Pith. sign in

Paper Citation Record · LEDGER

Prompt Injection 2.0: Hybrid AI Threats

As of 14 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 4 inbound Pith citation observations for arXiv:2507.13169.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.13169 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-11T04:15:53.991771Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-22T12:51:33.393440Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact2
  • verified fuzzy1
  • unresolved25
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation e22e7f76-32cd-4cb3-869f-3183830e0afa · outbound

This paper cites Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples.

Prompt Injection 2.0: Hybrid AI Threats Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.088522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.088522Z digest=sha256:e46a91f0d3182eca111e8ee2fe6d5db0a577e8ccf93f51534bfe9f9b5a2387ed

Observation 28fbf030-816c-41ff-903c-2df09f0a7f9c · outbound

This paper cites C., & Heichman, R.

Prompt Injection 2.0: Hybrid AI Threats C., & Heichman, R

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T16:34:08.065627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:03.214886Z digest=sha256:e728571c1ee46815ec1f9ef5ca195ee01fe3b7e7cc41eeda431a5ba1b587b4d0

Observation 4ba24e3f-f487-4b02-a626-63b6ad009055 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Prompt Injection 2.0: Hybrid AI Threats Prompt Injection attack against LLM-integrated Applications

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.313953Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.313953Z digest=sha256:8dd024ed2f09a79438c50ff7529ad4f63ab369f15244e2f11ea2cce0d500be07

Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.407180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.407180Z digest=sha256:091623aa5ba40edd2242ccc871fe25e47252600473465935041ad535826cfa13

Observation 2c8e481a-6979-4c1e-91d7-eb514330e081 · outbound

This paper cites From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?.

Prompt Injection 2.0: Hybrid AI Threats From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.503194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.503194Z digest=sha256:4dcc81ca340ad344476ca0287c3517a299178a033e822e749e13d9fb5680b5b7

Observation 81b7056d-e92d-4262-a83a-cfadff70051b · outbound

This paper cites AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development.

Prompt Injection 2.0: Hybrid AI Threats AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.402350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:03.624743Z digest=sha256:774dee1206d42f3c00ecb32e8acb4effa5e55c9ae7538b039ef9b7a477307e42

Observation 74108fff-12a9-4135-8e67-a6a18bca8085 · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

Prompt Injection 2.0: Hybrid AI Threats Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.695223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.695223Z digest=sha256:38b0b673d710e7cc272b7a4d71d5065a7784389c2ec64c7021d75dc99975be5e

Observation 9ffcd4e8-6f3c-4856-9cce-4421416681fa · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 8

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.818080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:03.778176Z digest=sha256:b295e2899c7b90e92b323e0b04cac17bf4370867407498cf1e7739dc012a1c08

Observation 67a374ee-c085-4de3-abb1-fb82d9c1fefe · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Prompt Injection 2.0: Hybrid AI Threats Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.842222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.842222Z digest=sha256:a6aa356c25d31bc8c7ac2d1ed18ba38969d80e7eb4a1e5fc87132273f12fd110

Observation 7f4cdc41-655f-434b-9be2-a74bc3172ba9 · outbound

This paper cites Defeating Prompt Injections by Design.

Prompt Injection 2.0: Hybrid AI Threats Defeating Prompt Injections by Design

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.919189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.919189Z digest=sha256:9c76384ad68c63215e21063958e2641652b9770db9088b380ca50df1d57ba233

Observation 1c073cff-1405-48a5-91aa-b7a78fc582b7 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 11

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.505229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:04.001119Z digest=sha256:e6110e885783f0a391c7793dfbdd35c5577f38c2d76678e39427b99bd3949dc9

Observation 43d9d6d4-67cb-4608-89d9-d5c6532faf25 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.307622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:04.096370Z digest=sha256:73ec0a7739477b908dc6d473bfe44f3d12a2a0192121b0844276601296f34b37

Observation 0c024737-d7c3-4a78-9b2f-f2c999750230 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 13

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.022398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:04.192243Z digest=sha256:205b09a4bc540a6e8ee66fda58d72230ec8b53be24c1b9b24687c60abfd7e210

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:c9813eca25087cc53f7779571de281ebb417ef44d6f8ae49d56b3251c66c6525

Observation 932b69ab-e882-49e0-a697-a9bbcf822bb9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.877652Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:04.375475Z digest=sha256:498a34c40fd6f476932518af88e1336197663ef18ac7feebd02e0091e0ad75d7

Observation e379a488-61be-486e-b10a-30e052f70bbd · outbound

This paper cites XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants.

Prompt Injection 2.0: Hybrid AI Threats XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.094966Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:04.450450Z digest=sha256:d389f88915e8af6e8810175b66229bd77aa8627b154e99c5cb436ee9084554bb

Observation 97ca63c5-25a5-4980-94cb-1c29107c98e0 · outbound

This paper cites The Hidden Dangers of Browsing AI Agents.

Prompt Injection 2.0: Hybrid AI Threats The Hidden Dangers of Browsing AI Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.510763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.510763Z digest=sha256:8135ec83823591b446947830b58c76e9bd64266fdb6c2ce2f3b1ec39e52bdf7e

Observation 48ce344e-7e62-45bd-8d86-18374023e328 · outbound

This paper cites Learning to Poison Large Language Models for Downstream Manipulation.

Prompt Injection 2.0: Hybrid AI Threats Learning to Poison Large Language Models for Downstream Manipulation

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.598552Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.598552Z digest=sha256:b14c0174c497855ca92addaf61d692eca86143c5eba6adcad2100c387e1a616b

Observation fb31b710-e5d8-497a-9bb8-b335be88601d · outbound

This paper cites Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.667309Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.667309Z digest=sha256:d696f984967a7741e9cb7c8bd7f25537f491cc1cc10d8c8cd0662253c8b7503c

Observation 8a60a853-a16d-4b30-beb5-e095804b0e30 · outbound

This paper cites Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.754226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.754226Z digest=sha256:5ec842867836052fc2a5c0f52f1c5698a69310978b9dc77303256c6cb930ef20

Observation fbe5eca5-fc2b-4390-98d2-c32b7d9b82ac · outbound

This paper cites Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.853306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.853306Z digest=sha256:267d92be784724e1f55ea4986859b305ac57ee9fed8480b0063256bc2e02d369

Observation 2a247095-3659-4852-b88a-22fed94a42b8 · outbound

This paper cites Manipulating Multimodal Agents via Cross-Modal Prompt Injection.

Prompt Injection 2.0: Hybrid AI Threats Manipulating Multimodal Agents via Cross-Modal Prompt Injection

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.952025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.952025Z digest=sha256:9addd34ad8d27a2402721da039b1b783fdd0bd6e4ea33bd368985d5540c87eae

Observation 6514fbca-975f-4253-a587-05efbc389ff9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.771915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:05.011939Z digest=sha256:60887cc5bae0f110bfd363f0f6ec89549ad1d5715d7b9ab6bb3ebc8eca5419e3

Observation 80107157-42c9-4510-a17b-5ec0990ce669 · outbound

This paper cites Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs.

Prompt Injection 2.0: Hybrid AI Threats Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.101373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.101373Z digest=sha256:b4557a5448522183ea7843d7dd20a995fb3851b67497f55a4c16070f35870b4f

Observation 711b04e6-a84a-4b06-8648-54f847ee47d8 · outbound

This paper cites Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition.

Prompt Injection 2.0: Hybrid AI Threats Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.169846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.169846Z digest=sha256:5b78f1ced6079572e11c2e4cea9d48a519fd40512dc398334ffb11dc9f35c78e

Observation 901f6257-6605-4160-b812-d5c36cc18a4a · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 26

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T16:34:06.657603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-06T16:34:05.255867Z digest=sha256:b4504405a7cdb916bc9ce671d8f26e938a88ed7ed63e1254fd8c49ff691d0032

Observation 53d2c546-ea9f-4636-bf87-72f6c0317db7 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

Prompt Injection 2.0: Hybrid AI Threats LLM Agents can Autonomously Hack Websites

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.325342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.325342Z digest=sha256:aada63ee5a66b7b678e6cff63456055a1d280775a15d40686aa8e034ae3732d1

Observation 4a6efbb7-8971-44ae-aabf-67ad24ecb2ae · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.379319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.379319Z digest=sha256:f25e2cee146574c21f6144ecad0dded1b141ebdc43a367aa69543724c8f2a83b

Observation 8a6b4405-be54-4aaf-bad0-de88deabf587 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Prompt Injection 2.0: Hybrid AI Threats Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.446734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.446734Z digest=sha256:476f385d6e0a1f0f9164f1fd79c5aaea04e8cf058190af350f2d3b764e74ce42

Pith citing papers

Observation e5e416d9-e605-440c-b626-69eb3f50bd19 · inbound

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities cites this paper.

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Prompt Injection 2.0: Hybrid AI Threats

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-18T18:06:43.025006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-18T18:04:09.528381Z digest=sha256:3413ca06d4b77e25482d6c9eae5b8c7acc851b130e80b4b05d4edc9eda9a5354

Observation 406e2f80-5836-4e26-8605-0a1161a23245 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Prompt Injection 2.0: Hybrid AI Threats

Reference 61

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.431852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:8737ed6d8ca7327fe11ed9263207975d6d1623fe75341270c835dee4342c188b

Observation 621df737-31d9-4a80-9d4e-e92f691c623e · inbound

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation cites this paper.

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Prompt Injection 2.0: Hybrid AI Threats

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:51:33.396810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-22T12:46:44.819224Z digest=sha256:ea02b3531fd7b75f8e7ce1e2f405cc902557944004fa0020233e901c768f15e0

Observation 3e6f750e-bd37-43e2-be17-717b63583de1 · inbound

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis cites this paper.

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis Prompt Injection 2.0: Hybrid AI Threats

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-11T04:15:53.991771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T04:15:53.991771Z digest=sha256:cd1f971a3b9d3e6f7f76e4be57bc5ee232fd8a733ba9888c15ad4f834e06ae6a