Pith. sign in

Paper Citation Record · LEDGER

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents

As of 14 August 2026, this Paper Citation Record lists 69 of 69 outbound references and 0 inbound Pith citation observations for arXiv:2607.14651.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.14651 v1

Coverage vector

measured 69 of 69 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T01:34:16.274037Z

measured 69 of 69 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

69 of 69 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved69
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation efb1544f-4945-4656-b4e8-d9142f5b2b0c · outbound

This paper cites GPT-4 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.350835Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.350835Z digest=sha256:905b648a5e6753c38a6ef81aaec606ae10312bcc244cf0aa7aa89074b62f2cfa

Observation a16b1393-4bed-48d8-a45e-8dfb1a9a37d1 · outbound

This paper cites Security in LLM-as-a-Judge: A Comprehensive SoK.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Security in LLM-as-a-Judge: A Comprehensive SoK

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.462689Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.462689Z digest=sha256:b249130cbbe3009807e9f905f3a0b09eef44d2c4a120d9dfa4f554f5adb6e5f9

Observation 02f83907-c1ef-45eb-a03b-56d8ef9170db · outbound

This paper cites Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.573233Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.573233Z digest=sha256:b53f3520b87193f2d3b472ff3bc804dc1e2f0ca1c0e37b0a9944d863ea7b5e76

Observation 23885b22-d53c-4feb-a2c2-3214076d8a0b · outbound

This paper cites One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.633226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.633226Z digest=sha256:7da3e3ab76c0fd3bd1bc45ae74b4cca40fb0187ad85fc4fa9fa0c137eace1875

Observation 899b38ee-2629-4b4c-b43a-835346108d79 · outbound

This paper cites {StruQ}: Defending against prompt injection with structured queries.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents {StruQ}: Defending against prompt injection with structured queries

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.702664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.702664Z digest=sha256:d115ab41dcdcf146a2b128df99be052c758bf6477ce02b3f2d5bc2b8d4925b82

Observation 7500767e-94d2-45fa-b1f7-0b16d9e7e005 · outbound

This paper cites Defense Against Prompt Injection Attack by Leveraging Attack Techniques.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Defense Against Prompt Injection Attack by Leveraging Attack Techniques

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.793732Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.793732Z digest=sha256:5ef31e52120555f1faa63d53279e1a1668d99ef22598961d704b1d92fcb0381e

Observation fb56b482-d5b2-45c1-8983-a331492f9308 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.887486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.887486Z digest=sha256:0f10715ec561035a92a5d59608b0c39884e6ed6a0502f7ca309e4b73d51946ba

Observation 55026f67-9df0-46e6-a444-49abfc50e492 · outbound

This paper cites Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.994388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.994388Z digest=sha256:f5d72ffe575141c3362f92802ff5ce941bb06f857c5a3ee3386406b646957c11

Observation efc735da-d2f6-41ab-a156-335d952c04aa · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.059236Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.059236Z digest=sha256:acbee80b359136a673984b6388d161e76780e2f9925bf94b2f813f905ba1273f

Observation c120fc0d-d989-4756-b503-0bd6675f7431 · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.167616Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.167616Z digest=sha256:0db07e8e514cee2db7a8917680e73c71daf206dbe4cb86ab8e090687d80f5ff9

Observation 16582e86-54e5-40b3-aaec-3d6c699ee57f · outbound

This paper cites A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.271092Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.271092Z digest=sha256:556ca151a9ab498bd60be80b4e5426a51b211d6449b5776578b3787ee2d980e8

Observation c0b78879-f55a-49a5-b2f3-82b9cba460b2 · outbound

This paper cites Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.368923Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.368923Z digest=sha256:7b55370ebe24678d53d356f1f96d4fa6859c331cdcce0699ff67174d4a091000

Observation b52b464b-ad90-4bc9-a7c8-1f005b15d842 · outbound

This paper cites Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.453299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.453299Z digest=sha256:93061614ac79a116894f6ac0886a29231f81e7934627e9b5f8b493d9ffb90fd9

Observation 83c2cbb1-59ac-4a51-8518-4b3fc2388519 · outbound

This paper cites ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.541857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.541857Z digest=sha256:3b1b7515020bc0812758af25094329afa30a2a370458f9934c94e788c7ca9306

Observation 8440165c-5f2e-4d67-a00c-9f88677dacda · outbound

This paper cites Gemini api documentation.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Gemini api documentation

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.611404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.611404Z digest=sha256:77706a4bb0ef8e59dc84dd860aacb406384b33aecc82db272d00a850e1fc6160

Observation 059abb50-3316-47b0-a20e-74ededbc0ab1 · outbound

This paper cites The Llama 3 Herd of Models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The Llama 3 Herd of Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.671967Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.671967Z digest=sha256:c832276cb9f5e6ed7db2ad8dcd98b61713d70e1b60f278bf448c6794f04aedcb

Observation 2ec1c44d-63e1-4917-8d9f-61c102c43e99 · outbound

This paper cites A survey on llm-as-a-judge.The Innovation, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on llm-as-a-judge.The Innovation, 2024

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.776015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.776015Z digest=sha256:aae565c9a42a34ad5f7eb012d0e652d46844a757b977b3dd92c624775eebca91

Observation afa007e4-dfd9-4410-9512-eba3d15c3ffb · outbound

This paper cites The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.831346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.831346Z digest=sha256:ff8ea3bb9c539b56a274c084e90336d48e54e1660d1fb4f50dbfb45b26a94f19

Observation 0b553bd3-21fc-473c-9d75-8839b2b7c32c · outbound

This paper cites Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.887333Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.887333Z digest=sha256:225861fbbf23e310a2b7671c961cdd3a48eb8fae26f0aabaa2d2d860601ba2b6

Observation 82fcbff8-f1e7-481f-964f-cad1ddfca6a6 · outbound

This paper cites Retrieval- augmented generation with estimation of source reliability.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Retrieval- augmented generation with estimation of source reliability

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.951513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.951513Z digest=sha256:903211aadd9de600908cc197f174e4c00683f06fd54733f56b8037ffc7d21932

Observation 02c2249e-63c4-4c56-85f9-fddacacfac84 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.996715Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.996715Z digest=sha256:585efee161cb8cc04fca981639c8a9b0608a36f7362b3c7a1fe8819ca9dfc511

Observation 82c12249-9869-49e3-af51-8748428f3423 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.069663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.069663Z digest=sha256:4b491744077fbe28e814847c7cb522199e1b0a7af2d6223d1619fd085fc8bdd8

Observation a7e9a3dd-8055-45bc-b155-a4f2613bbed2 · outbound

This paper cites Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.160512Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.160512Z digest=sha256:05bcae1e0ad45ab7087480038a64e77f3f917f5efecf2742554d7ef44d2c51dc

Observation 4f54209b-39ae-4118-8ba6-1a9d344c7a2e · outbound

This paper cites Memory os of ai agent.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory os of ai agent

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.223600Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.223600Z digest=sha256:0ffd274a7e9e51b70c9e24d5859e2d3746a4006179090367f2958875d95875f7

Observation 6ca8f49f-5d36-498f-aaf9-9beb9e4c8a40 · outbound

This paper cites Certifying LLM Safety against Adversarial Prompting.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Certifying LLM Safety against Adversarial Prompting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.280395Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.280395Z digest=sha256:4b3728d910964bb9dd6dbc96b4a189cd78946a59e9a863f4307d5fbd98877e19

Observation bf7399f4-f221-4ddf-a3eb-ba67ebea20e0 · outbound

This paper cites A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.340723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.340723Z digest=sha256:21b0c6b74f1d68df791a874e955460d098e29674cbcd7b34615b1802ca1fa8a8

Observation 43fadf10-30fb-4f29-b8d8-6bcd5169fb13 · outbound

This paper cites DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.398735Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.398735Z digest=sha256:58eb239dd91adb381f30bdeabe913ac0046f1de3a48760f8509799039ed368c4

Observation 293ca6f7-b29d-41c7-9bfd-71b0100d51d5 · outbound

This paper cites DeepSeek-V3 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V3 Technical Report

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.457582Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.457582Z digest=sha256:17485e278e7beb4e6240184becf2f783d04a0a2072f7c380817fafdb569789d8

Observation 87fafa08-223b-4569-84d6-8ec1e5486ee0 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Formalizing and benchmarking prompt injection attacks and defenses

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.522427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.522427Z digest=sha256:e8b393fdd0837c8cde08fe51a23cb222250664aae5e9d5203a4436702862681f

Observation 346e16d3-252a-4336-9bdb-d4cc6974ce70 · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Datasentinel: A game-theoretic detection of prompt injection attacks

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.614142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.614142Z digest=sha256:99417af809d1576369760c318818ead6decdc99f4fa75dc3191d8bd3ff4ecd9e

Observation 16249de5-45d1-4d97-b630-bd34820475e4 · outbound

This paper cites Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.697836Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.697836Z digest=sha256:6601f7774ffb85a19a5b8c4d6700e4eeb0b4e7a95fa5aef0c1267b9a7b750505

Observation 579581fd-396e-42e2-a371-16af1cc54dd4 · outbound

This paper cites Prompt-guard-86m: A classifier model for detecting prompt attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Prompt-guard-86m: A classifier model for detecting prompt attacks

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.754997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.754997Z digest=sha256:dbe2aa3a91413d13f314b3b26d9de2f23a4578ee3bc2d9b75aafc7280c830174

Observation c7f9ee4d-815c-46a7-9c18-3ea70c40d69e · outbound

This paper cites Towards lifelong dialogue agents via timeline-based memory management.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Towards lifelong dialogue agents via timeline-based memory management

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.819294Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.819294Z digest=sha256:df908793d8ab888ef8836513b6d3c8f68be19003cbaa811a65f0af6cf8c38bce

Observation cc4ee84f-140b-499e-b585-63e6d0cc97db · outbound

This paper cites Memgpt: towards llms as operating systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memgpt: towards llms as operating systems

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.873849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.873849Z digest=sha256:f1e7359ce9bb8c2dbf41329abb70d21d468c670dcdd730ee1a612199c021d546

Observation d27938c0-b181-402b-95a3-9da8334ed102 · outbound

This paper cites Generative agents: Interactive simulacra of human behavior.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Generative agents: Interactive simulacra of human behavior

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.936398Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.936398Z digest=sha256:663c37317574aa8b20746a7d83f0a29a330d47b9e4c0fcbcd9a213e283b46051

Observation 849b30c4-d735-4143-ba6d-9f15ca477d56 · outbound

This paper cites The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.976036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.976036Z digest=sha256:9faf19469f61d89acbca117762ca49935a0b73cfad25f3bc1d1e462c7f703186

Observation 362c6fdb-3e3e-4d7d-b9aa-48d86805e5b1 · outbound

This paper cites The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.062003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.062003Z digest=sha256:49cc15b14632046ff6d3a8ed0015dd153eee982b14fd74959920f1792a0164bb

Observation 9fd0ca62-34f2-4e1b-808b-0bcfc5047ac1 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.121949Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.121949Z digest=sha256:f379ac9a270b6d660a80ede8779fa1b3fe3e68b3e3b9cd1a9b4262af545e3b9e

Observation 52db8d48-94bf-45bb-94b9-deb16acafb7d · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.201286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.201286Z digest=sha256:af8dd4bd2395e97b7a3fff740ff707d21bf2f377a9318f25a59e0a33abcaad66

Observation e868fda4-cf0d-444b-9bd6-e666565699c6 · outbound

This paper cites Evaluating Memory Structure in LLM Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory Structure in LLM Agents

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.248312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.248312Z digest=sha256:b71c20644b91108ac187948cde9132226431b01b5d238f113c73328ca07d7347

Observation c1b06b0f-111c-49b5-b599-615b192fd5e8 · outbound

This paper cites OpenAI GPT-5 System Card.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents OpenAI GPT-5 System Card

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.314535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.314535Z digest=sha256:71b321d4a2e1c053836bbdfeca02350fcbe5ac69086b92c05bc069ce7ed80c8d

Observation 10b60ffa-218f-4542-8754-7862088de365 · outbound

This paper cites Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.426621Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.426621Z digest=sha256:783914fd3dcf6854bc273a50a11b8e6f18dfebe7a0b8d3ee2f5bf12c99164319

Observation b71f3248-c4b8-4034-961e-497c3c4634a0 · outbound

This paper cites Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.590292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.590292Z digest=sha256:ab411dc934f863b84494017390d4f883c3d6ba5dfd26c6366c9542ec337cd634

Observation a5e3e748-0d2d-4e75-8c52-dd05a557b735 · outbound

This paper cites Membench: Towards more comprehensive evaluation on the memory of llm-based agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Membench: Towards more comprehensive evaluation on the memory of llm-based agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.917754Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.917754Z digest=sha256:1eebfa8c194d0040d923509a24db56dac5c7ecb9cdf94219c1a4a88be4f159d1

Observation 92944e81-a041-401b-8bb5-220526e741ed · outbound

This paper cites RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.121805Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.121805Z digest=sha256:2ad0896505978de6be68d7bc2b73e441252beb4106ef538248cd1a8a7673922f

Observation 5a3a6e97-80e6-46e1-b767-4a1ac706cc97 · outbound

This paper cites In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.276252Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.276252Z digest=sha256:b885d94e988188e2fee0cb61c6a50c3f28f501c015591adde10bca18ddb2d6d0

Observation 047b3bea-3a53-43f8-b81a-d196d496aa46 · outbound

This paper cites Injecmem: Memory injection attack on llm agent memory systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.530907Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.530907Z digest=sha256:d0f4faf53f7219d76fb1a6d58a3a549a402f7456fcf9b603961fd618b70d5794

Observation 80a9a459-ee93-4e71-8f5a-86718df94357 · outbound

This paper cites Injecmem: Memory injection attack on llm agent memory systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.705785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.705785Z digest=sha256:5324c437707058b8943c7222e882238336d02b1347d39737def2ac75306b485a

Observation df01ad7e-7082-4b78-b5b4-ef1160df2dcb · outbound

This paper cites Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.873278Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.873278Z digest=sha256:b284e06582a572a0c1d705ebe02febc27fcdf8a52dfb1c8bb697cfb4836413e3

Observation c5f1adff-74f3-42b3-8aab-02e0106ad9d2 · outbound

This paper cites Unveiling privacy risks in llm agent memory.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unveiling privacy risks in llm agent memory

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.048192Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.048192Z digest=sha256:702b068f9752505a67d3fd8ec3fafc8fc361378532abc0ef10aff041469bca5b

Observation 876712ef-fdda-4d18-99f1-5e966dce468f · outbound

This paper cites Badagent: Inserting and activating backdoor attacks in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Badagent: Inserting and activating backdoor attacks in llm agents

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.211428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.211428Z digest=sha256:98895b8723ea5b7a61d5fcb3fd382af518eeaf2ad78ee99338f3c3ac40dc67f6

Observation c3e2e727-36c2-4e6f-8d96-777960f3524b · outbound

This paper cites A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.466738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.466738Z digest=sha256:d44e1cf54ea390acc5d0e491961e0c2a3cbd7029987c94f29a55748d9f2b7f66

Observation 82b6d6ba-3647-4f94-b88b-14bc2e4e6090 · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.714004Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.714004Z digest=sha256:23c11a6c2d8e2e00ee6745308b59a6495ae4b5f92be092a7758aa7d3361e3321

Observation 6515615e-6a8f-4969-b4d3-e622d0e6c7f9 · outbound

This paper cites TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.888330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.888330Z digest=sha256:181948f8501b8bb1912acb4de51d77a62894737927c228d0c6ced2a48bbc3c5b

Observation cc7fd6a9-b07f-41db-9747-5a38fc858013 · outbound

This paper cites Qwen3 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen3 Technical Report

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.040513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.040513Z digest=sha256:7929afc8fe8c2f9929961bfc62f3c73c076c53179992b917e38f0555873cff98

Observation 7108c89a-f2b8-407b-a2c8-bc0c1e275ef2 · outbound

This paper cites Qwen2.5 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen2.5 Technical Report

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.185128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.185128Z digest=sha256:bbac9d5caab16c81994c06f4ec29c70ecf3fc81eb63f2d928a7051717d577bf7

Observation b9f9abd6-c324-4231-9331-7a2829d983e2 · outbound

This paper cites Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.324713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.324713Z digest=sha256:b372e106db998b77810478dde0d5510aaae0ea88cd022fae38625f6265958214

Observation 03afb3c0-344e-426a-97f4-dc452860c5c2 · outbound

This paper cites Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.394297Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.394297Z digest=sha256:b3f5102509cf39ce5ffe8da1d9133fe20571ca39a210ce3a80b7fb8bcf5abc84

Observation 8fb362eb-347a-4ab8-8738-19a31ef43ab1 · outbound

This paper cites Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.468500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.468500Z digest=sha256:ce40f20c1ef3ab1604e85eb936c7bdd35dd42ac94aa20325ddae2d7cf3881c2b

Observation 24de91c5-82a8-4523-8f3c-da6301a92f30 · outbound

This paper cites $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.551445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.551445Z digest=sha256:72229d429593efe2438e504553b5db0d04b8f1cca7473689c893c9ffd8c02c69

Observation e4219fa4-fa52-40af-9e37-97625fbcc785 · outbound

This paper cites an unresolved cited work.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unresolved cited work

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.637578Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.637578Z digest=sha256:8d542cad917473d34271be22380b9288536c89daa73075696d836dba1c3ef1a7

Observation f0618914-3d92-438a-abbb-8906a7a2e0f0 · outbound

This paper cites A survey on trustworthy llm agents: Threats and countermeasures.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on trustworthy llm agents: Threats and countermeasures

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.701912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.701912Z digest=sha256:97effa1766fe75faf23b3090046912b4546861868daeefd0b6c26ef142a7bdcf

Observation 3cd06f6e-8d1a-4ffe-822c-7ccfb03ddae0 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.780493Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.780493Z digest=sha256:dfe3cf11f95fe9aa0dcaf189a1529488d4fa0e0b604552e91b3df335abfacf54

Observation 07bce797-16cb-4213-b2ba-8a92532579f1 · outbound

This paper cites Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.854510Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.854510Z digest=sha256:82ae3a9749e56629002c9065819f2a6d5f1f118aa4b877a41ab21755673e8b0f

Observation 56c1e3e7-ccbc-4a82-9b88-1c7ee188afd6 · outbound

This paper cites Traceback of poisoning attacks to retrieval-augmented generation.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Traceback of poisoning attacks to retrieval-augmented generation

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.939036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.939036Z digest=sha256:5b6976952e58a8c0a99a98500551d2cc4bda7ae165dd21f98d23ef56cad283e8

Observation 5f5d9c08-2fe4-495f-bbb6-56a7c896eafc · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.008911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.008911Z digest=sha256:8245e8c834dd2d297ae159b0400298f02cdef067de76683941dde44aafe2cfb1

Observation 9cc15a56-5bf4-4b03-a668-3bf0cee45f8e · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.107470Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.107470Z digest=sha256:33705c6fba597c519e8cd05b2d3741ee385a9f06cf3125f23009c07479f4d9c7

Observation 39fe3ff0-ba5a-4d15-be70-f549458eed3c · outbound

This paper cites Judging llm-as-a-judge with mt-bench and chatbot arena.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Judging llm-as-a-judge with mt-bench and chatbot arena

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.185613Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.185613Z digest=sha256:36f91a899e6b93b0f0ff64ca92abb08f25ced1c41cf9ce66c4e07ae4bd1f3506

Observation b2a5ba85-6a29-48de-bcc2-04b52117f3b0 · outbound

This paper cites Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.274037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.274037Z digest=sha256:110e7bba21db5b4e847e7b561a6dbffb9adf8374da26537756f39fd674f9cc5d

Pith citing papers

No inbound Pith citation observations are available.