Pith. sign in

Paper Citation Record · LEDGER

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

As of 10 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2608.00747.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00747 v2

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T04:17:02.594840Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved26
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation bb170696-a993-47e8-ac53-8a7eea8e35f0 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Ignore Previous Prompt: Attack Techniques For Language Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.494770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.494770Z digest=sha256:93f40d1619727b191d5f7b1c728078d3d90675a87ebac027584c1d63866a08a5

Observation e51ae8f8-dfe0-4058-aeab-bfe27432df12 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.499370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.499370Z digest=sha256:32ac9d727360e978937c65e723e7aa37da3a7c173ffcb6b927be08f76b0225d3

Observation 7c2b1b60-bd8f-485e-ba4e-d4076050b839 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.503427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.503427Z digest=sha256:210ba6d99a08eadd05257bfd2c436469c6fe5b6808f2df6ff5166f807078b93c

Observation ce38dc26-2af1-4fe8-ab2e-b556bf871fa2 · outbound

This paper cites A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.507970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.507970Z digest=sha256:ecb9ab90437317631c68395fca6916ab8942324c42dd99bb4764235915c64859

Observation b3b9ed97-2620-415b-96a6-711d66e37531 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt Injection Attack to Tool Selection in LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.512504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.512504Z digest=sha256:e869751af9115ac210fe4a55c5543aa90e06b99435f1e35a3d0b14b0e7f2cabc

Observation 558cf644-7c68-49fd-9844-57c81c380287 · outbound

This paper cites Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.516491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.516491Z digest=sha256:ef26ea81c9acfa3029346dc661d71b534fee31416b2d9dce32fdff517d37c696

Observation f5e615bf-34cc-4b35-992c-a4881832719f · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Memory injection attacks on llm agents via query-only interaction,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.520587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.520587Z digest=sha256:3af6a64f3208f8dc32e7fbfc311b036211b25e98d6c55747e81684c0d3ea6df6

Observation b85e4991-a6ec-41a2-ab09-3bd45cd0dd9f · outbound

This paper cites Prompt infection: Llm-to-llm prompt injection within multi-agent systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt infection: Llm-to-llm prompt injection within multi-agent systems,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.524559Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.524559Z digest=sha256:fe9aad486fe0d40fac9585d887ddaefdc8931300f9fb6ce4eff6966e7e7413da

Observation a13f49f7-e8f2-4232-9e0b-09ee727c3222 · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.527779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.527779Z digest=sha256:f07d58181f7726b5c7f1feaba7c5c8fa15b3e7a4b3ab4f14538147243ef261cd

Observation d1181928-a6dd-4bc4-81e2-21c2891f11cb · outbound

This paper cites IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.531826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.531826Z digest=sha256:ba3fbbd9fa69f842bd97852d65d6d20905362f6d3e0584a6a80b51d5acae8b68

Observation df05d453-c18f-46f1-af60-291b8c858210 · outbound

This paper cites Multi-Agent Systems Execute Arbitrary Malicious Code.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:76b95d390a08f6783a67403cdc30692f1ca3dcdda3b95e02535bc86e5dd39825

Observation a261c141-7ae3-4579-b997-dfd297475108 · outbound

This paper cites Red-teaming llm multi-agent systems via communication attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Red-teaming llm multi-agent systems via communication attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.539306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.539306Z digest=sha256:a420395a487a385fd4517fb28262e1a0059cc3826547394503155b494e935604

Observation 8af621a0-4dd1-4298-be2e-110119c99a48 · outbound

This paper cites Breaking agents: Compromising autonomous llm agents through malfunction amplification,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Breaking agents: Compromising autonomous llm agents through malfunction amplification,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.543199Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.543199Z digest=sha256:a7329fb01716247bc964b771b16a954e33d985c4271545040ce16194800151a1

Observation 59e1107c-10eb-4979-88e4-7a47f7bb4241 · outbound

This paper cites BadRobot: Jailbreaking Embodied LLM Agents in the Physical World.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems BadRobot: Jailbreaking Embodied LLM Agents in the Physical World

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.546665Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.546665Z digest=sha256:5b34dbda09cd183bf61d903856322e4243576890dd532a3a3ab7bca05e9b5b40

Observation 92ca83d1-8370-4254-a965-5d995bd50553 · outbound

This paper cites A study on prompt injection attack against llm-integrated mobile robotic systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A study on prompt injection attack against llm-integrated mobile robotic systems,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.550312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.550312Z digest=sha256:de8c88c7981a1185b8dbc907d706c3b3a2278a38885d55b2dc0bf155bb380e8d

Observation 780ac79f-a127-4fe2-a6d8-35f377c52541 · outbound

This paper cites Long-horizon planning for multi- agent robots in partially observable environments,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Long-horizon planning for multi- agent robots in partially observable environments,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.553854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.553854Z digest=sha256:b2ecbff7fd1a126a7314faf34cba59c24268b9cbd7ac88b3946126ed06cf1b8f

Observation b770397f-38d6-4569-a686-d40e456a5ef4 · outbound

This paper cites AI2-THOR: An Interactive 3D Environment for Visual AI,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems AI2-THOR: An Interactive 3D Environment for Visual AI,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.557683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.557683Z digest=sha256:23ee439ec86558d2577f50f801cb5677a1726333bf4d6873f087e9f29213911e

Observation 94a70e48-81f1-47a6-b2e5-c5d52ffe3948 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Formalizing and benchmarking prompt injection attacks and defenses,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.561146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.561146Z digest=sha256:de0acb0acddd2886a07e9053b759eede746d380d421f303aec8d238037495a0c

Observation 5989c688-0522-4bc9-a1f1-35dda94cdeef · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.564492Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.564492Z digest=sha256:1ff0117c570bb8ef1ba143de7423e6fdb9981faf64520bda48167a5e3a5f07a7

Observation c55359a1-2b3c-49f6-9650-7e85313e2762 · outbound

This paper cites Jailbreaking llm-controlled robots,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking llm-controlled robots,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.568841Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.568841Z digest=sha256:b59945b37ba74331ff0dac60fef6478bd8cdb7dddc7a871e361ea0e7b4aea3a3

Observation f0d232bb-7615-44f2-9eb3-c775250afb6d · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking black box large language models in twenty queries,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.573034Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.573034Z digest=sha256:573755903ae16b551567b98077355381aee61ceed2f69b7a5e0a3140d4637db6

Observation ccb795ea-410c-463e-b843-18a3122bd09c · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.576515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.576515Z digest=sha256:059cb035fc1cf4f5a3f3417fe8435bcd859775fb5486ea845d236748d2f2527c

Observation 3a84d894-086c-40ad-9149-71cfca548d58 · outbound

This paper cites Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.580448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.580448Z digest=sha256:b5d0b6f868e91799c1ad060bd468c71eb79f2061163ff7ed4d7815e9afbf887b

Observation f0902229-485e-4fd6-9b20-fbef892648d8 · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.584306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.584306Z digest=sha256:110c5c23f1899ec565acf3270c21aeaa8b08f75e78721ee82611a3aaeaae4a8b

Observation 3b86aa3e-7ec1-4254-bdcd-bd320813b959 · outbound

This paper cites Sentence-bert: Sentence embeddings using siamese bert-networks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Sentence-bert: Sentence embeddings using siamese bert-networks,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.587650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.587650Z digest=sha256:5213c9677cb8dd0a3c830ce5a549b13cb8157300beb4cc194606ecf6dfcd7d32

Observation f4472c28-19f9-4a15-a6fe-6d667a43d765 · outbound

This paper cites Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.591154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.591154Z digest=sha256:507a708d16059493202fb88e6bb3d02c9933c50023e1ce4365befdbde7a1178e

Observation 7b3561d9-29b1-40cc-91cb-e557b307c12c · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T04:17:02.594840Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.594840Z digest=sha256:e442a664a8c2bd8a0ba612062362b7d2a08e0328b5e876227e4c9532533a1354

Pith citing papers

No inbound Pith citation observations are available.