Pith. sign in

Paper Citation Record · LEDGER

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

As of 15 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 4 inbound Pith citation observations for arXiv:2604.24118.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2604.24118 v1

Coverage vector

measured 20 of 20 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-08T03:07:21.524834Z

measured 24 of 24 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-10T04:30:17.477789Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T17:47:07.180045Z

Reference resolution

20 of 20 outbound references displayed

  • verified exact1
  • verified fuzzy6
  • unresolved1
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch12

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 38648840-d053-4eb0-be8d-b05dcf8a8c4b · outbound

This paper cites Defending Against Prompt Injection With a Few DefensiveTokens.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Prompt Injection With a Few DefensiveTokens

Reference 1

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:31.049398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:eba17c7e9cc5d9e5fef6ab61a3d85f53ca761d21f4dd4177bc856839867eda82

Observation 6f7c90b8-2c6b-441a-8fe3-e71e38211f9d · outbound

This paper cites https://docs.cloud.google.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization https://docs.cloud.google

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.359110Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:ce0bacd0ea936be6e6d3695632eb260fb4ac3bedaa3191748f779d0d671b8c4b

Observation a98aa8a6-22a5-46c6-9d90-c4fbcc500f1f · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-05-14T22:28:55.556742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:8cd83c93da683b787a7b165a321b25c9ec6db34e143f0513e78965105756a243

Observation e46d2afd-0c0a-4d35-9f59-2d5818011af4 · outbound

This paper cites GPT-4o System Card.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GPT-4o System Card

Reference 4

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.475909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:b831a5778c70d537ac3951fac98a43f6d23abacaa5036a1764c186dd44ca9f0b

Observation 5acdecc0-a3ec-40b9-9e28-78be41ea06be · outbound

This paper cites Promptlocate: Localizing prompt injection attacks.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Promptlocate: Localizing prompt injection attacks

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.056074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:1af4ffab69c1857672cb9c1bae2b7268d348ba56e3b0cd159cc679b2253b8914

Observation 62cb19c6-20ab-4dd7-b231-467f86a45c7c · outbound

This paper cites InProceedings of the 2024 conference on empirical methods in natural language processing: industry track, pages 371–385.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 conference on empirical methods in natural language processing: industry track, pages 371–385

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.353350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:95491602fdc5e3f0d85603d63769ace23766ca55bc98af788bb86124c13d84ed

Observation 0758cb4a-9c1a-4ce4-84da-61f3390ff217 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 7

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.268382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:bd5f827c0a6e8a67d97678383730e0c6a18da5d865921429deb59322a1d2232d

Observation f6f6a1bc-9684-4b1f-b6a5-71b586ac4d02 · outbound

This paper cites In 2025 IEEE Symposium on Security and Privacy (SP), pages 2190–2208.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In 2025 IEEE Symposium on Security and Privacy (SP), pages 2190–2208

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.350682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:38ca4e36384efc07e70b9901d525c14970fce8c9e617b61138d1fbd00f5764f4

Observation 0488dda1-cd25-4591-854a-0876e3cecff1 · outbound

This paper cites The Llama 3 Herd of Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization The Llama 3 Herd of Models

Reference 9

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:30.755496Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:2ae575bd4cabfdaf0ac61834f95a06f70e1b78482c3954feb847411d87951cd6

Observation f4c90596-ae9a-4b7c-b243-ae36149a6b88 · outbound

This paper cites cellmate: Sandboxing browser ai agents.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization cellmate: Sandboxing browser ai agents

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:32.359050Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:b1caba87030776098e32775baa8e24e9316a50a28ce19ff940484ccd5cfebf7f

Observation 37cbf9f3-494f-449a-a4fe-5cfa6f0b6dd7 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Ignore Previous Prompt: Attack Techniques For Language Models

Reference 11

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:32.209358Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:97366be0241b007a8c484359071df86b557b78ec84ade2ccf6cfd6becbf627ac

Observation 27d3cb5b-29fd-4acd-80eb-021290cad666 · outbound

This paper cites 9 Gerald J Popek and Robert P Goldberg.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization 9 Gerald J Popek and Robert P Goldberg

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-11T22:16:29.937787Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:93bba8ad8d831fdf97c0e4439fea377a8f13395a6219fc1bb34dec0b6404a610

Observation dbf93f3b-29a0-4f42-9167-ca6ac4953537 · outbound

This paper cites InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, pages 660–674.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, pages 660–674

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.356257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:8e5da7353120df84a66242d6f217542ce0204b927b3312889712c6b9986a1129

Observation 0d540643-035f-498a-b251-c718ced57266 · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:31.942505Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:b70e8f390f154efffdaa92fbebc91061dd106b65011c42f0dfb164f6e9c41778

Observation 14c31d71-a508-46a2-988d-8d6d77f1f85a · outbound

This paper cites InProceed- ings of the 2009 ACM SIGPLAN/SIGOPS interna- tional conference on Virtual execution environments, pages 121–130.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization InProceed- ings of the 2009 ACM SIGPLAN/SIGOPS interna- tional conference on Virtual execution environments, pages 121–130

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.362088Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:9743c81642abda5c894bda0a6d1c247154db885ac6f5ad6cb330466d19c5f0d9

Observation e50554d4-97a1-45c3-a630-a85f144002b1 · outbound

This paper cites GLM-4.5: Agentic, Reasoning, and Coding (ARC) Foundation Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization GLM-4.5: Agentic, Reasoning, and Coding (ARC) Foundation Models

Reference 16

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.245875Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:2bc0a60d299c497a6a89bede4731c69d5766a213e9ee620a36639bcbc82f573c

Observation a6b9a0e8-0b36-4952-a915-54285597f024 · outbound

This paper cites In Proceedings of the 33rd ACM International Confer- ence on Multimedia, pages 10955–10964.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization In Proceedings of the 33rd ACM International Confer- ence on Multimedia, pages 10955–10964

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T22:23:09.348268Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:0f82986234802ac1e1634563993fcc0e3847b169dc9f7dba1a91c5df8db2a4a1

Observation 51ca2548-2ad7-4fb1-8191-5594169a9fb9 · outbound

This paper cites an unresolved cited work.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-05-26T22:23:09.345363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:87caa97496329f965af5dac4e1a9acb05ae0bd6afbefd9743293996c43f7420b

Observation af9bf477-2843-42a9-acb7-81f110a10627 · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T22:16:30.500382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:4d7622d6af9bc4b934c01d8a65fee7faadacd84806382bce09c8e7c188a19f6e

Observation 6ce32323-bb7a-402c-a512-5d461697239a · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 20

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T22:16:31.675479Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T03:07:21.524834Z digest=sha256:59bd641cff039a881cfb0bd9b0ea93533abb9dd83db2041fd67bfc41d23e2e7a

Pith citing papers

Observation 14d6e910-31d5-4ba8-be7a-354f80c8d7c1 · inbound

Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense cites this paper.

Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T06:40:05.033819Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T06:40:05.033819Z digest=sha256:570863e72d7e6cd2ef5e2d996015defdc06a0a3bdf191cc42d90ff77d95690f2

Observation e14d8970-0c9e-4951-a1ca-0975bdcf0c74 · inbound

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls cites this paper.

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 40

Resolution
unresolved
no resolver link, observed 2026-07-31T17:44:15.652372Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-31T17:44:15.652372Z digest=sha256:5ab06994d2767acdc38e984a20976ee8d4b0ec295956b3fd57d9b0a442d4543b

Observation 75de418b-5408-45d6-b1f7-883193b6c360 · inbound

SkillJack: Persistent Skill Backdoors in Self-Evolving Agents cites this paper.

SkillJack: Persistent Skill Backdoors in Self-Evolving Agents AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 19

Resolution
verified exact
local_arxiv, observed 2026-08-05T17:47:07.244007Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T17:47:06.821776Z digest=sha256:9aa70870f199a8cf6a82f54bdc42308c1bb66765a2f67b3f31cf285c5e3217c0

Observation 5f0beb60-b48e-4f15-8664-142f16e472f1 · inbound

SkillJack: Persistent Skill Backdoors in Self-Evolving Agents cites this paper.

SkillJack: Persistent Skill Backdoors in Self-Evolving Agents AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-10T04:30:17.477789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T04:30:17.477789Z digest=sha256:0db2d51832a3e9043f59f768096a6485d24fb382f91938d35ee1c5d02b85f183