Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-31T23:24:19.584090Z
Paper Citation Record · LEDGER
As of 21 August 2026, this Paper Citation Record lists 33 of 33 outbound references and 0 inbound Pith citation observations for arXiv:2607.23999.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-31T23:24:19.584090Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
33 of 33 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation aeac695c-9b02-4acc-84eb-a808e7344957 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents LLMail-Inject: A Dataset from a Realistic Adaptive Prompt Injection Challenge
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9ee9772c-52c1-40c9-8507-5291b06a9e54 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual-Use Hazards of AI Foundation Models
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9717f0fd-4b9e-41f1-9000-9311b93b6de6 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c08ec257-4107-4c63-bc5b-6e3e968135b9 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f15623fb-4e63-48a7-a836-0c8851e6a052 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents StruQ: Defending Against Prompt Injection with Structured Queries
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e004625-42f8-46f4-ada6-d0988f2534ca · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents SecAlign: Defending Against Prompt Injection with Preference Optimization
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4cd445f0-290a-4c60-b6b6-7af7ddf3b826 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Securing AI Agents with Information-Flow Control
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 57c374de-2176-4142-b4ef-4b8e297b7b86 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Defeating Prompt Injections by Design
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 03d99116-2a6c-42d7-a133-65f741bf37b5 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 40160c12-7f09-4560-81c3-d5c55c8cb5ba · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents PIArena: A Platform for Prompt Injection Evaluation
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 821494c3-93b2-4b8e-bb2f-c9f4f9c18a25 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3c6d3d66-f670-4597-ba6b-f672b28a96b4 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9cd601ce-f0bd-4cc9-b8d2-48f47dc6a814 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2ee13d19-4e71-44e9-879b-70ece1bc97b3 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1847c81d-a1bd-4925-8204-fb4336c41cec · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 537025d7-8b68-47e8-bd76-5ffb88b6a598 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79dd798b-0af9-4051-ae66-5709aa246531 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eaa2c2ad-ef7c-4974-ae9c-874e66312460 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0e5ab8cb-f451-44f9-9b0e-829a48db625a · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ec202576-c99d-448f-8282-f480d312a74b · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df633017-c20f-4002-931b-59ffa8d091b3 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Hidden in Memory: Sleeper Memory Poisoning in LLM Agents
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9d7b2f26-314f-449a-aa5c-5bad1cab13e5 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents On the Security of Research Artifacts
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a6561c55-5b02-4db0-9230-688998f169c5 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents XSTest: A Test Suite for Identifying Exaggerated Safety Behaviours in Large Language Models
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 91461674-e372-43c8-b8fd-57db70a1d14f · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Model evaluation for extreme risks
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 05ea2542-c8a2-4670-b3ae-2a66fa62a11d · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Progent: Securing AI Agents with Privilege Control
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 93f01eca-e0a2-46bd-b77f-26dffe350b4e · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f59612fe-e213-458a-ad2b-960d48303897 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents A StrongREJECT for Empty Jailbreaks
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 05761911-becf-4f48-8109-c5106db028bc · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6461035e-c70b-4983-b037-2ce642539fa6 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentWatcher: A Rule-based Prompt Injection Monitor
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation db4457de-bbd2-4963-a793-ecef3e38fac2 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 518f7e29-b41a-4e0c-9ac4-e543b5e30a0c · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b9707586-dd10-4ae5-9fcc-3f98054edf33 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e18f42e5-3596-43bb-acbc-680fa8fce847 · outbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.