Pith. sign in

Paper Citation Record · LEDGER

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming

As of 17 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.05108.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05108 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T05:11:49.315668Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact0
  • verified fuzzy26
  • unresolved28
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ce8157a8-3198-4805-9f11-09358257bf05 · outbound

This paper cites Ignore previous prompt: Attack techniques for language models,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Ignore previous prompt: Attack techniques for language models,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.154237Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.154237Z digest=sha256:3e243b239271f62306df5635adac4df7e350d484c674fec1aba96dd38e2645f8

Observation f2f22714-4efa-45ed-94b5-9bd9f4957670 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.781256Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.267686Z digest=sha256:f68e8d8c4eeffd387daf99555b814fc043e8934682d3251b1ce036b043243915

Observation bd61774f-d9cd-4278-95d3-dcd980725294 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Formalizing and benchmarking prompt injection attacks and defenses,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.674740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.327186Z digest=sha256:6be2c17cc4d4df84ecf790feecf2b51356afc2f64a28a55ee7ad7131593ea9ba

Observation 76d5a701-c412-4fe4-a7c4-3195dff7f224 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.473490Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.414814Z digest=sha256:c6ad899d5485df13dc0e572cc78ba05c556b195fc4520722d0fc04fd4c580f24

Observation bde26fa6-ac1b-4460-aa32-edc540ebccec · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.289540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.463507Z digest=sha256:4297983b919b22b84710b69c10fb4814e1939251ec0f7b478a7c9e80d99fb19c

Observation 14016feb-d5b0-4dd6-b8ab-4c41d96bc745 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.495675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.495675Z digest=sha256:91c248c84bd8db805f46f31e8eb297b4d55be6b700c2930b3de263496e6c3b02

Observation 7c719ede-b99a-4713-8f57-90f3d7c72b39 · outbound

This paper cites Muse spark safety & preparedness report,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muse spark safety & preparedness report,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.149686Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.604178Z digest=sha256:18901002fdbb713ae86dd70f1383b8c398216f2469cf21d1e2de0c4d2765abc2

Observation 16083f83-3eea-4cce-ac70-1f620f990eab · outbound

This paper cites Claude opus 4.7 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.7 system card,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.015812Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.676598Z digest=sha256:a29a942fc41207534826327237dc4b4d83e2ce62c7fe0f104749b2dddde8d513

Observation 23e69e23-13f4-44f8-a68b-54603f45fa10 · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Datasentinel: A game-theoretic detection of prompt injection attacks,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.853663Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.725244Z digest=sha256:52049fdf3b6dccdd752952f103b9e4b681174369bb2d7f8d5cbd85e8bbb12dcc

Observation a610dc2b-5572-47b4-ba4c-9b8222a28ea6 · outbound

This paper cites PromptGuard Prompt Injection Guardrail,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptGuard Prompt Injection Guardrail,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.674204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:45.794378Z digest=sha256:8a77f14a000c50e5e813f050f5e6b43eac73d2fd068560c804e33836cb47981c

Observation f1bf1c37-421f-42e8-a85b-5263240f4e08 · outbound

This paper cites AgentWatcher: A Rule-based Prompt Injection Monitor.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentWatcher: A Rule-based Prompt Injection Monitor

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.854500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.854500Z digest=sha256:41f8ba303603df9cf3f79675772ee4fcb449930683c93c4c8cc953a685e64aa6

Observation cb5317d7-a23e-4772-8e0c-cd71d6462d0b · outbound

This paper cites Meta secalign: A secure foundation llm against prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Meta secalign: A secure foundation llm against prompt injection attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.943166Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.943166Z digest=sha256:0fea37bf78072a7241a8ad74822566b474a148bb074c26b918edb5d9f1a2043f

Observation fccb7cd8-214d-4419-9e71-61df4f9a1633 · outbound

This paper cites Purple-teaming LLMs with Adversarial Defender Training.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Purple-teaming LLMs with Adversarial Defender Training

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.995659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.995659Z digest=sha256:cbddd918b260e725c644be3307a6ba8855f3a57c68e4d4c638b7f27bd4712c56

Observation 128eff0f-a175-4f43-85ee-a0e8d2807bf2 · outbound

This paper cites Black-box red-teaming of multi-agent systems via reinforcement learning,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Black-box red-teaming of multi-agent systems via reinforcement learning,

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.546133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:46.063263Z digest=sha256:3a873c6358dd9fe6cbd47a1900f8e0a4cd6b19286fe23e5d84f392cc3cf70a63

Observation 1506dadd-4cfc-4288-87d3-46cd75cdeb52 · outbound

This paper cites Learning to Inject: Automated Prompt Injection via Reinforcement Learning.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Learning to Inject: Automated Prompt Injection via Reinforcement Learning

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.111393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.111393Z digest=sha256:ecf40a1f205b6d7f2ce9f1a1d62ecfa25bf2f12c3396c9c5ef4ff292ce556703

Observation 6058760e-f676-4eeb-be9d-2d872b0e74d7 · outbound

This paper cites Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.203274Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.203274Z digest=sha256:19a591da067bfe0b91d186dc575c909c6a59aa63ca85433124a54b543643e92f

Observation f8e5973a-ec6c-48b5-8515-b3a7e9413797 · outbound

This paper cites PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.310041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.310041Z digest=sha256:363c251a7c7dfaf47dab76e8f97df0f418b47918bad8a76ccea538c0043e1d51

Observation 40477b0a-9b12-4a28-bfe1-36da9440ec23 · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Tree of attacks: Jailbreaking black-box llms automatically,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.382227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.382227Z digest=sha256:0a765ad6cf52da88949301e6d7e71304cb617e4f61f90d640a966c8b6e1cf7e7

Observation 7986393b-053b-411a-9513-0af5e38c9095 · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Jailbreaking black box large language models in twenty queries,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.449184Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.449184Z digest=sha256:66a0c8dd737a8194373cef9dc032ad2cc249dec06dd411b2d85c55078e74a27b

Observation 8b07b5e7-5bfc-4f94-a98d-05a9ccd7b76a · outbound

This paper cites Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.370992Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:46.532386Z digest=sha256:f13fcf58e0e4ea02ce3d18a25f5cb738d84e7d7a9bd8d9441b6210a1006ac8c2

Observation 975147fa-4954-4812-8b14-8f12eb3df08d · outbound

This paper cites Piarena: A platform for prompt injection evaluation,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piarena: A platform for prompt injection evaluation,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.198269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:46.588128Z digest=sha256:742849e4e92513529c62719f2174d3aee78da209fffbad8111e5b902b21c63f9

Observation d4dae2ee-2ff0-427c-83aa-68f923b3ab64 · outbound

This paper cites Gpt-red: Automated red teaming via self-play at scale.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gpt-red: Automated red teaming via self-play at scale

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.032827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:46.654896Z digest=sha256:35cada0ec47747cf30e562cc5ba88886dfa0a92c4bb24d70431c8a3c587fa2b2

Observation 6b1bbc84-dceb-4cd5-8669-4c88c9828352 · outbound

This paper cites How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.711658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.711658Z digest=sha256:52640db50a0f7f2c26a3242c1ee8be960ccac2a5aa087ca77ceab322a4e8f850

Observation f286f7ff-181a-40e7-8e00-de6f0b86b501 · outbound

This paper cites Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.767256Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.767256Z digest=sha256:95bad41c4e8cc02b448cd92f84ff6a2f029f8f8c6dfa28a3cd0dd8104f6dbbb4

Observation 66b2b30e-52df-4521-8173-9b09574fa6b6 · outbound

This paper cites Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.785109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:46.906206Z digest=sha256:b6accbc75c8a5568c37ef01ec1fc1c6e55a6c6623b1bf6e24eac9676edfcbb83

Observation 773492fa-d159-4a91-b778-4d6aac32070e · outbound

This paper cites DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.996106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.996106Z digest=sha256:40c223c1818342458a0a6ab75d3e449e83140307ab7d51baf809a3011f5f5830

Observation ef34a227-74f2-469e-9719-296058853a8b · outbound

This paper cites ReAct: Synergizing Reasoning and Acting in Language Models.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ReAct: Synergizing Reasoning and Acting in Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.055268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.055268Z digest=sha256:797c329fc6efacfb4c33b66a0b1a87575e15f3cf561df3e2725a3de2911940f9

Observation 83da0063-c6d1-44d6-ad44-f293bc8c0929 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Toolllm: Facilitating large language models to master 16000+ real-world apis,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.496789Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.096713Z digest=sha256:edcdbe61fa8b423d69ec71a2ad8ec6b4c01df485dd9b38303d5abb28a8adeff6

Observation e32db511-3395-4a05-b2f4-daa3e63dbbf3 · outbound

This paper cites Autoharness: improving llm agents by automatically synthesizing a code harness,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autoharness: improving llm agents by automatically synthesizing a code harness,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.164645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.164645Z digest=sha256:1d35f914fafa3d1073b830d7a2342bf395dd319a4911d81206b263e1f87ec41c

Observation 3e3a3567-d74d-46e1-965d-21c61d8ce21a · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Multi-agent Architecture Search via Agentic Supernet

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.247014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.247014Z digest=sha256:7dbaabf6547d1a56af3a91f87fed08e1a94f8b1214638afbb636aa898e341dd5

Observation 554b4a78-c0c9-49bb-8e1c-30dc5a1c2eaa · outbound

This paper cites TextGrad: Automatic "Differentiation" via Text.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming TextGrad: Automatic "Differentiation" via Text

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.342591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.342591Z digest=sha256:a791c09129890dc6871816e49c993484c5d9b358195c5e0b41afc94ee4f152ee

Observation 3c0af994-60f6-4303-96f5-c5a3d88969e6 · outbound

This paper cites Test-time training with self-supervision for generalization under distribution shifts,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Test-time training with self-supervision for generalization under distribution shifts,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.272634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.402594Z digest=sha256:251d12362a26a5b8c6ca144fcf3e6e1811378cc8f1ef205286aebbc1af553754

Observation 4761427b-17af-4cfc-94f1-f0fe0af33f58 · outbound

This paper cites Gemini CLI: An open-source AI agent for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gemini CLI: An open-source AI agent for the terminal,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.073223Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.493187Z digest=sha256:5b57ef805fa645a3cbc2f8c03ed92d1c00c5cb91be0b8ad11089bd7731586f03

Observation 5a1b9b39-aa08-4a74-b822-af031cc6d786 · outbound

This paper cites Codex CLI: A lightweight coding agent that runs in your terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Codex CLI: A lightweight coding agent that runs in your terminal,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.825124Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.564559Z digest=sha256:a65fb1e344243688b987d6dc7c8087a9238517bea09ce26d8517c77673a5c070

Observation b8b85a14-c728-4f94-8f93-c37e7e3f8b8d · outbound

This paper cites Claw code: A clean-room open-source coding-agent CLI,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claw code: A clean-room open-source coding-agent CLI,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.561952Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.614225Z digest=sha256:86fe0f2f81a3fd9a1a14219546d80c99e267d2a6fe0c14c2221bffdecf5ad5db

Observation c49965f8-9100-48da-8537-c1ebcda2ae54 · outbound

This paper cites Hermes agent: An open-source self-hosted autonomous AI agent,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Hermes agent: An open-source self-hosted autonomous AI agent,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.262640Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.654480Z digest=sha256:19dcfe6a85af6f31b9e851fb5b27453f8c8016336b3e50401c46300420ba0934

Observation 72716773-1290-4acc-85d2-783456d67671 · outbound

This paper cites Claude code: An agentic coding tool for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude code: An agentic coding tool for the terminal,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.011248Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.694271Z digest=sha256:21e16de324f2c96897dbb9be05843420c8ad74da17bb92179fb0b350bac1e604

Observation 03c25b03-505b-4056-9caa-f7d8060cf3a2 · outbound

This paper cites Attention tracker: Detecting prompt injection attacks in llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Attention tracker: Detecting prompt injection attacks in llms,

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.823611Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.764775Z digest=sha256:a244c028f76598520f4f2d88dd9caa1ec61242d9c1a21a33c27db7e51a02853b

Observation 6bf302bb-3a4c-4b99-9e42-3f29ecb6f5dd · outbound

This paper cites Piguard: Prompt injection guardrail via mitigating overdefense for free,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piguard: Prompt injection guardrail via mitigating overdefense for free,

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.534030Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:47.844255Z digest=sha256:ccdec325c054cec6366e3ba585ca541ded998a517152bb37d6dd9f403a78e938

Observation 4c31e5f5-4e0d-4b42-9b48-68ca1a65e058 · outbound

This paper cites Pishield: Detecting prompt injection attacks via intrinsic llm features,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pishield: Detecting prompt injection attacks via intrinsic llm features,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.884895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.884895Z digest=sha256:c98fd99d8651cb252c958679fa56060eba33e182789c185e0f4b3a994fc223b0

Observation b87c2d68-6b1a-4788-97cb-a45d674b1b06 · outbound

This paper cites Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.889944Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.889944Z digest=sha256:9f6bb883e9ee653b3324c5e44336c9a67c46819a3a2eccd18c5d480ab793f8c9

Observation 407bed97-eabb-4702-8561-0b84d15625bf · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.970675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.970675Z digest=sha256:70254faf2271813e6c980999b8d509374fc17a890e26f903674864648c455a86

Observation 333ca45e-6c47-4e83-9f80-76610928175c · outbound

This paper cites Defending against prompt injection with datafilter,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defending against prompt injection with datafilter,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.140727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.140727Z digest=sha256:b5d2f49ac98587c9943275d84430d9fb9728dfb06a4b77fb9149c6debb020f2c

Observation 059b8f4f-e9f5-4311-a80e-d78b91967332 · outbound

This paper cites Defeating Prompt Injections by Design.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defeating Prompt Injections by Design

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.276646Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.276646Z digest=sha256:3a4074e913fdb2a05cb2fb070d415eeb4708f071051fd2c3448e52f4946bb314

Observation 82359524-7b03-44e3-a8b2-982d4129ad90 · outbound

This paper cites Drift: Dynamic rule-based defense with injection isolation for securing llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Drift: Dynamic rule-based defense with injection isolation for securing llm agents,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.260009Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:48.451426Z digest=sha256:a329be3869db03181397471ed1ce8cd7b9fdeecbc6e1a29fb638a9295c2d450d

Observation d8392da2-dc0a-404f-91c0-488d8251085d · outbound

This paper cites AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.601504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.601504Z digest=sha256:75c3a3016a865f426208677a4353fc3c97b685b447742ea2fec8a22f5f40437f

Observation c23152a6-c5e5-4cd2-a546-fbde8379b1b4 · outbound

This paper cites Claude opus 4.8 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.8 system card,

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.990541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:48.792435Z digest=sha256:347ec009c63e641ca36e466fbdd7b5694d87af44b47bffee0a869ebdd70bb944

Observation d09fb8ad-d715-4abd-8272-6f2a4d75c615 · outbound

This paper cites Secalign: Defend- ing against prompt injection with preference optimization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Secalign: Defend- ing against prompt injection with preference optimization,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.702584Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:48.892272Z digest=sha256:652fbea09bdc0fa7917b07bd236e5371e9653df2e5f28dbd9499b6a0c622f964

Observation 9f07afa9-9677-4cdc-8795-3b858e9f8935 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.996878Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.996878Z digest=sha256:2715a8c4da79a5640bba0a0dd5e368e6ad78136fa295aec5f2a732b5296e843f

Observation c7126831-551e-4344-84b8-ffab5e6054f3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 50

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.514757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.034052Z digest=sha256:2de50d6a82c2c6232c658274b88d89537fa7b111ae1a17bfcb57042148392d00

Observation f5074bf4-fd08-4704-b766-4b57a2c2cdc8 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 51

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.296756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.083594Z digest=sha256:c4825bb99763efbd7a9c189782a3e1df48ffe8f32e0e7fd44d901ba9ed703f05

Observation c1fea9e2-c54c-47e1-b6a8-1f3ee21011a3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 52

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.021691Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.126679Z digest=sha256:8e90569d6b7eb3d8bdb0a26c3f1a315e329417b5c56beb96afcf94e398e55225

Observation b27962e6-48cf-4f7a-b695-dcc41b949dc2 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 53

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:50.833130Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.191010Z digest=sha256:7bc413a64b07601b998204353d86162b92d9bd73f099de950cb79a8a6165cfa8

Observation dc2a7192-903f-4f9e-bae5-1e721339cad3 · outbound

This paper cites ## In-context examples.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## In-context examples

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:50.559662Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.260862Z digest=sha256:d66ab7d3a6b916c1d016aa4485807f2effb291f9b9ae6a5fc93f9b3a878f7cbb

Observation a1f25a28-a12e-4227-91e7-d3686e6a9dcf · outbound

This paper cites ## When this strategy is expected to fail.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## When this strategy is expected to fail

Reference 55

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T05:11:50.294110Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-06T05:11:49.315668Z digest=sha256:0c3aa587733849d26880897dbbfc89aeb30bde115b43d3105f81cd1524fcbfec

Pith citing papers

No inbound Pith citation observations are available.