Pith. sign in

Paper Citation Record · LEDGER

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure

As of 9 August 2026, this Paper Citation Record lists 94 of 94 outbound references and 0 inbound Pith citation observations for arXiv:2608.02657.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.02657 v1

Coverage vector

measured 94 of 94 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T00:54:57.479602Z

measured 94 of 94 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

94 of 94 outbound references displayed

  • verified exact1
  • verified fuzzy49
  • unresolved44
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d08fbfda-b34e-4243-8c83-f0030f19dcda · outbound

This paper cites Get my drift? catching llm task drift with activation deltas.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Get my drift? catching llm task drift with activation deltas

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.266213Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.266213Z digest=sha256:59cafd066a06c633c61f77c02dc661f6f4fffd6fb470ef92a7cb95d189563e61

Observation 66fab6d8-702a-4ecc-838a-c48f2fc9e688 · outbound

This paper cites Prompt leakage effect and mitigation strategies for multi-turn llm applications.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Prompt leakage effect and mitigation strategies for multi-turn llm applications

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.268994Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.268994Z digest=sha256:1071ee3e6d0985f7aca538cc040ac04d7842981653d0bee4d55e9151f8300320

Observation 91de3c53-35a6-415b-95ed-0cf40ab86c8f · outbound

This paper cites Understanding intermediate layers using linear classifier probes.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Understanding intermediate layers using linear classifier probes

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.271636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.271636Z digest=sha256:cd831477fdc17452df7d7c26b5873bad02b879338fadb676478053a409de17c7

Observation ff90bb45-4397-4ff9-956f-2edd8c5bd96a · outbound

This paper cites IPIGuard : A novel tool dependency graph-based defense against indirect prompt injection in LLM agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure IPIGuard : A novel tool dependency graph-based defense against indirect prompt injection in LLM agents

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.274153Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.274153Z digest=sha256:63cdf894fd154219e6f46daed2c886f65967a0444cf7a55767ae4d65d0ec4fc5

Observation e2e9699b-5c2f-453f-b38f-89a9b3e2222b · outbound

This paper cites Jailbreaking leading safety-aligned LLM s with simple adaptive attacks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Jailbreaking leading safety-aligned LLM s with simple adaptive attacks

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.276562Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.276562Z digest=sha256:c7242c2574d6465f37489de031d7c157ee44d9e0a5564766515160f26dffadcd

Observation 8cc9763a-8480-4557-8eb1-bb1e64a55016 · outbound

This paper cites Many-shot jailbreaking.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Many-shot jailbreaking

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.279035Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.279035Z digest=sha256:e1399cc4277ec83df37864a14c855219f03e16e168fd15863b7c5919dba71530

Observation 30cb68a9-404a-4d88-919d-0e074d8523f5 · outbound

This paper cites Refusal in language models is mediated by a single direction.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Refusal in language models is mediated by a single direction

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.281666Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.281666Z digest=sha256:24c33a8b84c6ae84c024d2ec3d68c297e3a31d77ff503bcaf9a4fa3fbdf5674a

Observation 1dad014f-f556-4ac1-b8e3-dad75af88d13 · outbound

This paper cites Monitoring Reasoning Models for Misbehavior and the Risks of Promoting Obfuscation.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Monitoring Reasoning Models for Misbehavior and the Risks of Promoting Obfuscation

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.283796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.283796Z digest=sha256:1a8a57b33ab0d46c44a84ab29b5a8dd499e133af8a744ba302f2e3ce5a83180e

Observation 0e0e27b3-5bb3-4cae-92ed-2fa41f461abf · outbound

This paper cites Probing classifiers: Promises, shortcomings, and advances.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Probing classifiers: Promises, shortcomings, and advances

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.287306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.287306Z digest=sha256:1bf3b85915702c518fb6a20364c5f65795facf5d48bdf536e76935e9406c3b1e

Observation 2e8ce96e-6279-4039-9eed-96ffd287cead · outbound

This paper cites Language models can explain neurons in language models.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Language models can explain neurons in language models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.289469Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.289469Z digest=sha256:98073c04d911bc96dda2178d20b846f128d41098ebbccac5a30cd3b26c39ce3e

Observation 63e5737b-96ba-42cb-82fd-4e0fb201b452 · outbound

This paper cites Bogdan, Uzay Macar, Neel Nanda, and Arthur Conmy.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Bogdan, Uzay Macar, Neel Nanda, and Arthur Conmy

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.291652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.291652Z digest=sha256:66c07461716f166af4550b91d3cf27ab78e9ab2676e4de1425dce55cac74fb17

Observation a6a263c8-2f67-4aae-9e20-a3d706d5937e · outbound

This paper cites Reasoning Theater: Disentangling Model Beliefs from Chain-of-Thought.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Reasoning Theater: Disentangling Model Beliefs from Chain-of-Thought

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.293790Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.293790Z digest=sha256:f6849a64dac5bedfa21a2a1e50c1bd936cbbe0b8e5302d83cb88fce74b0887ba

Observation a28847c1-2e00-4907-a14e-ef00c900d453 · outbound

This paper cites Towards monosemanticity: Decomposing language models with dictionary learning.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Towards monosemanticity: Decomposing language models with dictionary learning

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.296237Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.296237Z digest=sha256:bc792cd135a50dba199bb4f690ce54d91826ddecdbb17ca11ddf82d11aa8023a

Observation 63baef44-47d6-4ed6-83ab-0f7c47353381 · outbound

This paper cites Discovering latent knowledge in language models without supervision.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Discovering latent knowledge in language models without supervision

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.298288Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.298288Z digest=sha256:ad13c37c5df35c831349b24a0bd8bb69cb370d77bb95ab7f250176949ca897af

Observation 56473867-639c-4524-b872-3b520e6d560d · outbound

This paper cites Vpi-bench: Visual prompt injection attacks for computer-use agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Vpi-bench: Visual prompt injection attacks for computer-use agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.300455Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.300455Z digest=sha256:86eee5a02e3a0cf78d01aacef8603911894e13355e367cae62d269f355b4b875

Observation 72eeef71-88fe-4937-8ebc-8b431c533a5d · outbound

This paper cites Ghostei-bench: Do mobile agents resilience to environmental injection in dynamic on-device environments? In ICLR, 2026.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ghostei-bench: Do mobile agents resilience to environmental injection in dynamic on-device environments? In ICLR, 2026

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.302659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.302659Z digest=sha256:3b235f9414c85ecb10d5056d012f13226c33cc9ca7837e1bcd4790ff231c6160

Observation 4008ff70-ac65-45f8-949c-28426be73e33 · outbound

This paper cites Struq: Defending against prompt injection with structured queries.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Struq: Defending against prompt injection with structured queries

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.662574Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.304848Z digest=sha256:6e8433bd20a89bc2fbd13eb408c5148688ffe1f23f74dc7155d711c4fe06ac67

Observation 89feb34e-ed98-4c2f-be38-e21986457ec7 · outbound

This paper cites Secalign: Defending against prompt injection with preference optimization.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Secalign: Defending against prompt injection with preference optimization

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.307016Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.307016Z digest=sha256:4ba39cffeee3a681e259016ffe1d856936128b27b0dee9fcc906c2fd0e3766e8

Observation a36b39f7-071b-415a-89e2-6df75d2f875a · outbound

This paper cites HarmonyGuard: Toward Safety and Utility in Web Agents via Adaptive Policy Enhancement and Dual-Objective Optimization.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure HarmonyGuard: Toward Safety and Utility in Web Agents via Adaptive Policy Enhancement and Dual-Objective Optimization

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.309027Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.309027Z digest=sha256:872eaceb3c52b07088d9119698b47518339b9901f6f543c9d31344483e193349

Observation 15ec6143-48ab-4c62-a8cc-746c2cf77db2 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.311523Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.311523Z digest=sha256:5e07547eae0143400a48969767d9455725ad46c5bfb379cd688c4e9964ba8583

Observation b234a609-1001-450b-9c75-f1abcba9a8f2 · outbound

This paper cites Constitutional classifiers++: Efficient production-grade defenses against universal jailbreaks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Constitutional classifiers++: Efficient production-grade defenses against universal jailbreaks

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.313974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.313974Z digest=sha256:31c6badae6536aec83e441ea7ca15ecf19d4b58cc979fc4a183e52c28d743669

Observation b0c0b495-3417-41f4-986a-d71828e8602e · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.650024Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.316139Z digest=sha256:acda6f47659749f26f339f86b6ac8bee07563ec6d3fed0ee425af0fb057f96bb

Observation 8ac70048-ae95-416f-a63d-231248544b44 · outbound

This paper cites Defeating Prompt Injections by Design.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defeating Prompt Injections by Design

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.318137Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.318137Z digest=sha256:4f138b1cfd911559f2027bf2a7e708948977cbc1e8643f5c11a29390bc696c9a

Observation 966911ef-668d-4ccc-ab43-9189468bdaca · outbound

This paper cites `` I ' ve decided to leak'': Probing internals behind prompt leakage intents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure `` I ' ve decided to leak'': Probing internals behind prompt leakage intents

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.642090Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.320597Z digest=sha256:4d9b77a1ab7e6bc484ffe77b3beeb6aaf378036a3e7a7184c2aa05fd890d39be

Observation d0d96b01-9b34-4a1c-b49f-a8102a1655d3 · outbound

This paper cites Safesearch: Automated red-teaming of LLM -based search agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Safesearch: Automated red-teaming of LLM -based search agents

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.633456Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.322864Z digest=sha256:7d543f142a30c6496429caac70236a83dc76ac74bf0426b2aade123cf8c5da79

Observation 6d6264ae-f349-4461-8f4e-b0b2d5f9cefa · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Memory injection attacks on llm agents via query-only interaction

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.626838Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.324992Z digest=sha256:8c35689d2bd01470799dafe7362f89eeda203498ff6a3c784036f9b0100bd3a0

Observation 2eaef61b-b7c2-4df6-be65-02cc20df039d · outbound

This paper cites Transcoders find interpretable llm feature circuits.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Transcoders find interpretable llm feature circuits

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.619747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.326982Z digest=sha256:9f9ef496cf310853faab725a1c4c90ba0a6a20c6123c46f01321b7639186a4c4

Observation 0b403446-6ee0-4ab2-aecb-e7567a98b1cf · outbound

This paper cites How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.329002Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.329002Z digest=sha256:9963bdfce12a9171dbd3ffdcc767e59c34d5e380a63ae5649f642811a575b89e

Observation c0cbdf7b-546c-42aa-b51a-009e357d52dc · outbound

This paper cites WASP : Benchmarking web agent security against prompt injection attacks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure WASP : Benchmarking web agent security against prompt injection attacks

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.612970Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.331204Z digest=sha256:d4dbcf58bc83441f473425cd775782d164d9b439482bd78de1d25d24bd8ba1ae

Observation 64116890-5e9e-4b32-90d6-122cb6145892 · outbound

This paper cites Patchscopes: A unifying framework for inspecting hidden representations of language models.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Patchscopes: A unifying framework for inspecting hidden representations of language models

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.605163Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.333380Z digest=sha256:cb0f2aa0b57923684bda71f40a3d1dfb70c779add6878751f88f1064fd651d3c

Observation 19713e46-219d-41af-8531-70043a946e9f · outbound

This paper cites Not what you've signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Not what you've signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.597790Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.335491Z digest=sha256:7fb4d6e858bed7dfb948cd333469a3ab45cd77db62e2409b2e8749535526fd64

Observation 52dae4b0-414e-4e78-8dc9-83e6b29ee94d · outbound

This paper cites Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agent smith: a single image can jailbreak one million multimodal llm agents exponentially fast

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.590704Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.337811Z digest=sha256:805989927a1b30281c390d936ec957570824eb84c110e7b96120e6bf1d05a580

Observation 151fd113-bd15-441c-a967-ae04ca36a7e6 · outbound

This paper cites Attriguard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Attriguard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.583531Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.340036Z digest=sha256:55b34111ebdeef53bf34cf4c51dd4710635ce307bbe1a6b31f15c4e08c12fe72

Observation e8380c2b-1bff-4d2a-aa42-494dbe876702 · outbound

This paper cites Internal representations as indicators of hallucinations in agent tool selection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Internal representations as indicators of hallucinations in agent tool selection

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.342044Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.342044Z digest=sha256:7353b491bac259be553f410862288ee07a12723e52a20b5e916e7d744caf0412

Observation 857e5167-3ac0-41a7-a5e7-a6535be22dec · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.344108Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.344108Z digest=sha256:fa8fbdc09232bbaf86c22c466875428c2bef67938ea580162d987923428100b8

Observation 1b1909c9-be26-4bba-9d26-689ae0a87232 · outbound

This paper cites Hsu, and Pin-Yu Chen.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Hsu, and Pin-Yu Chen

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.576749Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.346663Z digest=sha256:9df8bc168cb506d3ca2dc03c88033169176c3975819d85694f027bb00e159cfe

Observation 753b8d18-880a-439d-9d6c-5efc25da638b · outbound

This paper cites Safepath: Preventing harmful reasoning in chain-of-thought via early alignment.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Safepath: Preventing harmful reasoning in chain-of-thought via early alignment

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.569753Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.348740Z digest=sha256:5441b18d8f719793cccb406ec7d3d6ca13b016739b68a534fb29454366b6161b

Observation 20cdfd49-d376-474e-a572-fa398ec22ad7 · outbound

This paper cites Llm internal states reveal hallucination risk faced with a query.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Llm internal states reveal hallucination risk faced with a query

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.562396Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.350855Z digest=sha256:ce6db0acb0ae8c906f9ceb394aa8b3f695ab97b1731c372993f78fbc33e1be5c

Observation 6ba31737-4ee0-47ed-b5f0-f41c446651a3 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.555511Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.352864Z digest=sha256:bb4b3ce413c566c32c4aec6698b904525535da45ad4d54ff0e1fefbdefee4df4

Observation 09de3710-9633-48d0-9eb8-04646cbf2200 · outbound

This paper cites Promptlocate: Localizing prompt injection attacks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Promptlocate: Localizing prompt injection attacks

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.548137Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.354992Z digest=sha256:5ce827d23b9040a80ab00ad932a836d9b4dd6c0907d34ba9fa7c9529590d4201

Observation 2fc9f139-ca42-42a9-9e5a-391b474f2f18 · outbound

This paper cites Activation oracles: Training and evaluating llms as general-purpose activation explainers.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Activation oracles: Training and evaluating llms as general-purpose activation explainers

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.357115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.357115Z digest=sha256:019660bac471bb32236b576a18378969a194c091b7db869764f6342e9972bf77

Observation c531c47a-d446-4eb7-b2a2-98407dffcc16 · outbound

This paper cites Le, and Tomas Pfister.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Le, and Tomas Pfister

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.540719Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.359236Z digest=sha256:84af886720abe36452eb336fede0000c85718c11e1839030ab4ed62bb0ef9f84

Observation 132747cf-e63c-4979-82ce-86949a8c70b2 · outbound

This paper cites Hendryx, Summer Yue, and Zifan Wang.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Hendryx, Summer Yue, and Zifan Wang

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.533495Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.361278Z digest=sha256:1842f205d0910ffc861c603152e16ce6247affd4c80271a0c2ea0d55a7752797

Observation 9c11e71a-89f3-4c64-94a6-067cddbbacce · outbound

This paper cites OS -harm: A benchmark for measuring safety of computer use agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure OS -harm: A benchmark for measuring safety of computer use agents

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.526544Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.363431Z digest=sha256:84e460611b34af34106228a0c59656774c61f4b16e5ba79ff112c076068e8035

Observation 5aaea5ae-c316-4783-9714-1b9170c73a5a · outbound

This paper cites Measuring AI ability to complete long software tasks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Measuring AI ability to complete long software tasks

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.519743Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.365409Z digest=sha256:d47e7ced046cbb50da7b2aeb9c021cbfecb1fb0879a7bc182d80bcd0561349ae

Observation bbed69b4-bd07-4688-a003-e43f2c3f5d5d · outbound

This paper cites Efficient memory management for large language model serving with pagedattention.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Efficient memory management for large language model serving with pagedattention

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.512771Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.367501Z digest=sha256:c6597d92750e5c6f22581342a57a94f13234b5a266f030cef8986b9d78bbcf85

Observation e7c7ba09-adf7-4d49-99a4-c14604383937 · outbound

This paper cites Measuring Faithfulness in Chain-of-Thought Reasoning.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Measuring Faithfulness in Chain-of-Thought Reasoning

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.369612Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.369612Z digest=sha256:c7fe3c94e57b856f35d3f0d950890ce43af85b4c6f859a38721596f78210cdc7

Observation 39a8ec91-4374-48f9-80f7-73e24dbbf8c2 · outbound

This paper cites Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.371881Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.371881Z digest=sha256:c84fbba609ae29d1720eddb10d7116d9ae672c2eacee5603024ed3f85d7e9b32

Observation f42caaef-7e1f-422e-8307-c64c9ca00cbe · outbound

This paper cites Inference-time intervention: Eliciting truthful answers from a language model.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Inference-time intervention: Eliciting truthful answers from a language model

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.505775Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.374245Z digest=sha256:3145acc0dbfb509258bb4fdd378f5e2c143b98040ebd09b0818fc31aef16a35d

Observation 6fcfaa42-5014-467e-adb2-77b49e572752 · outbound

This paper cites When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents

Reference 50

Resolution
verified exact
local_arxiv, observed 2026-08-05T00:54:57.900478Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.376303Z digest=sha256:bad36632e07a82d3be968070c53d5459dcf74e09a22aa3f82aae667d18e489f8

Observation e3e69242-191e-4971-bbae-f7de1d05b9dc · outbound

This paper cites Eia: Environmental injection attack on generalist web agents for privacy leakage.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Eia: Environmental injection attack on generalist web agents for privacy leakage

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.499125Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.378711Z digest=sha256:7e9557dc1f77294ffff9c547081dbd69b79eafaae262cbd3c4d602f6d81f4277

Observation a21ab69d-9501-4b4d-8754-cdc997fe6bdd · outbound

This paper cites Vigil: Defending llm agents against tool stream injection via verify-before-commit.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Vigil: Defending llm agents against tool stream injection via verify-before-commit

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.380837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.380837Z digest=sha256:5fc5953358a2e400320dca4a2e463ceebb9ec9ffe52ff0c532f5c31e0dc0d5fa

Observation 58686ce0-c64a-498a-bb7f-8efaaba781bf · outbound

This paper cites SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.382991Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.382991Z digest=sha256:c1cc6458ac8fe5d69823ffea81039dccb026791e02953c2b57fcebea69e6e23b

Observation 05a13b9a-444d-4532-bbee-ba60d073641f · outbound

This paper cites Traceaegis: Securing llm-based agents via hierarchical and behavioral anomaly detection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Traceaegis: Securing llm-based agents via hierarchical and behavioral anomaly detection

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.385335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.385335Z digest=sha256:031ab164ab14c15a6a914e5ab46006d000e97588060efb0220dd56516cbdb7cb

Observation 0979778b-760e-4726-baed-2337ad6f4e30 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Prompt Injection attack against LLM-integrated Applications

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.388047Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.388047Z digest=sha256:b4ab44d7e0a9e257d7bc7c7608721273b9f259bbe8d9501b09e9f00d27d74988

Observation 7b178dcf-91be-47ec-9a6d-c6d8c194ea2f · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Formalizing and benchmarking prompt injection attacks and defenses

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.492224Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.390559Z digest=sha256:c801bf44a45cb3ec92dacedbfda11d6fa2ca6fd682868ba78f09534e6684974a

Observation 71eee48b-2e5a-47dc-bf87-71ffb9f381d7 · outbound

This paper cites Bogdan, Senthooran Rajamanoharan, and Neel Nanda.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Bogdan, Senthooran Rajamanoharan, and Neel Nanda

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.485385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.392735Z digest=sha256:6acbfa33ef62ee5e1973e59bf5c516f899ec3f6458e6d4f0219d1a12e0466b34

Observation c4d8cee7-3389-4157-b64f-ca4ec9ef9547 · outbound

This paper cites s1: Simple test-time scaling.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure s1: Simple test-time scaling

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.478348Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.394793Z digest=sha256:865a6e72f59f86a27c3023605fdec044496b0d37ec27f47042abcf50b605cdcf

Observation 893b2cf9-786d-4bd2-aa9f-68352e604a15 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.396764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.396764Z digest=sha256:d9be6da9c6343d79a405ef3c11215b7a0fc16e6fd9bb7a861a8ea4f23d177eb2

Observation c718d3d1-ec12-45bf-b72d-60bea70b0055 · outbound

This paper cites GPT-5.6 System Card.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure GPT-5.6 System Card

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.471150Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.399009Z digest=sha256:64c5275fc99d29733b60ef9d190a97920c224ce67d475fbfa67a58a85880c55f

Observation 04037920-c5bb-4d12-9836-f7b1aad4e620 · outbound

This paper cites GPT‑5.5 System Card.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure GPT‑5.5 System Card

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.464321Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.401172Z digest=sha256:77136ff0d29801a411dcc2af1c2a333024ac212c0256ab3dc205da159222dae7

Observation e515aa37-cf34-42f9-8805-3b0760dd2846 · outbound

This paper cites LLM s know more than they show: On the intrinsic representation of LLM hallucinations.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure LLM s know more than they show: On the intrinsic representation of LLM hallucinations

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.457553Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.403270Z digest=sha256:d6e5a8431934d38b9bc309275efd1284090d4ad18e79d0795cb2f33d1f2613ef

Observation 9a0ba171-7d4a-472c-9b56-b401a90e7323 · outbound

This paper cites Owasp top 10 for agentic applications for 2026, 2025.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Owasp top 10 for agentic applications for 2026, 2025

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.450194Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.405390Z digest=sha256:d21bf8498c4490142b4f990e3f6c5541fdacbb62a7dd91d1267b6996d0d9d4d2

Observation d6bff5c4-1b84-4aa0-81c9-a23ebc63fc4a · outbound

This paper cites Latent QA : Teaching LLM s to decode activations into natural language.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Latent QA : Teaching LLM s to decode activations into natural language

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.443308Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.407798Z digest=sha256:8d32dd8410a0cb2dc6d41f24bafaa0f710f5e51f66bc9e4a16bdb9cab7f9edef

Observation 78ca08a7-dca1-4c8f-89db-4590e1a59204 · outbound

This paper cites The linear representation hypothesis and the geometry of large language models.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The linear representation hypothesis and the geometry of large language models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.409979Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.409979Z digest=sha256:9067894e79a893f9a9e245d41eb139c70f09682c547cb61f653caf887c89d72d

Observation d03875ff-f35d-4ec4-98f4-7b63a190030b · outbound

This paper cites Scikit-learn: Machine learning in python.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Scikit-learn: Machine learning in python

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.412072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.412072Z digest=sha256:aad8fc1bedc23f3259137a5d3acfb24ac21357323a8e7afc46f164cf441e9f0f

Observation bd11d624-c7f0-4fc0-97cc-22b34db60500 · outbound

This paper cites Ignore previous prompt: Attack techniques for language models.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ignore previous prompt: Attack techniques for language models

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.427292Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.414164Z digest=sha256:1b5669b652f7701960e0149ed155730e305b06ff3a80c5012d714b3487e7cc6b

Observation 5d5ee724-8cc8-41e5-ae4f-6fe05c7b9439 · outbound

This paper cites Steering llama 2 via contrastive activation addition.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Steering llama 2 via contrastive activation addition

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.420169Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.416198Z digest=sha256:6bd5c739cded66be59b9bec2913f423f3ea487627a3fed4bc4b4025394f178b3

Observation 86e8a1cb-7287-4fce-9297-bc8354c6458c · outbound

This paper cites Great, now write an article about that: The crescendo multi-turn llm jailbreak attack.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Great, now write an article about that: The crescendo multi-turn llm jailbreak attack

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.412600Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.418435Z digest=sha256:d91483ac7407a18db7051210ddb7072faa8a540bea7f7941d76ca59d218755cb

Observation 863184d2-8aa0-42be-814d-e1743bc4b8c1 · outbound

This paper cites Ignore this title and hackaprompt: Exposing systemic vulnerabilities of llms through a global prompt hacking competition.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Ignore this title and hackaprompt: Exposing systemic vulnerabilities of llms through a global prompt hacking competition

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.404536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.420548Z digest=sha256:847f27ea69ff9617820a867da5f6cdf591168ff9433732b9d2dc820ff48d190c

Observation 1f4cf12f-5893-4691-8b22-b7ef8e271ac8 · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.422665Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.422665Z digest=sha256:022643d3e87303c3e0980f60a4cf5ad54f3f3bc25a5122cbb0a886f10b25dce2

Observation 6472a7d6-1abf-4bdd-9660-c053fd77c4d3 · outbound

This paper cites Daniel Freeman, Theodore R.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Daniel Freeman, Theodore R

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.424978Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.424978Z digest=sha256:a99dc557ab6f75ea3e039e91b8cc4c48ad4db381bc102b01f94faa6488837690

Observation 732b4a58-e52c-4901-aefa-6e93afcece8d · outbound

This paper cites Tensor trust: Interpretable prompt injection attacks from an online game.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Tensor trust: Interpretable prompt injection attacks from an online game

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.393335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.427297Z digest=sha256:58bf35e5a4c3a77b78315d557e9ebfdb43fb07487e37b74955ce5740f5161afd

Observation 304d6cf6-3ab3-4819-bb76-258b988ee964 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.429487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.429487Z digest=sha256:f53546493327cfc4c82a0ed3657620686f208f59dce1f3513ffbdbccd75c6967

Observation 79e606ba-5f75-47a2-b994-d20998f4f783 · outbound

This paper cites Raccoon: Prompt extraction benchmark of llm-integrated applications.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Raccoon: Prompt extraction benchmark of llm-integrated applications

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.386468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.431865Z digest=sha256:c534ba2fad20a8d02f5d1eb075e1ab2e3e11e06398d7f8738f6d71580355b858

Observation 8f6737ba-73f0-4be0-a105-0ee6ecf82c30 · outbound

This paper cites Agentarmor: Enforcing program analysis on agent runtime trace to defend against prompt injection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agentarmor: Enforcing program analysis on agent runtime trace to defend against prompt injection

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.434034Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.434034Z digest=sha256:e064c391c82c9f273e4f8a2d74cef74e8a5eac43f13ca39fcaad09ceb620a870

Observation 86c19c39-f6c1-4edf-83cc-2e23a301e48b · outbound

This paper cites Automatic layer selection for hallucination detection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Automatic layer selection for hallucination detection

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.379900Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.436433Z digest=sha256:3ca12f472bd9dff7f55f9ceb4954560d02e5b6c287463475adc9b0a2ab80a54c

Observation 15774ad1-a8ea-4106-b132-d3bab8aa8cfd · outbound

This paper cites Defending against indirect prompt injection by instruction detection.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defending against indirect prompt injection by instruction detection

Reference 78

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.373573Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.439190Z digest=sha256:08e46af3129a6568491a549250e497b77eab3a5ad6f7b0a688fcbb1ca26b8d4b

Observation 262a2156-1068-4ed9-8947-a7e8191de3eb · outbound

This paper cites an unresolved cited work.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Unresolved cited work

Reference 79

Resolution
unresolved
raw_fallback, observed 2026-08-05T00:54:58.367004Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.441842Z digest=sha256:f75b5131118caf6ee6c158323c1a1b038819c1bcd2564de02bc759d10d6322b4

Observation 6ef89cfa-42d3-4f04-9db6-015860dea1f5 · outbound

This paper cites Guardagent: Safeguard LLM agents via knowledge-enabled reasoning.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Guardagent: Safeguard LLM agents via knowledge-enabled reasoning

Reference 80

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.360303Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.444509Z digest=sha256:0226e103d53cb7c92c544c2c50a2dff5964961efd9a6d0cc361443ec6ef206ce

Observation 1d493fda-8275-47c3-aafe-268b4c406d5e · outbound

This paper cites Qwen3 Technical Report.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Qwen3 Technical Report

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.447210Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.447210Z digest=sha256:f7eb432db24080775b6a4e4cfccd197ca706aa4486ba76528b142cf88ea69e1a

Observation 6fe9ac39-009d-4c96-9856-8ad2cf964fa3 · outbound

This paper cites RAP-ID : Mechanistic prompt injection detection via impostor behavior analysis.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure RAP-ID : Mechanistic prompt injection detection via impostor behavior analysis

Reference 82

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.353289Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.449730Z digest=sha256:6e67dc01ad34f202310794a142d8abbbe27039c6606d3f2daffd8c26fd314b9c

Observation a53c2fca-6392-45a8-b876-3621dc0f40b5 · outbound

This paper cites The Reasoning Trap: How Enhancing LLM Reasoning Amplifies Tool Hallucination.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure The Reasoning Trap: How Enhancing LLM Reasoning Amplifies Tool Hallucination

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.452102Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.452102Z digest=sha256:a4dcc04685bfc1c3a592c37368bfc01b5f6887dc8999d39ce3acb9d9efea3e94

Observation fba3050a-4673-47d2-9efc-7f027e406c2d · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 84

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.346219Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.454810Z digest=sha256:4732bb2586d9e79951b354ce652e7f6572b08f68c5a5bcdba6b13958773484de

Observation 345000b5-0375-4133-b06d-bbf6b52daf2a · outbound

This paper cites Adaptive attacks break defenses against indirect prompt injection attacks on llm agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Adaptive attacks break defenses against indirect prompt injection attacks on llm agents

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.339017Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.457263Z digest=sha256:dc0a0885ff11b4bcc6a22145b99341b80397d0be9c27e51640479a7d0f6d2d4d

Observation 1b723bfd-acaa-4072-bbc1-098d825e287e · outbound

This paper cites Agent security bench ( ASB ): Formalizing and benchmarking attacks and defenses in LLM -based agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Agent security bench ( ASB ): Formalizing and benchmarking attacks and defenses in LLM -based agents

Reference 86

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.331177Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.460027Z digest=sha256:e3285e2080abc29700cbb48040d83473da0548baa0def1107e6f85014fde11fd

Observation 6f700c98-420c-45a9-ab76-da7a81683c1a · outbound

This paper cites Defense against prompt injection attacks via mixture of encodings.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Defense against prompt injection attacks via mixture of encodings

Reference 87

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.323879Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.462499Z digest=sha256:df49b708baeb86cef0238b085d885d90ac8e34f30a2c5d0e7c6365663783148c

Observation 5244c1af-d5fe-4fe5-93b3-f3e7a6e68f39 · outbound

This paper cites Toolbehonest: A multi-level hallucination diagnostic benchmark for tool-augmented large language models.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Toolbehonest: A multi-level hallucination diagnostic benchmark for tool-augmented large language models

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.316206Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.464901Z digest=sha256:189549e7a258789b0a1a003db71c810d95937d40e9f2c5433b3551387901eb78

Observation ce8c1d43-1646-4b00-85f2-cf3c0e528993 · outbound

This paper cites Iheval: Evaluating language models on following the instruction hierarchy.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Iheval: Evaluating language models on following the instruction hierarchy

Reference 89

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.308618Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.467554Z digest=sha256:1117fbff51ee7a3b53df372ed8d0ef06c75f176bf95adf5d1f801f3556df3186

Observation 21c06b96-d2df-4fde-88d3-b7fe379aefa8 · outbound

This paper cites Attention is all you need to defend against indirect prompt injection attacks in llms.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Attention is all you need to defend against indirect prompt injection attacks in llms

Reference 90

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.301434Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.470032Z digest=sha256:7eb73c2d8542364cda04113f54afd0f461da900368785650d6197b270a5a3542

Observation 8223654b-2157-406e-b45c-b8ecaefc50dd · outbound

This paper cites MELON : Provable defense against indirect prompt injection attacks in AI agents.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure MELON : Provable defense against indirect prompt injection attacks in AI agents

Reference 91

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T00:54:58.292845Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-05T00:54:57.472226Z digest=sha256:f9c0d12da8ed30613a59b88e47b6648c24d1987263884287d61ee1f82c0ae7e1

Observation 1ff8edec-df0e-4de2-a9c9-0cec8a9caa21 · outbound

This paper cites Your Agent is More Brittle Than You Think: Uncovering Indirect Injection Vulnerabilities in Agentic LLMs.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Your Agent is More Brittle Than You Think: Uncovering Indirect Injection Vulnerabilities in Agentic LLMs

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.474502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.474502Z digest=sha256:93f80313f9f43b14fd048ff3c67ac9e50b40f3d08f955a1369907d56e2ff43b2

Observation eb73bb13-2cdf-4042-afa8-7ed1493e80ed · outbound

This paper cites Representation Engineering: A Top-Down Approach to AI Transparency.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Representation Engineering: A Top-Down Approach to AI Transparency

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.476993Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.476993Z digest=sha256:42a78a330d883830ee5d24a907a7d1debbce68bbbecd85b0eb8867b4c7b5ff8d

Observation b2b6154e-2b53-4867-94d6-4e6d841655d0 · outbound

This paper cites Pishield: Detecting prompt injection attacks via intrinsic llm features.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Pishield: Detecting prompt injection attacks via intrinsic llm features

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.479602Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.479602Z digest=sha256:bad3751dc582cdef79c2273a134966e154cd623839c2890e6c1b02b6201a4876

Pith citing papers

No inbound Pith citation observations are available.