{"as_of":"2026-08-17T02:57:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:8625aba09a502a696decbdaa82bec73ce6fad4406184a48cf94a409c1f13a9a0","coverage":[{"denominator":55,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":55,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T11:18:55.535553Z","state":"measured"},{"denominator":56,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":56,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-16T06:30:59.297886+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-01T14:11:22.454449Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.02859","snapshot_observed_at":"2026-08-01T14:11:22.454449Z","title":"Atag: Ai-agent application threat assessment with attack graphs,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.18847","last_updated":"2026-07-21T08:35:22Z","snapshot_observed_at":"2026-08-12T17:59:36.055176Z","submitted_at":"2026-07-21T08:35:22Z","title":"Data Leakage Prevention in Agentic Applications via Preemptive Hardening","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-01T14:11:22.454449Z"},"links":{"cited_paper":"/paper/2506.02859","citing_paper":"/paper/2607.18847"},"observation_digest":"sha256:64ff25713cc46ec2d1c42aa537e20b8ee4c241357e949cc8c4c2e00e050be31f","observation_id":"fda9f30d-6ad1-4477-93a0-57b9274de9da","resolution":{"observed_at":"2026-08-01T14:11:22.454449Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2506.02859/citation-record","integrity":"/paper/2506.02859/integrity","json":"/paper/2506.02859/citation-record.json","paper":"/paper/2506.02859"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:48.674343Z","title":"Language models are unsupervised multitask learners,","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.674343Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:0b249d432b6a258ff5a332a38db1a53df87de06868fd71d86b0b5b86beb50a78","observation_id":"c63fffae-d1ed-4030-9e9e-6550ad9bb90f","resolution":{"observed_at":"2026-08-07T11:18:48.674343Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:48.780703Z","title":"Language models are few-shot learners,","venue":null,"work_id":null,"year":1901},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.780703Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:3b3db01e6ac755699b131608858fb971718a51c4423a16a66b6d107a857177ed","observation_id":"f0441c7a-9c19-4a8d-9f6f-9c8a6a617130","resolution":{"observed_at":"2026-08-07T11:18:48.780703Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2303.08774","last_updated":"2024-03-04T06:01:33Z","snapshot_observed_at":"2026-08-16T19:40:28.523700Z","submitted_at":"2023-03-15T17:15:04Z","title":"GPT-4 Technical Report","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2303.08774","snapshot_observed_at":"2026-08-07T11:18:48.928939Z","title":"Gpt-4 technical report,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:48.928939Z"},"links":{"cited_paper":"/paper/2303.08774","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:9f30102fff735d10469fdd4d902e6af477c5ebdf8dae4bc72462725a38484612","observation_id":"b8eeb21e-2ff7-4e49-a254-245bc5c580ef","resolution":{"observed_at":"2026-08-07T11:18:48.928939Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.13971","last_updated":"2023-02-27T17:11:15Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-02-27T17:11:15Z","title":"LLaMA: Open and Efficient Foundation Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.13971","snapshot_observed_at":"2026-08-07T11:18:49.085249Z","title":"Llama: Open and efficient foundation language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.085249Z"},"links":{"cited_paper":"/paper/2302.13971","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:268f8ed53dbfdc863c7d8062349fa42b3c48134d5bd4b6766343d2df62ce2558","observation_id":"52412f7a-03e4-464e-8fbd-6b9f8f81b4df","resolution":{"observed_at":"2026-08-07T11:18:49.085249Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:05.398213Z","title":"Claude 3 Model Card,","venue":null,"work_id":"7dea28cc-7275-4299-8691-d1070007843c","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.210303Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:817eb17d8eb5f932ce1bfde025f23f07a367ad194b076c15d74ccf5a7870cc04","observation_id":"8c90f604-8042-4f09-b31c-3127cb595528","resolution":{"observed_at":"2026-08-07T11:19:05.501190Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:49.296587Z","title":"A survey on large language model based autonomous agents,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.296587Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:d7c74060a3d768028995e6249f15ddb9fa0d067c1b0890fd5bf7fc50ac9777a3","observation_id":"dc832f8b-ee1f-48c9-aad9-289309528233","resolution":{"observed_at":"2026-08-07T11:18:49.296587Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.01680","last_updated":"2024-04-19T01:15:16Z","snapshot_observed_at":"2026-08-10T13:10:07.804621Z","submitted_at":"2024-01-21T23:36:14Z","title":"Large Language Model based Multi-Agents: A Survey of Progress and Challenges","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.01680","snapshot_observed_at":"2026-08-07T11:18:49.400413Z","title":"Large language model based multi-agents: A survey of progress and challenges,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.400413Z"},"links":{"cited_paper":"/paper/2402.01680","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ce1f7c2d5956a8f33f40e26bffa31bfb9048ac9e5fa0a81ea4bbb83c804666a1","observation_id":"0d6977d2-d81f-4744-b681-e7b6340cf7da","resolution":{"observed_at":"2026-08-07T11:18:49.400413Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:05.175283Z","title":"LangChain: Build AI apps with LLMs through composability,","venue":null,"work_id":"e3efbd19-6082-456f-a03a-4542d9f08687","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.505512Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:601992ef19e8561f44e78d847ab6ad9b8138133e1efcb3cbe310b4c6a7d0e284","observation_id":"58030831-e7eb-46ec-aacb-4950a66418fa","resolution":{"observed_at":"2026-08-07T11:19:05.275361Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.08155","last_updated":"2023-10-03T20:47:10Z","snapshot_observed_at":"2026-08-08T22:28:26.004138Z","submitted_at":"2023-08-16T05:57:52Z","title":"AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.08155","snapshot_observed_at":"2026-08-07T11:18:49.618134Z","title":"Autogen: Enabling next-gen llm applications via multi-agent conversation,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.618134Z"},"links":{"cited_paper":"/paper/2308.08155","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:cae905ec9d81f8f5c548b2b026a8039f79c3d88805d683df1845c4ce461c3614","observation_id":"bbb90895-17c1-4554-9e9b-1c6347d8abfd","resolution":{"observed_at":"2026-08-07T11:18:49.618134Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.951468Z","title":"Mulval: A logic-based network security analyzer","venue":null,"work_id":"257924d1-4565-461b-9f87-7d7d417051dc","year":2005},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.695176Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:2b5ed6e3acf516d6198e27263d65677d14d2ceee9debea54e76cff63a86af28f","observation_id":"75d7ce63-e997-4bb7-88dc-2338a60c56b7","resolution":{"observed_at":"2026-08-07T11:19:05.063110Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:49.820335Z","title":"A scalable approach to attack graph generation,","venue":null,"work_id":null,"year":2006},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.820335Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:dab7fa25528eaa5be4483379df322d4b4de5099e4f2d8b6fff2d0e9d1626c903","observation_id":"e36a6302-7e41-49a9-bb43-389c808f5390","resolution":{"observed_at":"2026-08-07T11:18:49.820335Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.657089Z","title":"From attack graphs to automated configuration management-an iterative approach,","venue":null,"work_id":"e8c303ba-70fe-4b64-8574-b2bb3831bd0e","year":2008},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:49.949489Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:2b0960bfdaee86b8e39420c5ec0bcc53e7a3419280da096cd20e03a7ebde9e01","observation_id":"9c1d6ce0-70b9-4c8c-9eb1-ea9be44002b6","resolution":{"observed_at":"2026-08-07T11:19:04.788938Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.398114Z","title":"Ou and A","venue":null,"work_id":"08634202-4f38-47b7-ad11-fc61a28f0e6e","year":2011},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.147494Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:89d2f229389b6d4c0bda8347a1367017310ad29e45b4e9ef505a225db975be4f","observation_id":"9ca26995-f4bc-497b-ad74-276c25caa19e","resolution":{"observed_at":"2026-08-07T11:19:04.545803Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:04.223626Z","title":"Securing the supply chain for commodity it devices by automated scenario generation,","venue":null,"work_id":"312dc28f-2ebc-486e-8250-daf713225fa1","year":2015},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.298247Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e51808b61c217a7c7a336918ee4e322604a651722ff0ac23fc4028148a3d7376","observation_id":"ed891b79-6dcf-4fd5-8d3c-ad15154cc1d0","resolution":{"observed_at":"2026-08-07T11:19:04.286718Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.957536Z","title":"Augmenting attack graphs to represent data link and network layer vulnerabilities,","venue":null,"work_id":"a33ee8e6-fc04-411c-af97-ce65f1ca7164","year":2016},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.454148Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:f80a2b75040ffefd8b7f83c3a7d78da405389befd41a2b4ad4bf056a6cac5bca","observation_id":"fb3d129d-8a1f-4259-962d-abea7ffe2a90","resolution":{"observed_at":"2026-08-07T11:19:04.067304Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.878767Z","title":"Extending attack graphs to represent cyber-attacks in communication protocols and modern it networks,","venue":null,"work_id":"a2255956-4594-4ee7-982c-8f72e87f505c","year":1936},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.589951Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:9ed3800866b4d00bf76447a791c16aefc7ab31687c416249894884ca2fc74455","observation_id":"ca34c6a1-94b4-4738-9df4-2b095c21ac19","resolution":{"observed_at":"2026-08-07T11:19:03.940406Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.647621Z","title":"Inferring the stealthy bridges between enterprise network islands in cloud using cross- layer bayesian networks,","venue":null,"work_id":"c58040ea-6a84-4eb8-8967-0a4e6bde3b0f","year":2014},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.753676Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ae72cff035f8b7ae818dba74eac90e41e8737d030fdecdfbfbe5191063c03ce0","observation_id":"7052f5ed-fd6b-4c5e-95f2-4c4706160ba2","resolution":{"observed_at":"2026-08-07T11:19:03.766737Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.434681Z","title":"Generation and dynamic update of attack graphs in cloud providers infrastructures,","venue":null,"work_id":"6c893ab0-6dc7-43cf-9a6f-8631457e93a2","year":2019},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:50.940100Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:9b56bb3f9a181de8d8e264f9d0f5368a3727ba4d23d53052c76a0cfbfc7728a4","observation_id":"a680d97c-4469-47f2-87df-c4ed4b50b361","resolution":{"observed_at":"2026-08-07T11:19:03.540924Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:03.152201Z","title":"Computer-aided human centric cyber situation awareness,","venue":null,"work_id":"3b4d55e8-c686-4017-b058-e874bfa8175d","year":2017},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.089724Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:141fbe4e2e01e717766dfc3c7b3c6049550a97dcee4d1bbaa0132812840060bb","observation_id":"f22a145f-8024-4557-b84e-2ac7afba0836","resolution":{"observed_at":"2026-08-07T11:19:03.320321Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.957045Z","title":"Coral: Container online risk assessment with logical attack graphs,","venue":null,"work_id":"7b66fb72-8111-4410-85bf-c146f9874aa9","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.195328Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:a1135d0c0968545f532d90c0e211674efd7433b69732427a90c8a801cb9cce32","observation_id":"17f92936-051d-4945-9947-08347229e2e0","resolution":{"observed_at":"2026-08-07T11:19:03.055511Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.764221Z","title":"Survey of different large language model architectures: Trends, benchmarks, and chal- lenges,","venue":null,"work_id":"0a63925b-5b97-40e3-ae82-830e0c4a214d","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.322376Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:7fa3c8edabf2500f6c476c781d35fbb53f84629f2b5762f0271ff5ea5a449f8f","observation_id":"b049d9b6-b4da-4a18-9e50-d280dd20a4f2","resolution":{"observed_at":"2026-08-07T11:19:02.851632Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.547879Z","title":"LangGraph: Building language agents as graphs,","venue":null,"work_id":"1f9764f6-d470-402f-b2c9-100c93235008","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.464218Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e9f5941583e4be2dee4cfbb30346c5eafd54900c486c1065a2056a857655cbb6","observation_id":"744f0259-4a33-4805-9d8f-8ea278418d29","resolution":{"observed_at":"2026-08-07T11:19:02.643299Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.413609Z","title":"crewAI: Cutting-edge framework for orchestrating role-playing, autonomous AI agents,","venue":null,"work_id":"05b88867-3bb9-4e61-ba6d-868ca0557268","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.577998Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:110adfb78e370e823b13507cd94e4fbb35479b3a9811021cae8519b6bff350a6","observation_id":"e281dc25-700f-413d-b83a-a1f727507a88","resolution":{"observed_at":"2026-08-07T11:19:02.498207Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:02.155714Z","title":"crewAI Examples,","venue":null,"work_id":"c613d129-52cc-4a75-ab5f-7b9c93ed8381","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.694702Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:48bae0b3e562a90dd6ad8a59bc021993ad292e08955eb56bd2df8efbc5a71124","observation_id":"737f5dec-e96e-4a1b-8698-3cc5b7f78409","resolution":{"observed_at":"2026-08-07T11:19:02.276450Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.932141Z","title":"Autogen 0.2 Examples,","venue":null,"work_id":"bbf2aec7-a9b8-4037-89e8-50b59d854ddd","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.831061Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:9d37344e623db83e5c540a20491da54d3206e656cd285cee008b0a45cab773da","observation_id":"f36dea29-b774-4d34-b8c7-d848dd70c2b8","resolution":{"observed_at":"2026-08-07T11:19:02.045953Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.665739Z","title":"LangGraph Examples,","venue":null,"work_id":"cf1aa33f-da79-4237-ad67-d8083cce5bed","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:51.952409Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:8fd5c754bdf7360dce4d7752e540dee0e618954a2f678f62d2cc00147fb1ce5f","observation_id":"973a10ca-a6af-4bb4-ba20-703716346497","resolution":{"observed_at":"2026-08-07T11:19:01.797617Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"8394.37083","doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:56.595793Z","title":"Llm security alignment framework design based on personal preference,","venue":null,"work_id":"8a524519-4d48-40ae-832a-aa54b1aa9634","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.053705Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:d1a61ae8629f50764b8257c38d58c69517df7f36d7727b25468a56ecda0a3f37","observation_id":"f97c28d9-ba4a-41a4-9f3c-cafe4325eb48","resolution":{"observed_at":"2026-08-07T11:18:56.674641Z","resolver_source":"raw_fallback","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.05374","last_updated":"2024-03-21T00:21:14Z","snapshot_observed_at":"2026-08-02T17:09:20.540788Z","submitted_at":"2023-08-10T06:43:44Z","title":"Trustworthy LLMs: a Survey and Guideline for Evaluating Large Language Models' Alignment","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.05374","snapshot_observed_at":"2026-08-07T11:18:52.176666Z","title":"Trustworthy llms: A survey and guideline for evaluating large language models’ alignment,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.176666Z"},"links":{"cited_paper":"/paper/2308.05374","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:6c80b414deb4ccc4c69e0cb6de37e0087b5e5c5c9eb363faacf14116cd0c8846","observation_id":"5026185b-a223-470a-bde8-d2f84acca9a0","resolution":{"observed_at":"2026-08-07T11:18:52.176666Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.423983Z","title":"Jailbroken: How does llm safety training fail?","venue":null,"work_id":"07c927b0-ef1e-4502-8026-de909774ca46","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.289961Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:63863b675ab0ac899f7ee7ea1e88c3cf5d6ce941a0e1a08eeb1f7639b100da63","observation_id":"ab045007-7e8b-439b-9cac-ca931c546b99","resolution":{"observed_at":"2026-08-07T11:19:01.520593Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05499","last_updated":"2025-12-29T02:25:27Z","snapshot_observed_at":"2026-07-06T15:40:27.639368Z","submitted_at":"2023-06-08T18:43:11Z","title":"Prompt Injection attack against LLM-integrated Applications","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.05499","snapshot_observed_at":"2026-08-07T11:18:52.408113Z","title":"Prompt injection attack against llm-integrated applications,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.408113Z"},"links":{"cited_paper":"/paper/2306.05499","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:07cc6f748aab5b84349803ea54bed3610ad40883717cc785c0ac3618d491e1cf","observation_id":"cd262355-7ecb-434e-b300-facc1e862685","resolution":{"observed_at":"2026-08-07T11:18:52.408113Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:01.179855Z","title":"Universal and transferable adversarial attacks on aligned language models, 2023,","venue":null,"work_id":"f80d4d75-2923-44c2-80b7-5fa814b2bd82","year":2023},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.543147Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ca2b07be29142ff47ee6a0f9ca02f8e4218ad9a9a167c9e6da300a57cfdac644","observation_id":"394989b3-4609-4313-93d3-dbd905f88339","resolution":{"observed_at":"2026-08-07T11:19:01.274640Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.04769","last_updated":"2024-03-11T01:21:32Z","snapshot_observed_at":"2026-08-16T14:17:55.443137Z","submitted_at":"2024-02-16T17:02:53Z","title":"Using Hallucinations to Bypass GPT4's Filter","version":2},"cited_work":{"arxiv_id":"2403.04769","doi":null,"metadata_source":"pith","pith_arxiv_id":"2403.04769","snapshot_observed_at":"2026-08-07T11:18:56.242164Z","title":"Using Hallucinations to Bypass GPT4's Filter","venue":"cs.CR","work_id":"f617f7bd-7a00-4a17-b930-7de74e801ab3","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.685303Z"},"links":{"cited_paper":"/paper/2403.04769","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:27ec0758a682b93053311384a86a5c841368158b2f38ac674d3bae875a46b9ac","observation_id":"f2f97a6d-e7a4-4b73-8754-fdce16afb0ef","resolution":{"observed_at":"2026-08-07T11:18:56.369783Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:52.842202Z","title":"Why are web ai agents more vulnerable than standalone llms? a security analysis,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.842202Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e16420b7c9f6c8dba3fe8122e6583751909d3ba8621eddbf09a6e5d37f0e26d5","observation_id":"d3d5875b-538e-4ed5-9955-c2dd2783a3b0","resolution":{"observed_at":"2026-08-07T11:18:52.842202Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.947283Z","title":"Causal knowledge analysis for detecting and modeling multi-step attacks,","venue":null,"work_id":"916580e1-7a5d-495e-984d-0fd95d50c580","year":2016},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:52.943526Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:ce1874002ba6760202218baad73a9e9b49b77444efb62bf86d4b4a55d5370025","observation_id":"26c41731-6142-4277-a271-023708ecbe4b","resolution":{"observed_at":"2026-08-07T11:19:01.055292Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.737877Z","title":"A survey on the usability and practical applications of graphical security models,","venue":null,"work_id":"2f3678e6-5025-4fad-ad15-0b1d5caaa10b","year":2017},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.076098Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:8c253f94a04ac0d0e9ecb6bc18ce750248d9e8a923997c5d78024a052c341e8c","observation_id":"b72fb89b-26e4-45a5-8c75-d37c8c5f91c2","resolution":{"observed_at":"2026-08-07T11:19:00.836113Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.508798Z","title":"Ou and A","venue":null,"work_id":"627d03de-e0ed-4a92-b1b8-d4783cb19d8a","year":2005},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.200626Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:727fdfa8a7fa98adb59180ff331254639b7fb2e5e057c96600452a296448dfb4","observation_id":"107e4ee6-1d28-406b-8ceb-2957d8356f20","resolution":{"observed_at":"2026-08-07T11:19:00.596910Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.261161Z","title":"Automated vul- nerability testing via executable attack graphs,","venue":null,"work_id":"b58b06d4-aede-468e-a2e9-d37d329ee718","year":2020},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.336873Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:0faab9962d729027ad81b57b5618431d287252bc8ccb5158f4105c216cdb104d","observation_id":"0340ff0e-8e21-4ea0-9853-0eaca49fa59c","resolution":{"observed_at":"2026-08-07T11:19:00.389908Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:19:00.018745Z","title":"Cvss-based multi-factor dynamic risk assessment model for network system,","venue":null,"work_id":"115b600e-deec-44e7-816c-0eaffcda217b","year":2020},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.439201Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:518a05a40ae199091c8da941fb36a2def689bafa46048da393731e7f2f5599b2","observation_id":"6f5ef271-20c2-48a4-a4a1-bb8344c9138e","resolution":{"observed_at":"2026-08-07T11:19:00.118295Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.785806Z","title":"Overview on attack graph generation and visualization tech- nology,","venue":null,"work_id":"2958d992-0fd4-4043-96d0-bdd7136f8b5c","year":2013},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.565165Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:5603485da3f49e8933d8bb275de523901089d448ba5c2a72d0a1e53fe305eb45","observation_id":"8e023437-6ee7-4f2b-a3a3-9aa68bcc67ef","resolution":{"observed_at":"2026-08-07T11:18:59.919064Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.579207Z","title":"A systematic study for understanding the security risks in 5g core network,","venue":null,"work_id":"b0cf8590-42e6-4d25-afbd-72da95fd656d","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.677352Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:69fc71f37ea2d09c1a20b79abd76ab893fb63aac8764267ecd21b8e7ea44decd","observation_id":"3ff6e752-ae18-4c06-869b-921f484d4299","resolution":{"observed_at":"2026-08-07T11:18:59.658367Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:59.286286Z","title":"Enhanc- ing cloud security: harnessing bayesian game theory for a dynamic defense mechanism,","venue":null,"work_id":"9c69631a-19d8-4fbf-a709-4bf45c2460c6","year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.815590Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:7620f19e26e7810724685fe6abaae17e0b194649af7e54000a59d881b3dcfcd5","observation_id":"135c28a2-c368-4f18-94c5-4658954f7861","resolution":{"observed_at":"2026-08-07T11:18:59.418218Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.963459Z","title":"Atag github","venue":null,"work_id":"4902238b-ff8b-4a04-a533-eb5783d398ab","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:53.949879Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:96d663e02db60384b497813545822110751aab308cef79ca65e8a622ed95e4e1","observation_id":"c29b7d07-9891-428b-9c74-e6ad86fd1174","resolution":{"observed_at":"2026-08-07T11:18:59.116565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.697068Z","title":"2025 Top 10 Risk & Mitigations for LLMs and Gen AI Apps,","venue":null,"work_id":"47bc776e-fe01-430c-b3d3-b4a11adb9ab0","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.086895Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:f3dd344a1a1a2f8da907517f4e5c84ebe1012f29010daf9bd57b3af7d56b7837","observation_id":"6a595c34-9ec0-4150-8066-00df3113ebb0","resolution":{"observed_at":"2026-08-07T11:18:58.832636Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.411935Z","title":"Mitreatlas,","venue":null,"work_id":"1972cdf4-e48c-4517-b5b1-3343ad752da1","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.185800Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:d268b29f282a03e2086f080b31e62e1f0a9c83dff20b0c64af12fb45923ac6e0","observation_id":"7fe77ffd-87e1-48b1-8153-7dda9c42c55c","resolution":{"observed_at":"2026-08-07T11:18:58.542050Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:54.317343Z","title":"Phantom: General trigger attacks on retrieval augmented language generation,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.317343Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:826a1f67f77ef569d7554e7ef1ed47fc54781b61226b502ac93d2f7bbba02f4d","observation_id":"cb7c81c9-2456-42f3-812a-6013554acc27","resolution":{"observed_at":"2026-08-07T11:18:54.317343Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:58.185163Z","title":"Common vulnerability scoring system","venue":null,"work_id":"afe1145a-d12f-40f5-94ab-e3bc1f99245e","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.424936Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:6cddbe0d702509138da7bfd3ce9d7edbeac68a536ed9798905e961a9196279ba","observation_id":"1b1aa1d1-a073-4bb0-b593-ebfd6dd7ba3e","resolution":{"observed_at":"2026-08-07T11:18:58.280792Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.02151","last_updated":"2025-04-17T18:55:45Z","snapshot_observed_at":"2026-08-16T14:04:12.947538Z","submitted_at":"2024-04-02T17:58:27Z","title":"Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.02151","snapshot_observed_at":"2026-08-07T11:18:54.543727Z","title":"Jailbreaking lead- ing safety-aligned llms with simple adaptive attacks,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.543727Z"},"links":{"cited_paper":"/paper/2404.02151","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:003973d85df2645f37190f6a09707e6fbaa908c9b169ecd76b572a3acf4a2908","observation_id":"080c9ed6-9cea-443b-bd00-606e4f4b2f51","resolution":{"observed_at":"2026-08-07T11:18:54.543727Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.911689Z","title":"AI Risk Management Framework — nist.gov,","venue":null,"work_id":"48044aee-1a2a-40bb-a018-f9b638346d00","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.705115Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:3ae5e0f79e2eb4316e8a00afeb7b9a1732989446119fcb346b3010ddbb092d5c","observation_id":"75c3a190-74af-4973-acfd-1220aa554ed0","resolution":{"observed_at":"2026-08-07T11:18:58.034126Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.664544Z","title":"Agentic AI Threat Modeling Framework: MAESTRO — CSA — cloudsecurityalliance.org,","venue":null,"work_id":"e80eca4e-3110-4fe9-9f51-53e9181513c3","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.857644Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:57f45a3f5909ddd310f9ecff20fa1f0e0941cad3981ec8feee534239d31f54b1","observation_id":"26232291-d5ce-4c88-add4-95eb535d2d64","resolution":{"observed_at":"2026-08-07T11:18:57.780054Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.406188Z","title":"OWASP Foundation, “Announcing the OWASP LLM and Gen AI security project initiative for securing agentic applications,","venue":null,"work_id":"22b2f219-dc1a-45e2-b799-826ce0776aa3","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:54.966005Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:59666ae4f1acf13c7ce4f87347404f89e2bbefba351c818c6c46e2310ec89888","observation_id":"f4d9ccbd-ee4c-4137-b36f-c2ecaddcf7d7","resolution":{"observed_at":"2026-08-07T11:18:57.508429Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:57.124299Z","title":"OWASP Foundation, “Multi-Agentic system Threat Modeling","venue":null,"work_id":"4cb91113-74bd-4f9c-8ccd-c15e5bdbb6b8","year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.076607Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:6b5180133f9058ec4b8ff68d7de4d7a1ca001306a43e2e329e9454509002a789","observation_id":"695d0d10-e310-4e95-8fda-47e227773647","resolution":{"observed_at":"2026-08-07T11:18:57.283991Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:56.889850Z","title":"Securing agentic ai: A comprehensive threat model and mitigation framework for generative ai agents,","venue":null,"work_id":"74c78a80-af21-4221-9e54-1dcb4a515b91","year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.201783Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e777eb1331b67c31a0d66fd0a5ca4fae9a8d1ecb1e45f84de9b8b3b510ab2745","observation_id":"21677672-78a3-4468-b639-9b31e9097eb0","resolution":{"observed_at":"2026-08-07T11:18:56.992001Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T11:18:55.402038Z","title":"Doomarena: A framework for testing ai agents against evolving security threats,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.402038Z"},"links":{"citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:e1d1fc6b9b1ce0d010f3372c7d0f97e40943d7c4af47b0a72a56ff6b84fbcc25","observation_id":"184e8ec7-0c5a-4199-9d12-ad870582ed6c","resolution":{"observed_at":"2026-08-07T11:18:55.402038Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2208.05750","last_updated":"2022-08-11T11:00:40Z","snapshot_observed_at":"2026-08-16T16:39:47.261231Z","submitted_at":"2022-08-11T11:00:40Z","title":"A Survey of MulVAL Extensions and Their Attack Scenarios Coverage","version":1},"cited_work":{"arxiv_id":"2208.05750","doi":null,"metadata_source":"pith","pith_arxiv_id":"2208.05750","snapshot_observed_at":"2026-08-07T11:18:55.740028Z","title":"A Survey of MulVAL Extensions and Their Attack Scenarios Coverage","venue":"cs.CR","work_id":"de6fd7bd-e959-4566-aebc-e19ad2085c28","year":2022},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.535553Z"},"links":{"cited_paper":"/paper/2208.05750","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:c9ce5dadb1722aa1f413fa9b9d3378808502a07bb3509b9041b4b63b2a50b652","observation_id":"a5dbbb8a-78af-4542-801c-9905d3d87043","resolution":{"observed_at":"2026-08-07T11:18:55.845485Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.19956","last_updated":"2025-05-02T18:42:42Z","snapshot_observed_at":"2026-08-16T05:36:44.756300Z","submitted_at":"2025-04-28T16:29:24Z","title":"Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.19956","snapshot_observed_at":"2026-08-07T11:18:55.303303Z","title":"Available: https://arxiv.org/abs/2504.19956","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs","version":1},"reference_index":2025,"source":"pdf_text","source_observed_at":"2026-08-07T11:18:55.303303Z"},"links":{"cited_paper":"/paper/2504.19956","citing_paper":"/paper/2506.02859"},"observation_digest":"sha256:904277c2577c62d258a4046ac71194acb1a9abdeea4a1e599ec826dd1792d9c5","observation_id":"bca5b16d-1e19-4cbd-8de6-ca1af8db510a","resolution":{"observed_at":"2026-08-07T11:18:55.303303Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2506.02859","last_updated":"2025-06-03T13:25:40Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-08T01:20:02.750987Z","submitted_at":"2025-06-03T13:25:40Z","title":"ATAG: AI-Agent Application Threat Assessment with Attack Graphs"},"reference_resolution":{"displayed":55,"state_counts":{"malformed_identifier":0,"metadata_mismatch":1,"parse_uncertain":0,"unresolved":15,"verified_exact":2,"verified_fuzzy":37},"total_outbound_references":55},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"thesis":"As of 17 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 1 inbound Pith citation observation for arXiv:2506.02859."}