Pith. sign in

Paper Citation Record · LEDGER

Context manipulation attacks : Web agents are susceptible to corrupted memory

As of 18 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 6 inbound Pith citation observations for arXiv:2506.17318.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.17318 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T23:59:59.384340Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-18T06:34:40.430872+00:00

measured 6 of 6 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-05T11:11:40.945299Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-08T00:24:22.457387Z

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy2
  • unresolved25
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6c110de6-a08c-425a-81ed-a4ffc0ed1515 · outbound

This paper cites Agent-E: From Autonomous Web Navigation to Foundational Design Principles in Agentic Systems.

Context manipulation attacks : Web agents are susceptible to corrupted memory Agent-E: From Autonomous Web Navigation to Foundational Design Principles in Agentic Systems

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.633517Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.633517Z digest=sha256:2645daa9caa0d9b729c0706c22c790412bcb68b710d8fcca43f8e957e347ca01

Observation 32db510e-a853-437f-9d8a-d7bde270be68 · outbound

This paper cites Defeating Prompt Injections by Design.

Context manipulation attacks : Web agents are susceptible to corrupted memory Defeating Prompt Injections by Design

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.114750Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.114750Z digest=sha256:72d00387179c3470a808fdaf922b5ad1b6f4f5affa57d17c6a38abf5f5127762

Observation 9c5b76c8-0fb1-40f1-8f00-36e9c8a21435 · outbound

This paper cites A practical memory injection attack against llm agents.arXiv preprint arXiv:2503.03704,.

Context manipulation attacks : Web agents are susceptible to corrupted memory A practical memory injection attack against llm agents.arXiv preprint arXiv:2503.03704,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.199362Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.199362Z digest=sha256:b12dd3a0aa25f32bcce54b8e132140ac91a9172baa850f54fd41f27c62a5d8c5

Observation c1667d30-140e-4145-985d-24abbef7fc40 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Context manipulation attacks : Web agents are susceptible to corrupted memory Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.399538Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.399538Z digest=sha256:bcb6096e3023c5884eac9ec56702291e250356c66e8177aae387d110a60836e4

Observation 7e80cdd0-7a0d-4a06-b73c-57daa70636ec · outbound

This paper cites Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training.

Context manipulation attacks : Web agents are susceptible to corrupted memory Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.453507Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.453507Z digest=sha256:15f5510a02af1df81c9c4b358615abc85ec07050e6badce776aa7d66252a1f46

Observation 7ab7792c-e789-4154-a3b6-519601f1212d · outbound

This paper cites Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.578866Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.578866Z digest=sha256:b73eb980f7c5c21b1ce4cf263b49bc0b3b79f070036be415e913736cf7f4d52c

Observation 22a7d239-5c65-481a-ae70-947d5b649241 · outbound

This paper cites AutoGLM: Autonomous Foundation Agents for GUIs.

Context manipulation attacks : Web agents are susceptible to corrupted memory AutoGLM: Autonomous Foundation Agents for GUIs

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.655062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.655062Z digest=sha256:3b0856e212d31813271610f0d87e3c5faf405e5d74926314343fa5e3aaf1dcdd

Observation c400cb14-701a-429e-8ef4-b3292688f52d · outbound

This paper cites Accessed: 2025- 05-21.

Context manipulation attacks : Web agents are susceptible to corrupted memory Accessed: 2025- 05-21

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:00:00.657809Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-06T23:59:57.753830Z digest=sha256:bdcda8cf68056cfe0218232c151daf974495bf20b4a44ea519786e0ad6305dae

Observation d3b431d1-5f74-4b7d-b0a5-47b2ff5c9453 · outbound

This paper cites Nagli, G.

Context manipulation attacks : Web agents are susceptible to corrupted memory Nagli, G

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:00:00.419469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-08-06T23:59:57.843937Z digest=sha256:bafc8d24207833a2e997750d67befc06a295747e53fa0954210637f5b4c8c48f

Observation 0f711ea3-6b3e-41cf-8876-56db82a3083e · outbound

This paper cites Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In.

Context manipulation attacks : Web agents are susceptible to corrupted memory Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.968116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.968116Z digest=sha256:962267bbf16ad8fe162df47f7caf0a71d2a92b7db1629c101bd72c9a7e5d0909

Observation 97c31c83-b164-4164-8d32-1c6d4c0dcd73 · outbound

This paper cites Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.046495Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.046495Z digest=sha256:4c503b877a0f2d64d0b68915e5cf9d344f62a91faeb6333f06b0ff0d9234e54e

Observation c560ef41-3caf-492b-8d59-6ee5f40b70d6 · outbound

This paper cites Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.150222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.150222Z digest=sha256:e1196f0aba18ebc6761174998f8f9f32b0a2c09b49b3fa81b82aaad07d7b72d6

Observation 854fd232-5147-4956-813f-04f42650ce18 · outbound

This paper cites NaviQAte: Functionality-Guided Web Application Navigation.

Context manipulation attacks : Web agents are susceptible to corrupted memory NaviQAte: Functionality-Guided Web Application Navigation

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.207154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.207154Z digest=sha256:36dbe886e7f0deb4524a5760f584dfe973e77eb823f1a07bd1740e4d9f376b08

Observation e5eb8fc5-f132-4016-a889-12123a376cd2 · outbound

This paper cites ScribeAgent: Towards Specialized Web Agents Using Production-Scale Workflow Data.

Context manipulation attacks : Web agents are susceptible to corrupted memory ScribeAgent: Towards Specialized Web Agents Using Production-Scale Workflow Data

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.320838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.320838Z digest=sha256:098bfceb54a27a1b124729e4637e78740cfba2965aadb577e66da71d3208a7f6

Observation ccae596f-1585-4b59-8a4e-918da8565249 · outbound

This paper cites Learn-by-interact: A Data-Centric Framework for Self-Adaptive Agents in Realistic Environments.

Context manipulation attacks : Web agents are susceptible to corrupted memory Learn-by-interact: A Data-Centric Framework for Self-Adaptive Agents in Realistic Environments

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.476318Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.476318Z digest=sha256:27f7f10df9577253c85ac094abf244f5c0e4492763aaa4a86bdf1fa00d9d40a2

Observation 9a6b55bd-94b3-4536-acde-883b10d6bc7e · outbound

This paper cites Cognitive Architectures for Language Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Cognitive Architectures for Language Agents

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.569340Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.569340Z digest=sha256:680bd22e295100d1e2d539880e705629ea1a198b1cbbb9ca65c4840463373735

Observation 2248a23a-f81a-4310-9ea8-e2998a16f579 · outbound

This paper cites OpenHands: An Open Platform for AI Software Developers as Generalist Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory OpenHands: An Open Platform for AI Software Developers as Generalist Agents

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.681501Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.681501Z digest=sha256:ae12d302ef4fd08516360ba84ebc9c729384309c43c0a3a6d85c957cb8ebf581

Observation 8d6ba60c-0766-45ab-b2ca-771efd58fc12 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.834733Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.834733Z digest=sha256:c4f715db027e1f22ffdaf4d074c8393aecce8c3c2cf4406ef0a3d0ba9d95fd80

Observation 2744fd10-c728-4929-859f-1aba7df71045 · outbound

This paper cites Effectively Controlling Reasoning Models through Thinking Intervention.

Context manipulation attacks : Web agents are susceptible to corrupted memory Effectively Controlling Reasoning Models through Thinking Intervention

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.885764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.885764Z digest=sha256:08ffc8e0051466207b8a861760ba1aa8874e3864c29d8c089e4ff61050d11eae

Observation 62995c05-718c-492e-b6f1-297d1fe614b3 · outbound

This paper cites AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.024265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.024265Z digest=sha256:525dd0cd787a84a9fced21a7ff2b81b16a72418facdcf150da4821421ea9b2cd

Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.158675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.158675Z digest=sha256:5cee1b6997c9b79a2cc7f2850973e6c993d8d1dde620d1c1e464105d99fd46e1

Observation c888e957-68cf-4710-acc6-12e5f1948611 · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.304589Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.304589Z digest=sha256:91bcc57a4d692ca4850e79d68c02512853fd9a15bdb2cad32ec52590dc77ee26

Observation d51fba25-3e83-422d-a8e8-dd541d5accef · outbound

This paper cites GPT-4V(ision) is a Generalist Web Agent, if Grounded.

Context manipulation attacks : Web agents are susceptible to corrupted memory GPT-4V(ision) is a Generalist Web Agent, if Grounded

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.384340Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.384340Z digest=sha256:3f1dd119bdd1449750971059e1e5c72560925faf21f267a8e9f30cc6f9e3261c

Observation 1dcae755-f2e7-4186-a403-9fce4adccbfa · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

Context manipulation attacks : Web agents are susceptible to corrupted memory StruQ: Defending Against Prompt Injection with Structured Queries

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.849987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.849987Z digest=sha256:fe49c866280f0f0ab48a9145eb95169e5dcfe9d9f6ee3e2335ae6ac93952d1c7

Observation dee9f153-8a10-4e6f-ad5b-794bda4ddd19 · outbound

This paper cites WebVoyager: Building an End-to-End Web Agent with Large Multimodal Models.

Context manipulation attacks : Web agents are susceptible to corrupted memory WebVoyager: Building an End-to-End Web Agent with Large Multimodal Models

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.316081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.316081Z digest=sha256:12609d00173d43e817a37447d008ffb133553b396f39383b108cdf01a701f35e

Observation 2a2103e8-0b56-46a2-9c61-afed381238ed · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

Context manipulation attacks : Web agents are susceptible to corrupted memory Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.775981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.775981Z digest=sha256:31d9aade63d997e3b8e930250553a0046ce4ae2645903ee575b166793e6545b4

Observation 0235cebc-d9cf-42b2-84c8-6fa715484961 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.937292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.937292Z digest=sha256:3be996aff897023919d43b653a17728cc79459ffdd9ced7b673671d825fbcd08

Pith citing papers

Observation b0eed74a-d1e3-40ec-8f15-ffd3ad4cb840 · inbound

Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution cites this paper.

Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-15T00:58:26.262828Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-15T00:55:00.205075Z digest=sha256:24cfdf348e13196b2f78bc15ecf284e69fa41d932c690c80d956b217f3a0a51d

Observation 8a349daf-1cd5-4ab3-85cd-5874eca60d1e · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 67

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:21:10.228512Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-09T17:13:47.722098Z digest=sha256:c94d0fdeb40ffa52f2c1ae3bf367af511b3ef60e99579a0e591352132add8187

Observation fb210899-fbf0-4cbf-b4e3-ff2401b488d9 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 66

Resolution
verified exact
arxiv_id, observed 2026-05-19T17:32:41.624005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-05-19T17:30:22.481943Z digest=sha256:6a0d5f6144d406b2c85c9faf64765ed299ece2adad5bb9392f5cb1d6401e2aa4

Observation ab84a808-fa4c-414d-a6ee-ce1b41f44785 · inbound

ElephantAgent: Contextual State Continuity in Agentic Systems cites this paper.

ElephantAgent: Contextual State Continuity in Agentic Systems Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-07-03T14:08:21.374393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-07-03T14:06:04.996981Z digest=sha256:caf8b0cca4367491ad3d5496d4ebbabd45a5220ea792a4f8ff5d49b610d5885c

Observation 235bf3eb-2b0a-4441-a2dc-a1f1b23270b8 · inbound

When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents cites this paper.

When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 40

Resolution
verified exact
local_arxiv, observed 2026-07-08T00:24:22.459420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.

source=pdf_text observed=2026-07-08T00:18:55.016013Z digest=sha256:471b269102559728d9295e69aa4282f18ee1f393d156a6e098e18f34a4ff430e

Observation 88c2e2f8-c8e8-4f19-8a87-23e39c6d2a30 · inbound

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents cites this paper.

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T11:11:40.945299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T11:11:40.945299Z digest=sha256:28d55ab48b75e9ff29d32bcb12deaedbe820c9585f895e47c3bfaa606199862b