Pith. sign in

Paper Citation Record · LEDGER

Prompt Injection 2.0: Hybrid AI Threats

As of 11 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 4 inbound Pith citation observations for arXiv:2507.13169.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.13169 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T16:34:05.446734Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-11T04:15:53.991771Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-22T12:51:33.393440Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact2
  • verified fuzzy1
  • unresolved25
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation e22e7f76-32cd-4cb3-869f-3183830e0afa · outbound

This paper cites Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples.

Prompt Injection 2.0: Hybrid AI Threats Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.088522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.088522Z digest=sha256:0cd4d49d804b556f4249d666a400a17ed77c678d6e13889196132d403c627414

Observation 28fbf030-816c-41ff-903c-2df09f0a7f9c · outbound

This paper cites C., & Heichman, R.

Prompt Injection 2.0: Hybrid AI Threats C., & Heichman, R

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T16:34:08.065627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:03.214886Z digest=sha256:a45c6cd11143724fecf8ba8cb6477097137aa334d0aafd7fbf69ba3ba173e913

Observation 4ba24e3f-f487-4b02-a626-63b6ad009055 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

Prompt Injection 2.0: Hybrid AI Threats Prompt Injection attack against LLM-integrated Applications

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.313953Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.313953Z digest=sha256:390814f3044f10a04633e8b1eff7545b3b08e2a71f0654cc0b7de57474d4daeb

Observation 513e5f8c-0e6b-4d1c-aa3d-8110b7bcb807 · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.407180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.407180Z digest=sha256:b8947baecdbddd03650441df9ac357b7441d29f1b80557f76318a0e42cbe0119

Observation 2c8e481a-6979-4c1e-91d7-eb514330e081 · outbound

This paper cites From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?.

Prompt Injection 2.0: Hybrid AI Threats From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.503194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.503194Z digest=sha256:fe0e80bd15a4746a3ffe134d26f351f203d1449168ba6d54d93c9a97ea09048e

Observation 81b7056d-e92d-4262-a83a-cfadff70051b · outbound

This paper cites AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development.

Prompt Injection 2.0: Hybrid AI Threats AI Ethics by Design: Implementing Customizable Guardrails for Responsible AI Development

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.402350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:03.624743Z digest=sha256:0869af2a855bbdd7cd88d6e87ba1e8ff37dcad4756094f8f860e239e5f992dce

Observation 74108fff-12a9-4135-8e67-a6a18bca8085 · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

Prompt Injection 2.0: Hybrid AI Threats Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.695223Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.695223Z digest=sha256:0bf5abeedcb7ae2d96245f3a0759b26584d4346f905b63012846831c642d404f

Observation 9ffcd4e8-6f3c-4856-9cce-4421416681fa · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 8

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.818080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:03.778176Z digest=sha256:5e12db6bc6336d9a16099c5ff0e73886ae36412326fbd44ea4fc7e11ece34bce

Observation 67a374ee-c085-4de3-abb1-fb82d9c1fefe · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

Prompt Injection 2.0: Hybrid AI Threats Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.842222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.842222Z digest=sha256:76610e4d96d7581dcad7f33c383b9f10ece36d6e03649ed9eb4e799571657b67

Observation 7f4cdc41-655f-434b-9be2-a74bc3172ba9 · outbound

This paper cites Defeating Prompt Injections by Design.

Prompt Injection 2.0: Hybrid AI Threats Defeating Prompt Injections by Design

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:03.919189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:03.919189Z digest=sha256:2e5ff01c4e27f6b7e673f1a34828ce5fdd33a02cfc6d8d2df12435900f73d8d6

Observation 1c073cff-1405-48a5-91aa-b7a78fc582b7 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 11

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.505229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:04.001119Z digest=sha256:87e8413366e7fef12a8cc7434b434851ffa1389fb105c40982294ba07a0cc499

Observation 43d9d6d4-67cb-4608-89d9-d5c6532faf25 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.307622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:04.096370Z digest=sha256:0741f9546114e55728d14722b6f445a320f0bc8031ccbc8abc80048c881a8dd4

Observation 0c024737-d7c3-4a78-9b2f-f2c999750230 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 13

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:07.022398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:04.192243Z digest=sha256:fc807b2788e4150ebe67ccdbcec7131eb331448010cc66b51e867d694bc5a619

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:1442fe6c390b7e00d4ed86f2eb65f77a397e9174af4e7fd185d72f48745e26ea

Observation 932b69ab-e882-49e0-a697-a9bbcf822bb9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 15

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.877652Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:04.375475Z digest=sha256:bdd3e9d9ebc5ddba6ab26dfc06b1dc08f708931f081a1e677360ba99013295b3

Observation e379a488-61be-486e-b10a-30e052f70bbd · outbound

This paper cites XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants.

Prompt Injection 2.0: Hybrid AI Threats XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-08-06T16:34:06.094966Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:04.450450Z digest=sha256:491629cfbd7b8d5100ad6db2ffb7f41772b76f53828dd1dabc026c2f7d9da02a

Observation 97ca63c5-25a5-4980-94cb-1c29107c98e0 · outbound

This paper cites The Hidden Dangers of Browsing AI Agents.

Prompt Injection 2.0: Hybrid AI Threats The Hidden Dangers of Browsing AI Agents

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.510763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.510763Z digest=sha256:58b8d4f8057b774ba9f00fe57c798430581f811222c42ee4f14f8250bc57d27a

Observation 48ce344e-7e62-45bd-8d86-18374023e328 · outbound

This paper cites Learning to Poison Large Language Models for Downstream Manipulation.

Prompt Injection 2.0: Hybrid AI Threats Learning to Poison Large Language Models for Downstream Manipulation

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.598552Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.598552Z digest=sha256:dc97721d0a8954804a6f6959327726651cc28d6c20321439185f7edab4002bc5

Observation fb31b710-e5d8-497a-9bb8-b335be88601d · outbound

This paper cites Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.667309Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.667309Z digest=sha256:5bc05a76f2c0a5b57ba93668fc9078d5f9efe9514d586ee5168f15912726b5fc

Observation 8a60a853-a16d-4b30-beb5-e095804b0e30 · outbound

This paper cites Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.754226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.754226Z digest=sha256:0ac2708998eba4073365faa563a2e12db3625e214a1013360a861350f704bff0

Observation fbe5eca5-fc2b-4390-98d2-c32b7d9b82ac · outbound

This paper cites Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models.

Prompt Injection 2.0: Hybrid AI Threats Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.853306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.853306Z digest=sha256:f4f0c7ed008d0af78ac24a34053c962934e505b2f95c93ee0affc4662e13ce2b

Observation 2a247095-3659-4852-b88a-22fed94a42b8 · outbound

This paper cites Manipulating Multimodal Agents via Cross-Modal Prompt Injection.

Prompt Injection 2.0: Hybrid AI Threats Manipulating Multimodal Agents via Cross-Modal Prompt Injection

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.952025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.952025Z digest=sha256:f944a9bdfaf2016e2cf802213d1286a136623e3530f6f800fc603135a45848ab

Observation 6514fbca-975f-4253-a587-05efbc389ff9 · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-06T16:34:06.771915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:05.011939Z digest=sha256:9b15ca915eb4d76d9727106324e530375832cda11e4c15ba1fdf548876f35818

Observation 80107157-42c9-4510-a17b-5ec0990ce669 · outbound

This paper cites Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs.

Prompt Injection 2.0: Hybrid AI Threats Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.101373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.101373Z digest=sha256:858f51eb6e6144ba03cd5084249750d6d20410a2a1793e66885b561346b77d9e

Observation 711b04e6-a84a-4b06-8648-54f847ee47d8 · outbound

This paper cites Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition.

Prompt Injection 2.0: Hybrid AI Threats Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.169846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.169846Z digest=sha256:528f69f5de516e183cd510be94f4d9c41fa49c38b9cb9f18495e70512211f7d6

Observation 901f6257-6605-4160-b812-d5c36cc18a4a · outbound

This paper cites an unresolved cited work.

Prompt Injection 2.0: Hybrid AI Threats Unresolved cited work

Reference 26

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T16:34:06.657603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-06T16:34:05.255867Z digest=sha256:1c6032a88aa3f69b88121989c2d588663105579fd0eaef0321dbffdddf096fd6

Observation 53d2c546-ea9f-4636-bf87-72f6c0317db7 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

Prompt Injection 2.0: Hybrid AI Threats LLM Agents can Autonomously Hack Websites

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.325342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.325342Z digest=sha256:b7ee24a7321612ac46a21f8fb10f681a2c0db79cc3b93e6c11f9ebbe7d579986

Observation 4a6efbb7-8971-44ae-aabf-67ad24ecb2ae · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Prompt Injection 2.0: Hybrid AI Threats Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.379319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.379319Z digest=sha256:daa90ff4f4fb5587cd0e9232fef8d1456a9fd2be3ab2d581098756f873ef44ea

Observation 8a6b4405-be54-4aaf-bad0-de88deabf587 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Prompt Injection 2.0: Hybrid AI Threats Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:05.446734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:05.446734Z digest=sha256:a81dde64f31a9ec2a39a79de269b3e9754ff7880143ef88f8a7a5b1cd3b49dc9

Pith citing papers

Observation e5e416d9-e605-440c-b626-69eb3f50bd19 · inbound

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities cites this paper.

Neuro-Symbolic AI for Cybersecurity: State of the Art, Challenges, and Opportunities Prompt Injection 2.0: Hybrid AI Threats

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-18T18:06:43.025006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-18T18:04:09.528381Z digest=sha256:3c2bb609c81d1e0990ba363520d4ac1f9e6c3e98d4b1a658420b31155e2dc009

Observation 406e2f80-5836-4e26-8605-0a1161a23245 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Prompt Injection 2.0: Hybrid AI Threats

Reference 61

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.431852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:e81c56a700539093a105b2ea371c6ea517fbae280c66b5e9e89f701640347acd

Observation 621df737-31d9-4a80-9d4e-e92f691c623e · inbound

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation cites this paper.

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Prompt Injection 2.0: Hybrid AI Threats

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:51:33.396810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-22T12:46:44.819224Z digest=sha256:63780b0da7cddc9e406be64f3195762f1ddc220854b98c16d00896af1a0d8b54

Observation 3e6f750e-bd37-43e2-be17-717b63583de1 · inbound

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis cites this paper.

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis Prompt Injection 2.0: Hybrid AI Threats

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-11T04:15:53.991771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-11T04:15:53.991771Z digest=sha256:4ee83c01332f5f0a35e121aea6a1254f7d3109ac62e16bb4f46a10bf1670caf8