2025-07-21T03:41:44Z","title":"PromptArmor: Simple yet Effective Prompt Injection Defenses","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-06T15:42:00.944376Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2507.15219"},"observation_digest":"sha256:1a619cc800906291863b93f0b47f04c3c2db45bb52b81438253ff1b2820cb80e","observation_id":"6fb7aee4-2f44-4257-8920-b8e04a98c701","resolution":{"observed_at":"2026-08-06T15:42:00.944376Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":"2501.15145","doi":null,"metadata_source":"pith","pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-05T22:51:28.498764Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","venue":"cs.CR","work_id":"3405c5e0-49c7-4576-ac78-69fc6b486a1c","year":2025},"citing_paper":{"arxiv_id":"2508.06418","last_updated":"2025-08-08T16:05:27Z","snapshot_observed_at":"2026-08-08T12:59:56.859606Z","submitted_at":"2025-08-08T16:05:27Z","title":"Quantifying Conversation Drift in MCP via Latent Polytope","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-05T22:51:28.105339Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2508.06418"},"observation_digest":"sha256:3eea26ae5cce0c3bcee6c8929c1ceba51a7eff90ce0aa70eb4a985d8f80090bc","observation_id":"dda0473a-f068-48a5-b58b-73328a2d860b","resolution":{"observed_at":"2026-08-05T22:51:28.507399Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.15145","snapshot_observed_at":"2026-08-01T14:11:22.404653Z","title":"Promptshield: Deployable detection for prompt injection attacks,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.18847","last_updated":"2026-07-21T08:35:22Z","snapshot_observed_at":"2026-08-08T16:25:54.761610Z","submitted_at":"2026-07-21T08:35:22Z","title":"Data Leakage Prevention in Agentic Applications via Preemptive Hardening","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-01T14:11:22.404653Z"},"links":{"cited_paper":"/paper/2501.15145","citing_paper":"/paper/2607.18847"},"observation_digest":"sha256:6a61e513ea34b35fcd03d3bb5cc092b37ea3eab3fa719dd7e983376a01afd41b","observation_id":"c5cea3cc-776f-49a5-ad13-96b85ee5c4f6","resolution":{"observed_at":"2026-08-01T14:11:22.404653Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2501.15145/citation-record","integrity":"/paper/2501.15145/integrity","json":"/paper/2501.15145/citation-record.json","paper":"/paper/2501.15145"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.418900Z","title":"Synthetic Python Problems(SPP) Dataset","venue":null,"work_id":"d7842b83-3610-4a7e-82c9-7f82dc3259c6","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.655185Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:997c7d6fbe7edbe235d76d2b663716ab2b69da6c099f08d2f478f7cdc4cd4347","observation_id":"a9b0e2eb-903f-4636-8665-20e675895086","resolution":{"observed_at":"2026-08-10T14:38:11.422630Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.407722Z","title":null,"venue":null,"work_id":"d38a3e26-5151-48a4-a62b-cd16a818387a","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.659639Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:f98866516271508073fee7dd9e91fc04e8a85dd5c0796c1f63879e4408723ff0","observation_id":"36789142-a7ab-4226-9758-8c02a1c5878e","resolution":{"observed_at":"2026-08-10T14:38:11.411292Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2107.03374","last_updated":"2021-07-14T17:16:02Z","snapshot_observed_at":"2026-08-08T11:58:24.516369Z","submitted_at":"2021-07-07T17:41:24Z","title":"Evaluating Large Language Models Trained on Code","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2107.03374","snapshot_observed_at":"2026-08-10T14:38:10.663848Z","title":null,"venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.663848Z"},"links":{"cited_paper":"/paper/2107.03374","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:de61a4dfb26e10eff0e61665016ac85af6f90fdbb0e6d071d3d35d51b5ebaf26","observation_id":"b4123771-61eb-4ed3-a78a-1c1f87e2bb74","resolution":{"observed_at":"2026-08-10T14:38:10.663848Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.396402Z","title":null,"venue":null,"work_id":"104f08db-d3ce-4df1-891c-a3dfdfff704d","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.668580Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:1620bdcb6c9ed1bc615f8dd226b95e8bc54072476bbf40aa876779b0abab1aa0","observation_id":"0a101140-b35d-40a9-8e31-31de44155a63","resolution":{"observed_at":"2026-08-10T14:38:11.400205Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.385656Z","title":null,"venue":null,"work_id":"00d43e87-a9a6-4f2c-928c-534b439cbde2","year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.676549Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:d848d5a3ca4b663d0b4a1143d7cbddfb2e7e82c401fe17948b12194b4ff74adc","observation_id":"c1a4e108-e2e6-4b2e-9b53-f1cb3e6f091b","resolution":{"observed_at":"2026-08-10T14:38:11.389301Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14233","last_updated":"2023-05-23T16:49:14Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-05-23T16:49:14Z","title":"Enhancing Chat Language Models by Scaling High-quality Instructional Conversations","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14233","snapshot_observed_at":"2026-08-10T14:38:10.684491Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.684491Z"},"links":{"cited_paper":"/paper/2305.14233","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e9aec0182f6efad0d5d63829f650af14737122396669c9561d3534658bcf538a","observation_id":"0bea6be7-c00d-4a10-b2ce-9485abc9f5e0","resolution":{"observed_at":"2026-08-10T14:38:10.684491Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.21783","last_updated":"2024-11-23T23:27:33Z","snapshot_observed_at":"2026-08-10T16:40:37.411115Z","submitted_at":"2024-07-31T17:54:27Z","title":"The Llama 3 Herd of Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.21783","snapshot_observed_at":"2026-08-10T14:38:10.689007Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.689007Z"},"links":{"cited_paper":"/paper/2407.21783","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:5aea79c551716f9e1687d9d600d5b8342756c4a72a8921e641ad4fcd6d4f7a5c","observation_id":"f758adff-8c80-43eb-b06f-7ef53093eb12","resolution":{"observed_at":"2026-08-10T14:38:10.689007Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.12173","last_updated":"2023-05-05T14:26:17Z","snapshot_observed_at":"2026-07-06T14:55:08.682906Z","submitted_at":"2023-02-23T17:14:38Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.12173","snapshot_observed_at":"2026-08-10T14:38:10.694084Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.694084Z"},"links":{"cited_paper":"/paper/2302.12173","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:4938b754cec4a51d40880ae10fa2040aaff8c1244f5932bb0e84481f184cd2a2","observation_id":"fbc2aa10-db96-429b-aaa1-a98bad8c4ef6","resolution":{"observed_at":"2026-08-10T14:38:10.694084Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2111.09543","last_updated":"2023-03-24T09:17:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2021-11-18T06:48:00Z","title":"DeBERTaV3: Improving DeBERTa using ELECTRA-Style Pre-Training with Gradient-Disentangled Embedding Sharing","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2111.09543","snapshot_observed_at":"2026-08-10T14:38:10.698026Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.698026Z"},"links":{"cited_paper":"/paper/2111.09543","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:ff0c227aaa18352658e3877137dec4a515dc8a5426d5af318809a96f82e974b8","observation_id":"430734d5-0bb4-45a0-a7b5-c64c1fbfdc8b","resolution":{"observed_at":"2026-08-10T14:38:10.698026Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2106.09685","last_updated":"2021-10-16T18:40:34Z","snapshot_observed_at":"2026-08-11T08:20:29.798517Z","submitted_at":"2021-06-17T17:37:18Z","title":"LoRA: Low-Rank Adaptation of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2106.09685","snapshot_observed_at":"2026-08-10T14:38:10.702531Z","title":"Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.702531Z"},"links":{"cited_paper":"/paper/2106.09685","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e8274d4008466ca79f9bd57b10c653d2272dea80ca8bea688683c337f0f0baf7","observation_id":"4e929d92-b2ea-4cdd-9efd-3a711c335683","resolution":{"observed_at":"2026-08-10T14:38:10.702531Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.00348","last_updated":"2025-04-23T01:35:19Z","snapshot_observed_at":"2026-08-11T01:59:50.770534Z","submitted_at":"2024-11-01T04:05:59Z","title":"Attention Tracker: Detecting Prompt Injection Attacks in LLMs","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.00348","snapshot_observed_at":"2026-08-10T14:38:10.707493Z","title":"Hsu, and Pin-Yu Chen","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.707493Z"},"links":{"cited_paper":"/paper/2411.00348","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:15301a97adf733740b1495cd1f0854fb9f56167d9305e89edf71a91278359c28","observation_id":"fa8ae770-decd-434f-9019-873469b9d942","resolution":{"observed_at":"2026-08-10T14:38:10.707493Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.10169","last_updated":"2023-07-19T17:55:13Z","snapshot_observed_at":"2026-08-10T14:34:24.189939Z","submitted_at":"2023-07-19T17:55:13Z","title":"Challenges and Applications of Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.10169","snapshot_observed_at":"2026-08-10T14:38:10.711675Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.711675Z"},"links":{"cited_paper":"/paper/2307.10169","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:33e5cf2e639be2e2c3250230f53f3230e3086f079b5de8aca6749f95561bffac","observation_id":"cdc94ba1-f4e0-4a7b-90e8-0d987d8a083d","resolution":{"observed_at":"2026-08-10T14:38:10.711675Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.22770","last_updated":"2025-03-30T16:39:15Z","snapshot_observed_at":"2026-08-08T06:17:50.732965Z","submitted_at":"2024-10-30T07:39:42Z","title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.22770","snapshot_observed_at":"2026-08-10T14:38:10.715889Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.715889Z"},"links":{"cited_paper":"/paper/2410.22770","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:2fee5d4d7e36dc57e7ec7e8e839a39bbe6aefdfa069734dac01f615f12b93334","observation_id":"eb4b1d80-ee42-47ef-97bb-5c0b891f7f69","resolution":{"observed_at":"2026-08-10T14:38:10.715889Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.720746Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.720746Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e9be674bac9667de5444a45c247dcf67551473de582c43802d2c854ace388dd4","observation_id":"3a570b69-e696-44b6-95e1-7fe185baa0b3","resolution":{"observed_at":"2026-08-10T14:38:10.720746Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.355227Z","title":null,"venue":null,"work_id":"9da1fcbc-47b0-468e-81bf-a0b35c8431f6","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.730931Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:17c80ad319aafd64e6abbef996a994a18769b3aa797b1f7050c9686c4e3d6c5d","observation_id":"7ec546d2-09b4-454d-8931-417970feef7e","resolution":{"observed_at":"2026-08-10T14:38:11.358799Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.343242Z","title":null,"venue":null,"work_id":"26ddd964-e362-4fb4-8eb9-e2e5f2bb9719","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.734732Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:7d7d1068f0a6a9e17ae126f94110a2bf0c90de68829e9a4c657c2516aced8ce1","observation_id":"ae868522-a959-4baa-b726-6accbe7b7d78","resolution":{"observed_at":"2026-08-10T14:38:11.347571Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2303.08774","last_updated":"2024-03-04T06:01:33Z","snapshot_observed_at":"2026-08-07T07:30:12.213965Z","submitted_at":"2023-03-15T17:15:04Z","title":"GPT-4 Technical Report","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2303.08774","snapshot_observed_at":"2026-08-10T14:38:10.738851Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.738851Z"},"links":{"cited_paper":"/paper/2303.08774","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:4e90b7671b7631627349d71977e6ccb77f000c3d1e14601e9f0d9b8ec053fd3b","observation_id":"a449f3a9-6ad2-4080-8ef6-29338e173cee","resolution":{"observed_at":"2026-08-10T14:38:10.738851Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.743167Z","title":"Wainwright, Pamela Mishkin, Chong Zhang, Sandhini Agarwal, Katarina Slama, Alex Ray, et al","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.743167Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:9d6e0e0c7408cc1447bd86b92a32f8f65beec7f271300cbeb24e1ca54512906a","observation_id":"1cada18d-5cce-4dc4-933c-4c10486c5a70","resolution":{"observed_at":"2026-08-10T14:38:10.743167Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2211.09527","last_updated":"2022-11-17T13:43:20Z","snapshot_observed_at":"2026-07-06T14:19:47.424778Z","submitted_at":"2022-11-17T13:43:20Z","title":"Ignore Previous Prompt: Attack Techniques For Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2211.09527","snapshot_observed_at":"2026-08-10T14:38:10.752114Z","title":null,"venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.752114Z"},"links":{"cited_paper":"/paper/2211.09527","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e07dd6a5747349204e7ca5a336e9dba8de1e403b351f5d792f544915358e4920","observation_id":"ed18f4c6-1517-4f7b-a14f-541740e2ccbe","resolution":{"observed_at":"2026-08-10T14:38:10.752114Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.17673","last_updated":"2024-01-08T19:11:26Z","snapshot_observed_at":"2026-07-06T17:09:55.651197Z","submitted_at":"2023-12-29T16:37:53Z","title":"Jatmo: Prompt Injection Defense by Task-Specific Finetuning","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.17673","snapshot_observed_at":"2026-08-10T14:38:10.756911Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.756911Z"},"links":{"cited_paper":"/paper/2312.17673","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:2b96c6c0f574122a0cafb7d3962498051d92d5b2f7f2549292a35d5906eeaeea","observation_id":"cd390d15-0022-45d2-88a3-f93878cbf92f","resolution":{"observed_at":"2026-08-10T14:38:10.756911Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.323236Z","title":null,"venue":null,"work_id":"930d212e-0410-4edb-b10d-d3ece3f43d48","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.760989Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:97371a9be2ac46f9cf4f66ab33d55457ed271d1b0f8d05aeee6ef40166bc3959","observation_id":"d306e8c6-4453-470b-87f5-bc4c825e1ff2","resolution":{"observed_at":"2026-08-10T14:38:11.327290Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.310829Z","title":null,"venue":null,"work_id":"9542f6e7-0571-4d26-bd64-1d8ad0ef11b7","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.764678Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:4860ca5368c9fadb7ed1a8bd5def14ad2f70a9caaac261b7e1262106b14172b6","observation_id":"a4944b51-6881-4a3f-98cc-bc88dbeaae2b","resolution":{"observed_at":"2026-08-10T14:38:11.314722Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14965","last_updated":"2024-03-27T04:38:44Z","snapshot_observed_at":"2026-08-07T01:32:47.981682Z","submitted_at":"2023-05-24T09:57:37Z","title":"Tricking LLMs into Disobedience: Formalizing, Analyzing, and Detecting Jailbreaks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14965","snapshot_observed_at":"2026-08-10T14:38:10.768234Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.768234Z"},"links":{"cited_paper":"/paper/2305.14965","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:134b015f5a4cf4df0ad139e429d7823b7d2fd1928719e119e4923445d96c169d","observation_id":"ea31d402-a21e-4380-a1cb-175ead1a2da6","resolution":{"observed_at":"2026-08-10T14:38:10.768234Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.16119","last_updated":"2024-03-03T00:12:16Z","snapshot_observed_at":"2026-07-06T16:53:18.275859Z","submitted_at":"2023-10-24T18:18:11Z","title":"Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.16119","snapshot_observed_at":"2026-08-10T14:38:10.772475Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.772475Z"},"links":{"cited_paper":"/paper/2311.16119","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:9cf2713e9383658f17c8022b4723efc9834e650f3a062bc3b700fd96a8b63074","observation_id":"8a3c8de3-e72f-42e5-9b9b-750ed42eba3e","resolution":{"observed_at":"2026-08-10T14:38:10.772475Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.03825","last_updated":"2024-05-15T12:06:31Z","snapshot_observed_at":"2026-07-06T16:03:34.432602Z","submitted_at":"2023-08-07T16:55:20Z","title":"\"Do Anything Now\": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.03825","snapshot_observed_at":"2026-08-10T14:38:10.776605Z","title":"Do Anything Now","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.776605Z"},"links":{"cited_paper":"/paper/2308.03825","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:4cc5ad38aa7350f234bae24b26547b8fec4dc8bc64a338e561ec03e7970b8a88","observation_id":"6d4a26dc-8e4d-407d-98e8-7b3ce237e84d","resolution":{"observed_at":"2026-08-10T14:38:10.776605Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.298716Z","title":null,"venue":null,"work_id":"f1998651-1650-4151-bc27-95a989089a5a","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.780646Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:ec6db8484c4fc433204f75bc81ef295910ffe98d68cf2713830d2f06e87cd158","observation_id":"e954736d-74ad-432f-bd8f-3297b2cc3764","resolution":{"observed_at":"2026-08-10T14:38:11.303077Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.11805","last_updated":"2025-05-09T21:04:06Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-12-19T02:39:27Z","title":"Gemini: A Family of Highly Capable Multimodal Models","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.11805","snapshot_observed_at":"2026-08-10T14:38:10.784378Z","title":"Dai, Anja Hauth, Katie Millican, et al","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.784378Z"},"links":{"cited_paper":"/paper/2312.11805","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:fbe5b411e7d8f1f35c6ce53823de0576e60dd5a271ad12dc4bc0e6ab7ee98b16","observation_id":"6daeda31-1370-4c4c-b7da-e9c02c435b21","resolution":{"observed_at":"2026-08-10T14:38:10.784378Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.13971","last_updated":"2023-02-27T17:11:15Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-02-27T17:11:15Z","title":"LLaMA: Open and Efficient Foundation Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.13971","snapshot_observed_at":"2026-08-10T14:38:10.788382Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.788382Z"},"links":{"cited_paper":"/paper/2302.13971","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:6cf927900758b361faa1e7bd7ef51e27a316e91873e02b7782c3fe12f1383487","observation_id":"9031ac05-1c26-46a1-b7ab-8a8391e3d086","resolution":{"observed_at":"2026-08-10T14:38:10.788382Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-10T04:45:11.275468Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.13208","snapshot_observed_at":"2026-08-10T14:38:10.792153Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.792153Z"},"links":{"cited_paper":"/paper/2404.13208","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:b4b757054c6370491c5f1234a1997b317582b1ec38ac5d3156c6511a72cf9016","observation_id":"49c8ba2b-bfea-4f87-aeb7-6f2aa4cd2269","resolution":{"observed_at":"2026-08-10T14:38:10.792153Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2408.01605","last_updated":"2024-09-06T18:17:07Z","snapshot_observed_at":"2026-08-09T15:49:58.734883Z","submitted_at":"2024-08-02T23:47:27Z","title":"CYBERSECEVAL 3: Advancing the Evaluation of Cybersecurity Risks and Capabilities in Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2408.01605","snapshot_observed_at":"2026-08-10T14:38:10.796063Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.796063Z"},"links":{"cited_paper":"/paper/2408.01605","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:25666d6600387873e54002a41abacebc0cf06d5bfcf62809de35ebc1b2fab3f0","observation_id":"0d80e17d-1ac1-4b7c-befd-95140e1ca5c4","resolution":{"observed_at":"2026-08-10T14:38:10.796063Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2212.10560","last_updated":"2023-05-25T23:50:07Z","snapshot_observed_at":"2026-07-06T14:33:11.945106Z","submitted_at":"2022-12-20T18:59:19Z","title":"Self-Instruct: Aligning Language Models with Self-Generated Instructions","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2212.10560","snapshot_observed_at":"2026-08-10T14:38:10.800055Z","title":"Smith, Daniel Khashabi, and Hannaneh Hajishirzi","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.800055Z"},"links":{"cited_paper":"/paper/2212.10560","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:e79a6c7bd23fcde74332d684aa28fd19c7c005fa6a35663ed2f50db3fabe674b","observation_id":"6e641870-270d-4651-ae70-77cf1ce74a13","resolution":{"observed_at":"2026-08-10T14:38:10.800055Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2204.07705","last_updated":"2022-10-24T07:00:15Z","snapshot_observed_at":"2026-07-06T13:00:53.618234Z","submitted_at":"2022-04-16T03:12:30Z","title":"Super-NaturalInstructions: Generalization via Declarative Instructions on 1600+ NLP Tasks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2204.07705","snapshot_observed_at":"2026-08-10T14:38:10.804159Z","title":null,"venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.804159Z"},"links":{"cited_paper":"/paper/2204.07705","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:d830f9b150848f5a1a762267c44bf695622f530daf6ee24692c83c3e144b978b","observation_id":"ccf65128-c3b4-44fe-8758-92a5eace32ac","resolution":{"observed_at":"2026-08-10T14:38:10.804159Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2109.01652","last_updated":"2022-02-08T20:26:45Z","snapshot_observed_at":"2026-08-10T07:52:08.606999Z","submitted_at":"2021-09-03T17:55:52Z","title":"Finetuned Language Models Are Zero-Shot Learners","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2109.01652","snapshot_observed_at":"2026-08-10T14:38:10.808151Z","title":"Zhao, Kelvin Guu, Adams Wei Yu, Brian Lester, Nan Du, Andrew M","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.808151Z"},"links":{"cited_paper":"/paper/2109.01652","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:a54da2e96e8e22c05a93b6d6dbabbc6c38f12b845651763ee09ef7f888023cdc","observation_id":"28f8851d-78e6-46dc-9232-b2b29d79ece2","resolution":{"observed_at":"2026-08-10T14:38:10.808151Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.06387","last_updated":"2024-05-25T07:01:15Z","snapshot_observed_at":"2026-08-06T13:25:52.403871Z","submitted_at":"2023-10-10T07:50:29Z","title":"Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.06387","snapshot_observed_at":"2026-08-10T14:38:10.811952Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.811952Z"},"links":{"cited_paper":"/paper/2310.06387","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:fc19e42552ef7dc6ba0ba1b62e10d649a98805307dc0714dc29fddce4a13edcb","observation_id":"0175743d-88fe-4eb6-9851-69008c436cdf","resolution":{"observed_at":"2026-08-10T14:38:10.811952Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.285999Z","title":null,"venue":null,"work_id":"33f1f081-6a5b-4769-8944-64b6464cf689","year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.816173Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:1cfc0f39b62ab59ebfc5d204bf93943b38824c5b4a25dd1226d178efbc5bdc9e","observation_id":"5624ae63-1e2e-44db-a517-e2a5e557d6a0","resolution":{"observed_at":"2026-08-10T14:38:11.290763Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14197","last_updated":"2025-01-27T08:51:16Z","snapshot_observed_at":"2026-08-11T04:13:43.714152Z","submitted_at":"2023-12-21T01:08:39Z","title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.14197","snapshot_observed_at":"2026-08-10T14:38:10.819685Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.819685Z"},"links":{"cited_paper":"/paper/2312.14197","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:14c031194659b32598160f567017a73f5e56a5182119d660229a73ec63c55fb7","observation_id":"cdda15a5-3796-4d18-9e1a-2d542bc05a47","resolution":{"observed_at":"2026-08-10T14:38:10.819685Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2309.11998","last_updated":"2024-03-10T19:34:57Z","snapshot_observed_at":"2026-07-06T16:21:45.588487Z","submitted_at":"2023-09-21T12:13:55Z","title":"LMSYS-Chat-1M: A Large-Scale Real-World LLM Conversation Dataset","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.11998","snapshot_observed_at":"2026-08-10T14:38:10.823352Z","title":"Xing, et al","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.823352Z"},"links":{"cited_paper":"/paper/2309.11998","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:16d3a7c991bbfc9648f1c79bc2d749385abaf793cded580ca38cb961f2450872","observation_id":"defdacfd-8992-4a0f-83f2-a13ab9707d1d","resolution":{"observed_at":"2026-08-10T14:38:10.823352Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.07911","last_updated":"2023-11-14T05:13:55Z","snapshot_observed_at":"2026-07-06T16:47:08.877195Z","submitted_at":"2023-11-14T05:13:55Z","title":"Instruction-Following Evaluation for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.07911","snapshot_observed_at":"2026-08-10T14:38:10.827282Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.827282Z"},"links":{"cited_paper":"/paper/2311.07911","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:385390d576d4f0ae5b8905ffce62ddf0c7c5a4f3076317d03e2fd0cd7816be95","observation_id":"596a5622-8e09-4e7a-9b5e-185a8ea05ab8","resolution":{"observed_at":"2026-08-10T14:38:10.827282Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-07-06T15:59:23.019044Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-10T14:38:10.831214Z","title":"hello!” are classified as an injection). Communications with the model developers revealed that the “jailbreak","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.831214Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:c9bbedc6524a62528efe64a466b2362e78a34bbdf8dcae0b3a5d565388c84366","observation_id":"6738e3dd-4006-41f4-b406-2220d1abe217","resolution":{"observed_at":"2026-08-10T14:38:10.831214Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2203.02155","last_updated":"2022-03-04T07:04:42Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-03-04T07:04:42Z","title":"Training language models to follow instructions with human feedback","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2203.02155","snapshot_observed_at":"2026-08-10T14:38:10.747784Z","title":"doi:10.48550/arXiv.2203.02155 arXiv:2203.02155 [cs]","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.747784Z"},"links":{"cited_paper":"/paper/2203.02155","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:a3e9d12c6ab6f6133c935ae236ec14aebe03f9187b8cc1d8ede03c15d43eb5cf","observation_id":"c1460b56-bd4c-464d-b07b-71b262190cb2","resolution":{"observed_at":"2026-08-10T14:38:10.747784Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:11.373294Z","title":"https://www.databricks.com/blog/2023/04/12/dolly-first-open- commercially-viable-instruction-tuned-llm","venue":null,"work_id":"2fbb6085-5096-4b8d-93ae-1cf5277496c4","year":2023},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.680476Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:95cb801b0505afeeab51179cb7de5f990f48ac7fe7a7331e632ea8cf9d15eaee","observation_id":"b6211f10-57d6-4d7d-a37a-1691415c0ff9","resolution":{"observed_at":"2026-08-10T14:38:11.377794Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-10T14:38:10.727112Z","title":"In USENIX Security 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.727112Z"},"links":{"citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:eb5b347de16c2260ba314609ade4517982d900015058b4bf50375ce7c4467c5b","observation_id":"dd7110e7-c90d-42a0-9c3c-d11d2a2c5e90","resolution":{"observed_at":"2026-08-10T14:38:10.727112Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.06363","last_updated":"2024-09-25T19:48:39Z","snapshot_observed_at":"2026-08-11T03:37:22.279261Z","submitted_at":"2024-02-09T12:15:51Z","title":"StruQ: Defending Against Prompt Injection with Structured Queries","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.06363","snapshot_observed_at":"2026-08-10T14:38:10.672411Z","title":"doi:10.48550/arXiv.2402.06363 arXiv:2402.06363 [cs]","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks","version":2},"reference_index":2025,"source":"pdf_text","source_observed_at":"2026-08-10T14:38:10.672411Z"},"links":{"cited_paper":"/paper/2402.06363","citing_paper":"/paper/2501.15145"},"observation_digest":"sha256:3869e5b59b48fbd686478380e0b2a24df0722f0072959bb8825ee9808e21b0bb","observation_id":"56b49855-31aa-49e4-bd2c-99e7ed05df51","resolution":{"observed_at":"2026-08-10T14:38:10.672411Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2501.15145","last_updated":"2025-04-12T02:58:59Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-10T14:32:18.612026Z","submitted_at":"2025-01-25T09:03:19Z","title":"PromptShield: Deployable Detection for Prompt Injection Attacks"},"reference_resolution":{"displayed":43,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":41,"verified_exact":0,"verified_fuzzy":2},"total_outbound_references":43},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-11T06:34:44.6726+00:00","source":"crossref"},{"observed_at":"2026-08-11T06:34:36.301508+00:00","source":"retraction_watch"}],"thesis":"As of 11 August 2026, this Paper Citation Record lists 43 of 43 outbound references and 3 inbound Pith citation observations for arXiv:2501.15145."}