Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.867597Z
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 24 inbound Pith citation observations for arXiv:2502.08586.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.867597Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-07T14:34:34.815687Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-07-03T15:48:35.883148Z
27 of 27 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation c7440ac4-45e3-4bb7-a91f-820a2aed8b14 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e852125b-d6ff-4489-a04b-a77da23ae6c3 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Tianyu Cui, Yanling Wang, Chuanpu Fu, Yong Xiao, Sijia Li, Xinhao Deng, Yunpeng Liu, Qinglin Zhang, Ziyi Qiu, Peiyang Li, et al
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9480e77a-efff-4347-abae-590188524f7c · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Security and Privacy Challenges of Large Language Models: A Survey
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bbfe858a-5d44-41c9-b60b-bc90690c4f1b · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bc7e9b01-f2a8-4054-9ba0-f5b095ca68cf · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks RLPrompt: Optimizing Discrete Text Prompts with Reinforcement Learning
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 684061cc-aec2-4e2a-b6d7-3144133a965a · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Feng He, Tianqing Zhu, Dayong Ye, Bo Liu, Wanlei Zhou, and Philip S Yu
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 98431140-7e89-4d59-ab0a-9a96b91afff6 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7a1455d9-0caa-4766-8dd8-7b9a09263566 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a1327166-0d8e-46ff-ab58-1c332a735972 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Red Teaming Language Models with Language Models
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7334860c-ab06-4cda-ae72-f58a63806e3b · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8cde1543-df87-4c5d-817a-1cfe0574c2f7 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0d2695b8-6189-4fba-a967-dad5b534717a · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Language agents achieve superhuman synthesis of scientific knowledge
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eda3da75-5be5-4065-9e7c-fa974e876269 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Evil Geniuses: Delving into the Safety of LLM-based Agents
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0d3f6b33-8f2f-4906-9e14-19c0ec4db78b · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Data poisoning attacks against federated learn- ing systems
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 662ad39e-bce8-4c2a-9cfd-0c3fe35e30f1 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B¨ol¨oni, and Qian Lou
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1f68dc76-45a4-4ecf-8a2c-213780f94de8 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7efd6251-11e5-49d5-8b67-2007d2b53ac3 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 75e283ae-38ba-4953-92f4-67cd737699ad · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eaaceb16-a8fe-4fb8-8a94-57705e2572ee · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks WebArena: A Realistic Web Environment for Building Autonomous Agents
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1f195015-f753-4464-a947-6a6c78bc07e5 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e82cbe66-f7fa-4f7e-89ff-287c47565931 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d3be1a2-b8fb-4a6e-849c-808561abf87a · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2017
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b8f9803-dfee-4eb5-832e-dde61e6a10e5 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents
Reference 2020
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 71d462d9-5a9b-43a1-aea4-39010fe76e3e · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks A Real-World WebAgent with Planning, Long Context Understanding, and Program Synthesis
Reference 2022
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c78bb0e7-56c5-4300-8fbf-19f51297f658 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
Reference 2023
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 86005911-1a78-45d4-baa8-42fdf1046c33 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks ChemCrow: Augmenting large-language models with chemistry tools
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0ddb43a-d175-449f-ae19-ea1f7c0025f3 · outbound
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Scalable Extraction of Training Data from (Production) Language Models
Reference 2025
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 253b84ab-1d66-4a3a-9997-cb0a75bd596f · inbound
Large Language Model Agent: A Survey on Methodology, Applications and Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 175
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation be51e42f-0e70-476d-9a6d-26463ffa2c86 · inbound
Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4de0b938-f923-4b0a-8e57-4b32cf438f03 · inbound
MLA-Trust: Benchmarking Trustworthiness of Multimodal LLM Agents in GUI Environments Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5f9b130e-a6b8-4e84-a6b8-d2fa89e8e789 · inbound
A Red Teaming Roadmap Towards System-Level Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d2036883-0a11-4792-ba90-bc10698481e9 · inbound
Levels of Autonomy for AI Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · inbound
We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 26006061-4145-4732-9dd9-8613a9c4af73 · inbound
A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f34403d8-64b3-4b77-bb38-3907e4f94c74 · inbound
Throttling Web Agents Using Reasoning Gates Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f01aec10-85e1-4790-83b8-2ae442ff8fba · inbound
When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0f547531-39aa-44f7-bad3-35e3f742389d · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e36b5551-e79c-4033-9e44-68fbdd28bc08 · inbound
Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eae352de-994f-46ac-b9b6-3eb072c67fb0 · inbound
CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 98b32e61-f9b1-48ef-955d-d23a9baee00c · inbound
Agents at Risk: How Users Unwittingly Undermine LLM Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 74e5a25f-89fd-455c-b8cd-06a8e35d706f · inbound
LLM-AutoDP: Automatic Data Processing via LLM Agents for Model Fine-tuning Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6353e071-8de9-4ae8-bddb-063f71c72e15 · inbound
OS-SPEAR: A Toolkit for the Safety, Performance,Efficiency, and Robustness Analysis of OS Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b563fa63-c81c-4092-865f-be3c916bf6c8 · inbound
Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 99
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 28206dc5-9048-4a28-8234-857c0250edde · inbound
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation feca9d20-b067-4135-afa2-fb5e6e604f1d · inbound
Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 88883738-429d-418b-9449-9a44d034f077 · inbound
Why Trust Your Agent? Empirical Security Gains from TRiSM-Guided Agentic Workflows in Healthcare Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 82e558c9-e23d-48c4-ae91-8a16c5ac1b37 · inbound
Agent Security Needs Redefinition through a Holistic Framework Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 268
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6c261576-7405-40f9-bbb1-2588d573b740 · inbound
One Anchor for All: Unified Multilingual and Multimodal Safety Alignment for LVLMs Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b5d24510-d72f-4e28-a4a8-9a1a0f87e169 · inbound
Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f9c7f59c-9fc1-4e6e-b474-ad1fb264f142 · inbound
Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 39a8ec91-4374-48f9-80f7-73e24dbbf8c2 · inbound
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.