Pith. sign in

Paper Citation Record · LEDGER

LLM Agents Should Employ Security Principles

As of 12 August 2026, this Paper Citation Record lists 90 of 90 outbound references and 18 inbound Pith citation observations for arXiv:2505.24019.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.24019 v1

Coverage vector

measured 90 of 90 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T12:42:18.393562Z

measured 108 of 108 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00

measured 18 of 18 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T04:33:17.074410Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

90 of 90 outbound references displayed

  • verified exact0
  • verified fuzzy23
  • unresolved67
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bd985b7c-b0df-459b-8000-298db5310957 · outbound

This paper cites Firewalls to Secure Dynamic LLM Agentic Networks.

LLM Agents Should Employ Security Principles Firewalls to Secure Dynamic LLM Agentic Networks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.530457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.530457Z digest=sha256:b9da8350c02925910ca96c725809e2ad22b1681874107b69c8e2b339c4053f6d

Observation d5d6c0d8-f456-42ec-a9f2-834243d80537 · outbound

This paper cites Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press.

LLM Agents Should Employ Security Principles Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.608335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.608335Z digest=sha256:7e02b29a6e4eee8fc0239807fb39f3cf03cdd0c5760a49157167643fab5ce396

Observation cdec2bb5-bbf7-450e-a9ff-048260c07d27 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

LLM Agents Should Employ Security Principles Detecting Language Model Attacks with Perplexity

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.698195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.698195Z digest=sha256:c16f8864223096028a82d4cf833350c099b6b64990eabf58f0917bf9fe5d2e9a

Observation d05109fa-289d-4952-ad75-ecd264b038e0 · outbound

This paper cites Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/.

LLM Agents Should Employ Security Principles Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.809393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.809393Z digest=sha256:8194fc0344a5aa398d3ec65522a1abe69e90e3dc1e2e5d28f0d818e260709c37

Observation 089e5c0d-478b-43ef-bfa3-b3b54410e83b · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

LLM Agents Should Employ Security Principles AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.942106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.942106Z digest=sha256:ddeb3d368e8e5eaa18298b865834372e7ff0efc3964ca832834a9baf3e890442

Observation dd089303-22eb-46fd-9132-1b9724232760 · outbound

This paper cites Monitoring computer use via hierarchical summarization.

LLM Agents Should Employ Security Principles Monitoring computer use via hierarchical summarization

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.032707Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.032707Z digest=sha256:9f2a7f15552f84193591ebee69a6be628f41f282f8fe01fef3c93b489278d6d5

Observation 9ff1aaba-0123-4546-9680-1d68c64f885f · outbound

This paper cites Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol.

LLM Agents Should Employ Security Principles Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.133502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.133502Z digest=sha256:1d66eb958acf0f787c60d43f2b46b8f5e9e38425f6b151aefb58f9d1c245c974

Observation be791b63-2bd7-4f41-afd4-8331c45673cb · outbound

This paper cites https://github.com/microsoft/autogen/.

LLM Agents Should Employ Security Principles https://github.com/microsoft/autogen/

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.217203Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.217203Z digest=sha256:380534f699bcad0cc4e7630e626fadddc094b9fc0737f554c2875d18f1ce52c2

Observation d65cd2b0-10c3-4be9-bb2e-824e744adbb6 · outbound

This paper cites AirGapAgent: Protecting privacy-conscious conversational agents.

LLM Agents Should Employ Security Principles AirGapAgent: Protecting privacy-conscious conversational agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.321358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.321358Z digest=sha256:afd7017c818781d7914c489444463d4b72a60da34718ba2709e072d74627b891

Observation d64ee457-9957-4055-8516-91b05dfbe8bd · outbound

This paper cites International AI Safety Report.

LLM Agents Should Employ Security Principles International AI Safety Report

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.396694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.396694Z digest=sha256:3fe5f2643960094868fe96c41607c722562f7fc1fad559f38d93afd2c1d355f5

Observation dbcb2b21-ad46-4d62-a163-76dcfe37b233 · outbound

This paper cites Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment.

LLM Agents Should Employ Security Principles Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.476447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.476447Z digest=sha256:c7a3282adb7934fdd52b819bd2bb3f2b39052701113085b8156c9b481088c859

Observation bd117973-b3e8-4121-a09d-423378211520 · outbound

This paper cites Computer Security: Art and Science.

LLM Agents Should Employ Security Principles Computer Security: Art and Science

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.571062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.571062Z digest=sha256:f2c6570e7a8f9a806715eba1d180e1beedd9e57c409606df920aede30c02404a

Observation 8d9940fd-8a91-4caa-9895-691e6f6f76d3 · outbound

This paper cites Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020.

LLM Agents Should Employ Security Principles Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.674312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.674312Z digest=sha256:7f0559a494d8a9f05250b9de13a22b2ce9117b7de3baba331b3119e63f3e4324

Observation d347328e-ca07-425f-b855-b3af2492b132 · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

LLM Agents Should Employ Security Principles Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.749191Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.749191Z digest=sha256:d3dfc97a4c762e993f5001c749107d46792eb715d63824af6f4bef0b25724d90

Observation 867af2a8-de4d-4a33-8869-65aa2047e972 · outbound

This paper cites Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

LLM Agents Should Employ Security Principles Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.823955Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.823955Z digest=sha256:cc6b7f538945d2c6dfc6a82cc8d59e7fc87bcd653d0c8918b8af9b4e32c983ed

Observation 596ee284-0ea0-4129-8f46-0a457afe19d0 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

LLM Agents Should Employ Security Principles LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.956892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.956892Z digest=sha256:2e3a9060487abba759ead9fea974fe63ab4b9505625ba8689872fd24a5df51c4

Observation 2892f98d-6ca6-4c1c-a487-fc9581d063d9 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

LLM Agents Should Employ Security Principles Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.078265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.078265Z digest=sha256:3be774b57124d91c4dcb4275a905fdeed7053ca032c170d8cddd51300ea29d9b

Observation 4fcb89fa-0184-401d-bb07-7ef9b69a6a92 · outbound

This paper cites LLMs for Customer Service and Support.

LLM Agents Should Employ Security Principles LLMs for Customer Service and Support

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.185759Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.185759Z digest=sha256:887aa086e943f1c6a6d940b69a89f3aad88be975eaea8d77406c8d902d1dd85e

Observation ceb442c8-68b9-40a3-8631-22abaefc089f · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

LLM Agents Should Employ Security Principles AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.263611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.263611Z digest=sha256:67c25b3827b99dd806c50cc710c7d9442775fccdf1eab1b33cf591a6dbc8a546

Observation 25525d58-b3c5-4ba9-805e-03c7bf4cf5dc · outbound

This paper cites A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025.

LLM Agents Should Employ Security Principles A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.351103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.351103Z digest=sha256:93075b0e737b5f09d5a7b5c59535f9a7f49544e507816b12a002d7e90d54322c

Observation daed623c-b688-44db-a438-1e84c1d74c33 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

LLM Agents Should Employ Security Principles LLM Agents can Autonomously Hack Websites

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.460789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.460789Z digest=sha256:ff78a5f47380a269cb0711e78caf78ca196167e985d4e9334b33597de95e7cee

Observation b98b3fef-4049-4ffc-ac4c-0154f96d31d3 · outbound

This paper cites Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms.

LLM Agents Should Employ Security Principles Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.991712Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:12.564782Z digest=sha256:2ac33f1a92d28ed4a9c1d9b4cf77eac5ba464be32659879a4bc83fff0b449369

Observation 59849ad6-626a-4837-baa2-6e83386a7dcd · outbound

This paper cites Announcing the Agent2Agent Protocol (A2A), 2025.

LLM Agents Should Employ Security Principles Announcing the Agent2Agent Protocol (A2A), 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.889907Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:12.637148Z digest=sha256:062ed96ff313bab8a2eb66a0fb135957e1a93778582a7cb7c63151215eca454b

Observation eef13c70-b45a-442e-ae02-560f42321cae · outbound

This paper cites Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024.

LLM Agents Should Employ Security Principles Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.790524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:12.733210Z digest=sha256:26c494e5768ff60fe9d57cf1974fab7bdea6a9acc0aead82740c4c7e0bae6c40

Observation 96993d6c-dce1-4cbf-b163-c9a0afd3c2b9 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

LLM Agents Should Employ Security Principles Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.836704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.836704Z digest=sha256:06ce4cd27d2c19fec024c9e9635e84830517d52f0d275a92b858f1b970d7c9e9

Observation 83cb01ea-f7e7-4ada-a985-5faed646f991 · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

LLM Agents Should Employ Security Principles TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.942186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.942186Z digest=sha256:00244e966d1558ce6572dbf148017e8721d189c44071d6aaef4666910db4cb0c

Observation 1c1f3d12-d2ea-4e88-a032-f246d074d031 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

LLM Agents Should Employ Security Principles Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.041837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.041837Z digest=sha256:d58c11b3c1a5bd5f90055420d7d077776bd0c539718c1c1a93a9db402ac99c67

Observation e070e8a2-7038-46cc-8d1e-ec256ef640c2 · outbound

This paper cites DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines.

LLM Agents Should Employ Security Principles DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.159532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.159532Z digest=sha256:a2622e22d39bb3748a11415bf04499764ef8cd6134687286ac556349fee73c5b

Observation 30dc0c33-a749-4094-8680-eaa2a1479476 · outbound

This paper cites https://github.com/langchain-ai/langchain.

LLM Agents Should Employ Security Principles https://github.com/langchain-ai/langchain

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.630328Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:13.243542Z digest=sha256:52ed4de9271f688daeb3ba38c35971c1c858596dadb2473df8ef3a1cba16779b

Observation 03efd940-4c6a-4584-833c-436b070c380c · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

LLM Agents Should Employ Security Principles Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.333338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.333338Z digest=sha256:1e9764996d9257e61390fa8df20f835897544a97745f266174a4b3fd270a30b3

Observation 9961eabc-da01-4075-8d8c-7ca6e07d3d7a · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

LLM Agents Should Employ Security Principles DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.406934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.406934Z digest=sha256:c2a85967bdfaf90a07b3840a2e074ab9fdb2fe9c04c6e91cc333705e64e8d726

Observation 9efe313b-f1dc-4273-a168-662a114e3017 · outbound

This paper cites RAIN: Your language models can align themselves without finetuning.

LLM Agents Should Employ Security Principles RAIN: Your language models can align themselves without finetuning

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.448589Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:13.445643Z digest=sha256:e00e3438a47dff2ac3f5d579355cbf97650eeda424267a4129a8e7f4609ab301

Observation ef746f30-99ce-46c0-b78d-883f9882a0a9 · outbound

This paper cites Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025.

LLM Agents Should Employ Security Principles Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.310516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:13.503135Z digest=sha256:5c842678b2397f975ea49f91045b2959f8ef37c7b202140d0bed4c885d9d88b2

Observation c56f5cee-ca82-4ebd-9976-a68fe5bcdde3 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

LLM Agents Should Employ Security Principles AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.581416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.581416Z digest=sha256:0c9bfb5e4a6496685293fc1ff5f8bd8199f20904528ded3494330b405030944f

Observation 4ba3acef-79e5-48ee-86b5-c7196eac569b · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

LLM Agents Should Employ Security Principles Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.656779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.656779Z digest=sha256:8c6e5942154d73aea296da661507eaba3b6d5f9da1027bbea735aed659439a78

Observation 94717349-e1fe-4ad4-a098-bb4a1eefcca5 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

LLM Agents Should Employ Security Principles Prompt Injection attack against LLM-integrated Applications

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.736788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.736788Z digest=sha256:aae86b4a5ab6865a583d7debd64f76098f35804298d6c767dfb6a09c92bd6b99

Observation 4076bcf0-2259-46ef-b7b3-4336c42dee73 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

LLM Agents Should Employ Security Principles Formalizing and benchmarking prompt injection attacks and defenses

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.810103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.810103Z digest=sha256:fd74cbad7a2dae855547da91f828f3d77a55f704893f6f97bd5924099282ebe7

Observation 63ce2e3b-8681-4ef4-932a-ae59ee8ac81d · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024.

LLM Agents Should Employ Security Principles Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.058794Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:13.859636Z digest=sha256:b7e4838abc92db1d763a716a4695804aa5fd8cbbbd8c6e7a479e45c19a131d90

Observation 58de7286-4c36-43da-907b-85ec38fcfd78 · outbound

This paper cites Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data.

LLM Agents Should Employ Security Principles Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.926146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:13.934623Z digest=sha256:e01397edc819746025a038e8ee9ef158521878cc7c66e3dec0845e2320006764

Observation 01f8cddd-f5a4-45f6-9135-eaae55082fa6 · outbound

This paper cites GPT-4 technical report, 2023.

LLM Agents Should Employ Security Principles GPT-4 technical report, 2023

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.016657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.016657Z digest=sha256:fdeeac45b22c901e6279b4f82174974b4c93820c07f965c56eab0faf7a2c1b4f

Observation b3203619-4d85-4a8c-ab2a-f8420dd879cf · outbound

This paper cites Optimizing instructions and demonstrations for multi-stage language model programs.

LLM Agents Should Employ Security Principles Optimizing instructions and demonstrations for multi-stage language model programs

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.731074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.102885Z digest=sha256:89cb9451901c68fc28ef764c64fb7919e4f927d61d3a9f07722b581dd133ae8c

Observation b6d67e25-53c6-461b-aa1d-e997e1b703d6 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

LLM Agents Should Employ Security Principles Ignore Previous Prompt: Attack Techniques For Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.183326Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.183326Z digest=sha256:eb573cc13e33f4e07a96416867c1c121cb393d64ebbb905ff701ece8017c570a

Observation 8526a788-4653-4897-8018-f8bda732c331 · outbound

This paper cites The sandwich defense, 2024.

LLM Agents Should Employ Security Principles The sandwich defense, 2024

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.609888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.231663Z digest=sha256:3d8f135a1ea04d9da31ca84cbaa635d4b3505484e404973ec3e13289b8491820

Observation 6a19f497-1e9f-4732-8da4-fc51e0ab031d · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

LLM Agents Should Employ Security Principles Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.391206Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.309044Z digest=sha256:827cc253453c96300eac2d049bc5aa444420baf70ba131b2af6ee125bfb69b35

Observation 39a7815c-9f5a-4977-b7ee-6fcf06d14461 · outbound

This paper cites Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024.

LLM Agents Should Employ Security Principles Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.349072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.349072Z digest=sha256:8ba6a6b3940d1a9fc0a7f27186f68d344c099e6812d2a55577537e7891a7ae14

Observation cf62a05f-e636-4597-af89-a63000ad4fd1 · outbound

This paper cites Improving language understanding by generative pre-training.

LLM Agents Should Employ Security Principles Improving language understanding by generative pre-training

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.458743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.458743Z digest=sha256:018886bf506fc31d021a6585b342cabfdd90c0fe2f63d435d1212d77f786430b

Observation b095827c-cbd0-499c-9369-795dbcd17625 · outbound

This paper cites Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019.

LLM Agents Should Employ Security Principles Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.067470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.532396Z digest=sha256:035d28c5048c1fb84f25e2487b303ac5b476bba297d0da06d18546d379a9f8b4

Observation e92c744a-dbb5-4a26-ab6a-45083317a23a · outbound

This paper cites Identifying the risks of lm agents with an lm-emulated sandbox.

LLM Agents Should Employ Security Principles Identifying the risks of lm agents with an lm-emulated sandbox

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.597041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.597041Z digest=sha256:9d57e739c67d504983e09ffb644d0da93fc4bf990588cbe13b147fe11dd44177

Observation 5ea5a6d0-fd10-4acd-97a8-9e32e13e4d39 · outbound

This paper cites Saltzer and Michael D.

LLM Agents Should Employ Security Principles Saltzer and Michael D

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.926538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.704723Z digest=sha256:5cdff1bda8881d2672fc31d5699b98b46296afee62018dcf9cb7857af66d01cd

Observation 12f99703-4403-4662-8a8c-f52513336761 · outbound

This paper cites Scalable and transferable black-box jailbreaks for language models via persona modulation.

LLM Agents Should Employ Security Principles Scalable and transferable black-box jailbreaks for language models via persona modulation

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.847173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.809955Z digest=sha256:60b38ec1380c94b045e2a2e5e5ee99838ed1447c7a89964a5c72984a88e2e742

Observation 2c2bde08-6264-4a0e-8f08-47e16c10a20c · outbound

This paper cites PrivacyLens: Evaluating privacy norm awareness of language models in action.

LLM Agents Should Employ Security Principles PrivacyLens: Evaluating privacy norm awareness of language models in action

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.711449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:14.862141Z digest=sha256:19a1263ae6e1009bc9bcf01ca15090dbbbb9e108c6bc362729fd584a613d211d

Observation ed2e0c91-b822-4f97-aeaf-90334fe082a8 · outbound

This paper cites Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024.

LLM Agents Should Employ Security Principles Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.965587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.965587Z digest=sha256:d066d3f2496a1499cc68f5eab3d4df94d7e2195589cf869bbc4c385c6eff1f51

Observation 490b3d32-0aaf-4692-91a5-47f4cf418e97 · outbound

This paper cites "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.

LLM Agents Should Employ Security Principles "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.041346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.041346Z digest=sha256:8d2f34287be8ca8769363a6f033a7c87e38ffdbcc9d23bd7c0680e2ce0bc2ba3

Observation 7913acda-421d-4cda-b47a-e7e91e03b39d · outbound

This paper cites Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn.

LLM Agents Should Employ Security Principles Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.568018Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:15.133715Z digest=sha256:2b81e0def8555955991b15da3aa10e037ea8ed1b62dd26f5abf150e01c2403c8

Observation 62a2d446-309d-4e3a-bdec-858410c0b0e0 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

LLM Agents Should Employ Security Principles Progent: Securing AI Agents with Privilege Control

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.258181Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.258181Z digest=sha256:5cead9ce2d96e218b5b2b2426f4bba693c79293a7231c8ed93bc19ec478d5a46

Observation 66496283-4700-425d-8a6a-d96b84f88a3d · outbound

This paper cites Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles.

LLM Agents Should Employ Security Principles Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.340645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.340645Z digest=sha256:577aa588f852fed25b429130abd5741448584b32362df3708e316ec63393e6c8

Observation 7e370c83-7e1d-49cb-bf5a-fd9b142233aa · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

LLM Agents Should Employ Security Principles LLaMA: Open and Efficient Foundation Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.374992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.374992Z digest=sha256:da368b67c92cc8cc5d0d89eb7a90d6d5545b2abad8cd62d67ac334da8030013d

Observation 49bcb3ce-1f1a-4aa2-b8ed-f22c0a351464 · outbound

This paper cites Contextual Agent Security: A Policy for Every Purpose.

LLM Agents Should Employ Security Principles Contextual Agent Security: A Policy for Every Purpose

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.456892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.456892Z digest=sha256:5f071f24ce55227cb3f7b6aca07e1a45e4f157f6be2a5da65ad4689f80677523

Observation ccc84b4b-c405-43f6-a854-5b58edeb97bc · outbound

This paper cites Unveiling Privacy Risks in LLM Agent Memory.

LLM Agents Should Employ Security Principles Unveiling Privacy Risks in LLM Agent Memory

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.532647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.532647Z digest=sha256:e6d26f1ac979214068a7336de1260ae1e297bdadfad06f66a65792f7e034686a

Observation b2416549-9e07-4fe0-a7c2-c50da359fe7e · outbound

This paper cites Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models.

LLM Agents Should Employ Security Principles Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.631370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.631370Z digest=sha256:aa323425b519e964d0887a2f28c724b0ffbbfc8866a099ac21513585d3a09d17

Observation 6e96c548-5365-4c4e-a1c9-ae934e9cf4fd · outbound

This paper cites Jailbroken: How does LLM safety training fail? InNeurIPS, 2023.

LLM Agents Should Employ Security Principles Jailbroken: How does LLM safety training fail? InNeurIPS, 2023

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.471413Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:15.706109Z digest=sha256:6109724951b8ed9e789a94cff7231a82c8399dbb32144075204fa1b2ad2423b4

Observation 002ddea9-086d-45ec-b623-7ae8f92a9849 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

LLM Agents Should Employ Security Principles IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.770833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.770833Z digest=sha256:f0143780f610485e54eaa80df8afa1b7b4256435ca0d5cdfc64622c693529136

Observation 501d3fa2-9165-4f6f-9a3a-612981623685 · outbound

This paper cites Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023.

LLM Agents Should Employ Security Principles Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.297070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:15.848097Z digest=sha256:d2a2b1814d21c608f8c3181f7213e4161fb3d119c73c960a9c2963a5819ea043

Observation 33867e88-cbca-4552-8a3e-9e4b7474d0df · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024.

LLM Agents Should Employ Security Principles Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.919093Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.919093Z digest=sha256:847c5d15e26f1c2182ce986aadef77876613de88053e285c794becacd368bdb6

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:d7cb8b160b7283c4cb622387aa61005b93640ea559fdb9f20b7700c043f637cb

Observation ba5b2bdf-6dcb-42ea-9e6d-51a56a1db8fc · outbound

This paper cites GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts.

LLM Agents Should Employ Security Principles GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.057577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.057577Z digest=sha256:9e0b9740f884261885ade7c406cc6942c03e0048dd60e3e2ccac4ce3ec2570d3

Observation a35ad4c9-6bde-41a7-aa1a-c4a918fbf45e · outbound

This paper cites LLM-Fuzzer: Scaling assessment of large language model jailbreaks.

LLM Agents Should Employ Security Principles LLM-Fuzzer: Scaling assessment of large language model jailbreaks

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.038320Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:16.121597Z digest=sha256:e42fbdb30936d241ac6f5d3523db76b4324b32300e6284eaaba6fd3e4d20b892

Observation 9ecd6738-1a77-4f90-b57a-10e3daf71070 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 68

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.780421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:16.201346Z digest=sha256:d634f7fc6a753f66d490833224efced3c5a04a5486061fde2eb757d6616ce16d

Observation 8971b96f-62de-484e-9f31-5cfc8ebf7e08 · outbound

This paper cites R-Judge: Benchmarking Safety Risk Awareness for LLM Agents.

LLM Agents Should Employ Security Principles R-Judge: Benchmarking Safety Risk Awareness for LLM Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.267748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.267748Z digest=sha256:4d7b450d8c79fbae3e8d37137d7acbb36e39f9dd7dfe0e9b5d34aa31636ad0ab

Observation b55ef027-4d4d-46ce-81ce-066aa0603d52 · outbound

This paper cites GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher.

LLM Agents Should Employ Security Principles GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.601536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:16.345626Z digest=sha256:a40c85ec97c79f1c1a2f407bf6a932b8ac142065cb18343596d85a5b6fe07e22

Observation 5dc51e68-0ae0-474a-82ae-456547c0ebde · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

LLM Agents Should Employ Security Principles InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.461006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.461006Z digest=sha256:56f2de2b0f25d8b602079a8098a2be3c98647ad9ea3ce0c9f3bd54b63c9ec1e9

Observation 8ac99a43-caa9-4b74-a84e-8675f8bc3679 · outbound

This paper cites Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y.

LLM Agents Should Employ Security Principles Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.440904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:16.557915Z digest=sha256:3b082ed3569bde2010427c7a9bf7c705bab2417742550457f1d244a86b1d649f

Observation 4adf505c-776b-47ab-bae3-822d609394ca · outbound

This paper cites Goal-guided Generative Prompt Injection Attack on Large Language Models.

LLM Agents Should Employ Security Principles Goal-guided Generative Prompt Injection Attack on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.635079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.635079Z digest=sha256:39e6eea9908ceb9994774ebcd87f17141724ba2de0023628fcc9a69843549e3a

Observation b10c2da8-b53b-4941-aedf-cac699e19392 · outbound

This paper cites Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents.

LLM Agents Should Employ Security Principles Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.322556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:16.733672Z digest=sha256:3d06d136328cf227bd3ed34f94814a99c9a6e1b8181694bde97fb621d3ce2c75

Observation 6bd88959-2a42-4211-9da3-316e90d52851 · outbound

This paper cites Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction.

LLM Agents Should Employ Security Principles Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.802912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.802912Z digest=sha256:b58870401319a19b35ce88366c5e9ac9031ed36a188c07d72445d98f20865239

Observation 9c4055af-829d-4ce2-946d-b7ff3dcb3103 · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

LLM Agents Should Employ Security Principles Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.878014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.878014Z digest=sha256:2d274432159c9109befad1d74ac0ef01f3f6dd34f3c575589b11685bb873f4d7

Observation b4aec45b-fb05-4462-b4da-1ef170ba4aa4 · outbound

This paper cites Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025.

LLM Agents Should Employ Security Principles Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.979796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.979796Z digest=sha256:25f72cf08a98447a040ae37c37836ff236b91fe8688f38a2bf31530d7254c771

Observation 4755f0c4-0df9-493b-bc87-041b609ba668 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

LLM Agents Should Employ Security Principles RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.059726Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.059726Z digest=sha256:c18c4f0caa34333095b57108c6b1ba42a549f02395868a133d886bdb87577012

Observation f9c6f5a0-b45e-4e3f-b09c-c24ef5337624 · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

LLM Agents Should Employ Security Principles WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.145765Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.145765Z digest=sha256:34753ee5b795693e866350bb5291e01b65a4af617e0066d28a1e23ab7c3b1d08

Observation 4e6c1294-ed3f-4e98-9bd1-d33b70975e5f · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

LLM Agents Should Employ Security Principles Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.234871Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.234871Z digest=sha256:21dbaab43d98fc4b622f7355b58e854fe2f5696dfc4337ecb89c8812fcd62d86

Observation af664236-e50d-4876-a479-04426623bb7f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 81

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.222084Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:17.371158Z digest=sha256:52140cfe788043e8a0cc5cfd27953d0fc9ae2955fa6ad02360620770b90f46ba

Observation d893c327-457a-43bb-a07b-23da90095d20 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 82

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.117728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:17.414088Z digest=sha256:a64b033dde550a6989f87c16b30820e4f8de7a405203d565517b885704f5e169

Observation 6d981ffe-26a1-4e16-a9c6-f9bd07cd4b93 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 83

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.981233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:17.513349Z digest=sha256:ef8351b22219ecd0b05fc80ee392499cd70b0182ac5fe5f7f4071e1e38174ac2

Observation 068bf66b-2211-4c74-a8f3-0b52c326865f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 84

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.877047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:17.692770Z digest=sha256:eae5bf2f69283f3a021b45c6bfc0d89ebcdfe3422a13b2e1df13b5c567d8becf

Observation d0b69c9e-f71d-4e53-8e62-b9548e2a0acd · outbound

This paper cites Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning.

LLM Agents Should Employ Security Principles Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:21.708644Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:17.877754Z digest=sha256:5b78bc315d2f10bf9b13fc0c7a976b718744349ee968442d15c442d4230bcd13

Observation 3379054e-420d-48f9-b4ee-1498a4230ae7 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 86

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.492939Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:18.044792Z digest=sha256:f8d238eae1a6d04449993265cc12e32899fafe28913db0dc7c26b76bb2ed0d7e

Observation fabc4ed9-d310-4eb0-a9bc-e162304cd1c5 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 87

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.276654Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:18.209326Z digest=sha256:bbbb9237b773d8e84a8e32c40880eb83f38d14de2bc73a08b1baf1fcd077d975

Observation a23379ba-d10b-4a84-8488-6a14c06a5562 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 88

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.946610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:18.275656Z digest=sha256:dcc12509a9f342173d4effab225bbff3988e36ac711bca5836269e45f37cc1ea

Observation 3bd0b09a-4f36-4946-aad4-d0ec73c114de · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 89

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.646846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:18.334643Z digest=sha256:ad2c61d82c4650482d1dccf6c18ec790d76419082758b5ec642228a5216fd072

Observation 3586a497-e439-41c5-bcb5-2bfc07e1b6ca · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 90

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.381960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-07T12:42:18.393562Z digest=sha256:64a53827c3a4bc2b99d8e0fc4387317a573e703f4da2cef2eeba5320eb3d8753

Pith citing papers

Observation 16f8fd0f-70db-4624-818d-15468c6f285e · inbound

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks cites this paper.

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks LLM Agents Should Employ Security Principles

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T04:33:17.074410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:33:17.074410Z digest=sha256:5425aa9ef4add925df0c3874759ae47b92b017850a281202941713f020848603

Observation ac2932f3-7626-4f90-8d04-0933120e2807 · inbound

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance cites this paper.

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance LLM Agents Should Employ Security Principles

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T21:22:59.187197Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:22:59.187197Z digest=sha256:92189bb4bb05e809d62098c24a5b1a806e54b4c383c0c40655103ef1b2dfc4b4

Observation 7c43d2ea-12ac-4812-93c2-e9bc600e31ab · inbound

Security Considerations for Artificial Intelligence Agents cites this paper.

Security Considerations for Artificial Intelligence Agents LLM Agents Should Employ Security Principles

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-15T12:40:00.295146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-15T12:37:27.153365Z digest=sha256:f7206c2faeafd9ef9fb267dbe44dfd596dcb8084a9ac207dbb065ae36ef58bb7

Observation 10df942f-6b11-48c7-a27b-d46eaacc960b · inbound

Parallax: Why AI Agents That Think Must Never Act cites this paper.

Parallax: Why AI Agents That Think Must Never Act LLM Agents Should Employ Security Principles

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:01:04.817173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-10T15:13:07.178551Z digest=sha256:2e29202497007910f0be5735fe8c105e06754e00070863c4667cdc78cce08e23

Observation a4819020-cad8-41ab-9560-085e22e71429 · inbound

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents cites this paper.

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents LLM Agents Should Employ Security Principles

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:01:14.315710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-09T18:56:12.400565Z digest=sha256:dbc646212b8feb8c8ce41399b261a7a56e9882df085ab5806cf246c708fea700

Observation e4e679a8-f1a2-420d-a7ab-a670893e7829 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:46:31.792945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-07T02:12:30.086152Z digest=sha256:4010a52c6fa14164945661f8e51afe5897bc0affd43833d918c8cffa9299663a

Observation cb51a1bf-cc9b-4d9b-b170-fe13e60abd32 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:55:44.451126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-08T17:56:09.884837Z digest=sha256:3504d484a36419363571cc2b61533598d4ffa996d765c7c61d0c3787fe10f70e

Observation e4d2c026-00c6-45b8-b140-e16f5678ab00 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks LLM Agents Should Employ Security Principles

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.084545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:7eecd028cd5451b4550cb1ed126d31575b228f98762c420607ce0dcbc0a7c44d

Observation 65f35965-3cb2-4e70-9c1f-4339f87c9b74 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:28:00.169507Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-14T21:23:48.061702Z digest=sha256:9db0030e86513069d572acd1eeeae6822fd3296c7b0cb95d8983e78a9343eac0

Observation f948f307-afc6-420e-b662-4c12c1ff14cc · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-20T23:29:12.644850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-20T23:28:47.424991Z digest=sha256:ddfc6bb6999bd592dc97648492ce5352521c2b80e3224d1d4e82f70e64bd8167

Observation 0d2ef391-5e3f-409c-b30e-6059138001f7 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-03T00:07:27.596565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-02T23:59:14.667099Z digest=sha256:99a38aa9e9af1c9ebbe94d8b394a4ff1fe36bbae3e2d85f5a612914f13581266

Observation 7c7b7853-fdc2-4fea-8023-43dc2990d156 · inbound

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI cites this paper.

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI LLM Agents Should Employ Security Principles

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-02T03:26:29.052170Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-06-28T10:04:44.962968Z digest=sha256:485db6e62e4f2ffd6ba57b260dd185f1bcb8fe4789c51691806c8086de259269

Observation 71e6500c-65af-4abf-8e9d-d28e894d7da6 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation LLM Agents Should Employ Security Principles

Reference 244

Resolution
verified exact
arxiv_id, observed 2026-06-27T13:20:57.050204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:f3f01be6172547a32e8f29cd4cecfba9b2c33be52a71656f093f3e0e7656e137

Observation 90a16c7c-2cd5-4ae4-86c9-ef72ddf6ee7f · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-07-04T18:00:00.381118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-06-25T23:17:58.968269Z digest=sha256:8afdcb630cb55445ae9099bcae8c65a9a82d286bade3c2e9ca2e9de4b84e087d

Observation 32bf28b6-f117-4c6b-8aa9-951c366ffe89 · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-12T12:34:58.460933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T12:34:58.460933Z digest=sha256:de6ceb1fd140ec3d850d6c894a3035b0f9232e2a82e10911bd72c8c3ea64521a

Observation c8d7d5bb-4367-4626-a82c-7e3f4a68c151 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents LLM Agents Should Employ Security Principles

Reference 44

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T13:39:51.356324Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:2e44839472c193713f48f9f8cca6752dc8cdc99535f70ba8e5d343b8a92bcdbe

Observation 58d014e1-8893-40b7-9413-4900eec7ff11 · inbound

Safeguarding LLM Agents from Misalignment through Provenance Analysis cites this paper.

Safeguarding LLM Agents from Misalignment through Provenance Analysis LLM Agents Should Employ Security Principles

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-07-04T01:29:22.001648Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-04T01:26:25.858521Z digest=sha256:cf637c905a87377edeed7449af8dcb54a5a61eac62f5a7a4b14ceaf261706944

Observation 2cc1333c-e2fb-42b6-9c5b-f243dd227d9f · inbound

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents cites this paper.

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents LLM Agents Should Employ Security Principles

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T13:11:53.371921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:11:53.371921Z digest=sha256:db4f4148c7b98348bba9519814528baa66ed150ee62d91502ae6411abdacdba2