Pith. sign in

Paper Citation Record · LEDGER

Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

As of 18 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 17 inbound Pith citation observations for arXiv:2503.00061.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2503.00061 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 17 of 17 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 17 of 17 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T04:36:29.559595Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T10:49:46.745286Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 740cc3d7-758b-4ea9-a2d7-72ecddb95aef · inbound

From Texts to Shields: Convergence of Large Language Models and Cybersecurity cites this paper.

From Texts to Shields: Convergence of Large Language Models and Cybersecurity Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-16T04:36:29.559595Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T04:36:29.559595Z digest=sha256:bb41a4649994a19cbf61cd9a7e56f35d227b70e377db551b8ab732ca45772c8f

Observation 8369a571-a0fd-49dc-a7f1-c3f6ce9a8943 · inbound

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks cites this paper.

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T15:41:21.733238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:41:21.733238Z digest=sha256:2753fc7765639ab8d0ba7e191ecbffbccf209d250d9fc066f9911e5c06d2ab68

Observation a6e14267-9edb-4393-acd3-b185c0e9545a · inbound

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem cites this paper.

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-15T19:45:09.562953Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:45:09.562953Z digest=sha256:77c451101b31df5b448e904eea2fa5b475782b7fcb6a4c4447fa81446b39bf3b

Observation 51ccba5c-0fd9-4e72-a5ab-81c28a9ee95a · inbound

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models cites this paper.

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T23:01:04.689987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:01:04.689987Z digest=sha256:a40573a55c4d1b664cbd768aa2852a210901fe702ee802c78be497f851e5f868

Observation 9ea67daa-1d07-4f90-9671-84575271cc77 · inbound

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree cites this paper.

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-06T15:52:56.834425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:52:56.834425Z digest=sha256:46c97e4cd93023cd0e3d3005ed5b87b07e44e5fc7a19bc14a0e47f75053575d6

Observation 0a56cf42-0de8-4745-9800-6888724488e7 · inbound

Evaluation and Benchmarking of LLM Agents: A Survey cites this paper.

Evaluation and Benchmarking of LLM Agents: A Survey Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 113

Resolution
unresolved
no resolver link, observed 2026-08-06T12:44:21.855663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:44:21.855663Z digest=sha256:53d40b2bbcf9c7f8b1e2eb7401e3cb1c17dca11ff5964bcfb8253f71dfad97bb

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · inbound

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment cites this paper.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:9551f72bc47d957cdcebe9369493a06f97674046e12df73f2b14dfdb483300a6

Observation aaefaa14-f0e5-4ae6-ae8c-704b169e0d45 · inbound

Prompt Injection as Role Confusion cites this paper.

Prompt Injection as Role Confusion Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T20:20:17.489468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-15T20:18:44.156726Z digest=sha256:3ca81d7e3282e838ea7c28b58d3bd7d502245d3774135c671eb54e6abdb62509

Observation 4ba43b50-8c77-4efe-b4aa-401bbf253463 · inbound

Prompt Injection as Role Confusion cites this paper.

Prompt Injection as Role Confusion Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T21:46:13.122809Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T21:46:13.122809Z digest=sha256:ee85243142375eece00194969f9e09545d9c29b495d8395d7985ff8cd6e9d747

Observation 9a401447-f264-4022-b7b6-b7ad9e7d6c02 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-10T11:55:21.361407Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-10T04:42:33.450658Z digest=sha256:e2ac212519bc0c19d0e179f8e982bcb567bcac42adfda1f131cc377bb6fbca1c

Observation 2f46234b-ec34-4284-b0e3-1f5d923705b6 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-21T00:53:53.069031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-21T00:51:22.907932Z digest=sha256:d0a1243ee9b54e4b4c0d854b528fdc1c603ceb027e0ae089212a3d5678bddc34

Observation 8a1698d4-9ac6-4d00-906b-66f0ce2ae004 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T15:56:48.909336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:56:48.909336Z digest=sha256:db07d6f4fa4fd13cdb40f18fceaa0714b28008f72d4e3b759d567ba87c6294d8

Observation 44b2861b-6791-41e5-a7f2-f7cb2cfe1322 · inbound

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults cites this paper.

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-06-28T20:52:38.007689Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-06-28T18:18:52.472535Z digest=sha256:63fa7a9c6660d052242a1179c528766e79e08778391b69a53e0ab59900d41616

Observation 7b3c326f-5f17-4e07-b878-cf799d84a27a · inbound

GIF: Locally Sound Geometric Information Flow Control for LLMs cites this paper.

GIF: Locally Sound Geometric Information Flow Control for LLMs Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 56

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:49:46.746919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-26T08:24:49.908288Z digest=sha256:99a5b2ad468f830177464e64b9c95c1eff7c170d2405cd15ccf223ebe617323a

Observation a693f6b7-cb2a-490e-9059-1d37a9adb93a · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 30

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.903048Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:945edcc37fca8c719e475dc9e88b17d83e0684c0e795e244f955de77d6fe1cb5

Observation c508a3db-130b-452a-958d-286fec2ad66b · inbound

ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments cites this paper.

ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 62

Resolution
unresolved
no resolver link, observed 2026-07-31T04:54:36.195909Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T04:54:36.195909Z digest=sha256:d0d0d8fab7a7679ee75f048d08f0387cc3096a1a30d3177cbd5bc726cbd18d37

Observation e47d4d2c-b630-443a-8f7b-8c3713f333d4 · inbound

Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents cites this paper.

Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-15T19:23:23.340515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:23:23.340515Z digest=sha256:fbf10052611d34822fe80b5ef9d3c8cc5408e976ca8d21748b3de58ac94c8208