Pith. sign in

Paper Citation Record · LEDGER

Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 56 inbound Pith citation observations for arXiv:2312.14197.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2312.14197 v4

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 56 of 56 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 56 of 56 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-08T20:57:43.602204Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

9
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 97817b41-db3e-41fd-8e9d-f58974c5f7ff · inbound

Defending Against Indirect Prompt Injection Attacks With Spotlighting cites this paper.

Defending Against Indirect Prompt Injection Attacks With Spotlighting Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-14T22:28:55.424003Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-14T22:28:55.370749Z digest=sha256:624c59d560cd8ce349ef7f6205a10188866376e4ccde3fdc86114b962c54babe

Observation 634df275-c0b3-42b6-993e-17572a6d9b11 · inbound

LLM Agents can Autonomously Exploit One-day Vulnerabilities cites this paper.

LLM Agents can Autonomously Exploit One-day Vulnerabilities Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-18T04:18:27.662132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T04:18:27.597704Z digest=sha256:a76eacffd45f7b84ae944d07bfef60c8c33e355c89baca0988e3c93b73ac6830

Observation 196cfb2e-0fa5-4054-b31e-bfa081355095 · inbound

The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions cites this paper.

The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:59:30.797232Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-12T10:59:30.728091Z digest=sha256:7c34d2dfa44b831575d3ebecb6bac1279d6c13d18584269ad854f1de1c0deef2

Observation d352e1af-4809-454a-9774-144f23f1472d · inbound

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents cites this paper.

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.402235Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T06:35:13.331872Z digest=sha256:64574493e16cfc22a2a1c8c9b39a79c3921026b2bd14452a57c44af807c85015

Observation 8e27a0e4-8b48-4c9a-999d-38612545cce3 · inbound

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents cites this paper.

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 157

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.224615Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-12T13:36:57.011451Z digest=sha256:38cbd04ea5cd9e9b910df47be494bd090ab87a5d5cbfa047ba7c67bd6abbc600

Observation 8bcc4d61-5791-4f0f-9293-c6aa22d3d377 · inbound

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search cites this paper.

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-08T20:57:43.602204Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T20:57:43.602204Z digest=sha256:ee537ad8bab56987709ce83845b9c084721db00cb3f038ad3445a0e7967fb323

Observation 41a497e6-9ae9-4b69-bfe5-5cc3204fd3a7 · inbound

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety cites this paper.

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 140

Resolution
verified exact
arxiv_id, observed 2026-05-23T04:42:34.016624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-23T04:39:04.591722Z digest=sha256:f1fa07308c444a9f72f41d7c136f6cf2e70959f5cd513e1deba856e141b0d11f

Observation 1bec698a-1e6d-4541-b8ff-39f77ebb7b5b · inbound

IHEval: Evaluating Language Models on Following the Instruction Hierarchy cites this paper.

IHEval: Evaluating Language Models on Following the Instruction Hierarchy Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T23:56:00.128652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T23:56:00.128652Z digest=sha256:3619191f6e085ab30af93270103761296731a7426d21d451b3df433876721c3a

Observation 6c012428-57fa-4c01-9a96-0fe31bc4bc35 · inbound

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction cites this paper.

Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 45

Resolution
verified exact
arxiv_id, observed 2026-05-22T19:11:58.044991Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T19:10:55.009810Z digest=sha256:3cbdac2fab53b349dc3d02a463be194e59c9225becb24e87d54631503ada7050

Observation a00eec65-66f6-4758-a934-70a4f8216626 · inbound

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks cites this paper.

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T15:41:24.481852Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:41:24.481852Z digest=sha256:a190ca414ff764c72b99328d7f9bb6d9cf4da021fc7ad774a1b69043d66917b5

Observation ed10cf18-6a79-4b5b-bef3-d9087450a1c8 · inbound

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains cites this paper.

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T15:14:46.395816Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:14:46.395816Z digest=sha256:5ede886c80e02e77b5c293f20a4dec3076e88b9f6294173112fd05753f179beb

Observation 3f184b0b-621e-427d-97b3-bcef0124352b · inbound

Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models cites this paper.

Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T14:55:02.679214Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T14:55:02.679214Z digest=sha256:632ce789339e9a6d94b0d728d5a8ebe65a55bb7559cc0a823a46ab19114289c7

Observation f8bffdc9-cb67-4366-8440-8cd448565bba · inbound

A Critical Evaluation of Defenses against Prompt Injection Attacks cites this paper.

A Critical Evaluation of Defenses against Prompt Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T14:36:12.693088Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:36:12.693088Z digest=sha256:10f2dcc23cdcf7710d4ec907707d8cfc2d17bcf80b4502a0e2d1e09a713463ed

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · inbound

LLM Agents Should Employ Security Principles cites this paper.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:123e05aeec13f18c2afefe71b4d883a6f0986461eec5342acfe58e98b7203fed

Observation b0693264-866e-4e60-9f8e-589c4dda26a7 · inbound

JavelinGuard: Low-Cost Transformer Architectures for LLM Security cites this paper.

JavelinGuard: Low-Cost Transformer Architectures for LLM Security Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T05:41:25.529733Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T05:41:25.529733Z digest=sha256:cf568ecdc06361a1225d3e3601382441f4f37de78870910dfbdc73ec4fd7a105

Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · inbound

Context manipulation attacks : Web agents are susceptible to corrupted memory cites this paper.

Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.158675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.158675Z digest=sha256:49c288289c291af2a712cf601db2a38bf6c84b4df574972d9cbbee12fca0eb63

Observation 089d26cc-1fdc-429c-99e4-2da7b551d9a5 · inbound

BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services cites this paper.

BLOCKS: Blockchain-supported Cross-Silo Knowledge Sharing for Efficient LLM Services Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T22:40:38.187097Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T22:40:38.187097Z digest=sha256:a3826535ba06ead9ad94c25bf4a373c533132a7225bd4ad24337236849d5cdd2

Observation 2783b487-2406-40aa-aff0-c2ebdf3fd4ae · inbound

Prompt Injection 2.0: Hybrid AI Threats cites this paper.

Prompt Injection 2.0: Hybrid AI Threats Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T16:34:04.277916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:34:04.277916Z digest=sha256:7a772ed46e896130c9b3fa17cb7f6a458db0e76dd62cf64a6321cc3ca18c5af8

Observation 176dae2d-28d1-42fe-8986-b5645525b5c9 · inbound

WebGuard: Building a Generalizable Guardrail for Web Agents cites this paper.

WebGuard: Building a Generalizable Guardrail for Web Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-06T16:12:51.333428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T16:12:51.333428Z digest=sha256:22b86b0314e03aa5998f39d744c798b5e799ef6300deca69d9ed3c5ed72e18a9

Observation 1bc81062-1a6c-4fe0-9237-9da26b29fbe2 · inbound

Lexical Hints of Accuracy in LLM Reasoning Chains cites this paper.

Lexical Hints of Accuracy in LLM Reasoning Chains Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T18:48:50.863975Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:48:50.863975Z digest=sha256:21041c893ec4cc7dcae425c1bc78975724bb2d205d9be0d60825214f4f667743

Observation f3cba737-1295-4552-94ac-1eadc91f1413 · inbound

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior cites this paper.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.954752Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.954752Z digest=sha256:3730749143aaa41dc2974ac56b2e151701af3d37b131c8a62208713916d0f1e6

Observation 538c7225-0d0a-4c6b-ac48-d2634878d9c3 · inbound

When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift cites this paper.

When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T23:22:38.844788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T23:22:38.844788Z digest=sha256:c02062cfbfc04dd9d580f69f2c3bd85f7462ca100db87b44c278a6cd62bd44a5

Observation 35a8932a-22a3-494c-81c9-d86984fec96d · inbound

Many-Tier Instruction Hierarchy in LLM Agents cites this paper.

Many-Tier Instruction Hierarchy in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T07:16:01.976213Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-10T17:15:10.392678Z digest=sha256:d69d627706301c1fcd81ed1cb832ea3b554c409a6a7c09fc23a68f5792d73e2a

Observation 21110f35-c167-4750-b0ab-02728ebe78ad · inbound

An AI Agent Execution Environment to Safeguard User Data cites this paper.

An AI Agent Execution Environment to Safeguard User Data Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 82

Resolution
verified exact
arxiv_id, observed 2026-05-11T13:11:05.750535Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T02:14:40.639143Z digest=sha256:48f574d33c3ff341f3aa1a28c83de4a667f101ef3501c7cdee4e7a0bccfd2fa3

Observation ddf3556a-3549-46ad-a5f2-bdcf15b60da8 · inbound

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents cites this paper.

Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-05-08T22:39:20.577096Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T08:08:24.524671Z digest=sha256:b663c2a552e935803a3af02613d04dc73a6cd497457bc774424654e23e8ec5c7

Observation 6f2a28f4-9667-48d1-9ac0-280daa79c69f · inbound

Evaluation of Prompt Injection Defenses in Large Language Models cites this paper.

Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-11T21:21:12.079621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T05:50:20.608166Z digest=sha256:b92436650f162a08e5089fcc2931478a1dc58931fa2c8f5c876a129064bdd91e

Observation 5cea8fcf-d59d-48f1-89e0-2a4697a3e2a9 · inbound

Evaluation of Prompt Injection Defenses in Large Language Models cites this paper.

Evaluation of Prompt Injection Defenses in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:19:28.460702Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-14T21:05:23.800356Z digest=sha256:0a67ab176ba89aa4bda909e96b034bb62f1a31824509c5911af903ba08c8c26a

Observation 5deca162-d313-4484-9760-fe45fbd8fd38 · inbound

Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills cites this paper.

Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T23:46:15.850426Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-07T16:22:49.737626Z digest=sha256:c1d1d9774062da0ec789c25cbdd969975c4ea4a73af436f4bbbebebcb5a49546

Observation 4df578a0-c781-4de1-b581-4a218ecc0751 · inbound

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates cites this paper.

Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-09T05:55:31.844341Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T19:17:06.375875Z digest=sha256:76e7bd0b04e1df1b6415c327e5de997a9ac7530a9d4aeb8e5780bcff1ed1879c

Observation 5ed01e6b-6fc6-47c6-a027-c680e263f2dc · inbound

MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning cites this paper.

MIPIAD: Multilingual Indirect Prompt Injection Attack Defense with Qwen -- TF-IDF Hybrid and Meta-Ensemble Learning Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T02:30:55.043183Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-11T02:29:13.992357Z digest=sha256:40609f0e2f94481b9c0588235b41f3c8bd3a3181eb192fbb5fbc6f4ae560e2c8

Observation 94dece42-48ac-4aa4-9809-3eabdf2dff25 · inbound

Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture cites this paper.

Designing Intelligent Enterprise Agents: A Capability-Aligned Multi-Agent Architecture Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-12T07:56:31.056812Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-12T01:28:08.332456Z digest=sha256:d106cef54e8f2e812eb2b63018af07fedb6ee6263155ab770f424fe5f7209f30

Observation 9ecdb9c3-bf96-487c-82c8-3cb9a3d65a2a · inbound

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection cites this paper.

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-13T05:47:21.316847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T05:46:07.132408Z digest=sha256:2307a5cbba0aea4bc8f2639ffc4820b441330af48ba30019945f79a91f511e6e

Observation d7ea9cee-c29a-424c-a1fc-95159a7899e7 · inbound

Web Agents Should Adopt the Plan-Then-Execute Paradigm cites this paper.

Web Agents Should Adopt the Plan-Then-Execute Paradigm Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:49:41.559958Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-15T02:42:05.644536Z digest=sha256:8ac904495e657c924288d9d46317dab586c79d40a8f44445ec261d0db129494e

Observation 6d920e85-e211-42f2-9b1c-b84621608982 · inbound

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments cites this paper.

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:58:10.879410Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-20T09:58:05.349147Z digest=sha256:e9be6238aea71cb61ef830b6cfbcca7510db9a0ad05a4cc673fa1ef0924a1a11

Observation 96d1112b-1e1f-4495-906d-adc3117086d0 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-20T09:48:11.595740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-20T09:46:42.413501Z digest=sha256:b6028ce702df7af41988cb663c2f3b1f115cfcf6b07824daad01d32156449ea4

Observation 9ba8124f-19fb-4857-8068-ac007779b074 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-22T09:01:20.110761Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-05-22T08:57:29.491043Z digest=sha256:53c3bda653941806c9e96c7c07c5761881d9965ea88a6f857c256f97971a9858

Observation f181d1bb-35c0-4a36-a207-e8d540d349f4 · inbound

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors cites this paper.

From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-06-28T22:12:41.463500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-28T22:06:41.245543Z digest=sha256:f479917a29719f860a95619c4e143c9e424c952c3a7ec4d54e32d2c4960058bf

Observation 555d4ea9-e22d-4319-b0a9-e4c6f1242427 · inbound

Gate AI: LLM Security Benchmark Evaluation Methodology and Results cites this paper.

Gate AI: LLM Security Benchmark Evaluation Methodology and Results Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-01T22:46:19.188961Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-28T15:05:08.411286Z digest=sha256:0a7615dfce1d0278bab36008c3f39c1917e3865267c98cc0b27254c9b172ac86

Observation 3e4c895e-cfc9-4a55-9b54-7af85df3f8db · inbound

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models cites this paper.

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T03:16:33.675784Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-28T10:13:48.860754Z digest=sha256:5afc9785964110779213d73433a363403e6a5a74c786fd408c9ea2e30ebe5967

Observation 38171ffc-1869-4d10-8738-4d7cc4d694bb · inbound

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents cites this paper.

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-07-02T04:16:36.037768Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-28T09:15:57.044886Z digest=sha256:f4a0983fef5a26bccac21c0ad95e722403400a97edaa0acb666d152a68e35e50

Observation b33c16d6-51a3-4269-abf3-cd2c764d9730 · inbound

Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure cites this paper.

Semantic Quorum Assurance: Collective Certification for Non-Deterministic AI Infrastructure Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-07-02T20:47:22.530818Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T20:15:56.875933Z digest=sha256:525423ded15f4cdcfec3578b788cadf6719ebd30b7d6626f893c4ffbf476226b

Observation 39a76038-c48d-4c09-89e8-23658ccc3593 · inbound

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents cites this paper.

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-07-03T01:47:31.928375Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-27T16:15:47.454172Z digest=sha256:55b4a3ea3ece0b9661624b8de4f5ed82450e9fe220640f19ff2dd0e64e923193

Observation a20cd9a1-eef5-4e8f-8222-55fe1691cca6 · inbound

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents cites this paper.

MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T04:57:38.192366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-27T13:33:24.087333Z digest=sha256:9312800348ab8f91a529cc9073e2b1dfbc7f6285301c8b68505ea5eb151a84f8

Observation 8d9d6654-035b-4a06-81d5-39432b32e719 · inbound

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs cites this paper.

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-07-03T05:47:41.229355Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T13:05:57.618969Z digest=sha256:28b6c5769b9ab6ade56a724ef37d6f1aa36bf5f97d954630dfb5200dbc0974cb

Observation 317cc991-7106-429f-8973-67bdeb1617af · inbound

PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents cites this paper.

PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T11:07:07.442032Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T11:07:07.442032Z digest=sha256:22427f2ed92041853bba8ccf0b9afa721340db6ea61d5ccfadc37a7e733e58ff

Observation 33fe266d-6331-498b-95b6-950f61ab31a0 · inbound

Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks cites this paper.

Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-07-03T22:08:59.310448Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-26T23:45:25.770548Z digest=sha256:53927b89bbfc29a0e6158a03cfe724a0a9bd1bfd07b92d5c6bf9916cffea3f69

Observation 850b25ab-2f1e-4164-817f-87a33240546e · inbound

A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots cites this paper.

A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-04T02:09:22.497299Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-26T20:00:14.036515Z digest=sha256:b5e19a0efcdd69d50e8918965d0e6c4161ed2889f48ede984e1cf6eda2a3f1d4

Observation c2abf31c-073e-42f1-a60a-a9089c3a6ac8 · inbound

Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift cites this paper.

Confidently Wrong: Severity-Aware Calibration of Prompt-Injection Detectors under Attack Shift Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-07-04T09:29:44.070733Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-26T09:55:08.178751Z digest=sha256:e304022acb0947a1b0002a525d42961b6386b70e6471579484d158d11feb7b66

Observation a47829da-290b-4947-a457-56cd4adcb915 · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 78

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.893169Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:a29929a85d622a43a454ba88848ce8bb7cefd312ab288ef069230e6281efe692

Observation 882da221-d8ed-4050-bd80-7898a459ec4b · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:70958e64c7c183642d943ad818d492eca1cc81aa9605e5e262095cbb477b9a3c

Observation 322d5c44-c7ab-417d-9221-8c2d96b559fe · inbound

Information Discernment in Large Language Models cites this paper.

Information Discernment in Large Language Models Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T13:26:27.643188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:26:27.643188Z digest=sha256:ce3b4ee2f7c928fb6739e4403e5e59cdd962c31ba6aa6d64bf5d5b1da2951227

Observation db4457de-bbd2-4963-a793-ecef3e38fac2 · inbound

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents cites this paper.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.576853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.576853Z digest=sha256:c05cd5493ebcf6c1d21da3030975a7ae1142c85f9bbff8f407f29d40e588a785

Observation 755f590a-9840-4bb8-8040-56b56c73a6aa · inbound

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls cites this paper.

Beyond Aggregate Risk: Role-Stratified Conformal Risk Control for LLM Tool Calls Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-03T01:25:30.766287Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T01:25:30.766287Z digest=sha256:752da9a4727dfaec6ddcd704662ebe26aa58939b3e8bfc2b53b84b920f3689e1

Observation 6e8d9b35-c683-43d6-a186-a5732b86ad10 · inbound

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges cites this paper.

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-03T00:55:23.831248Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T00:55:23.831248Z digest=sha256:ccc08ee7267d9f6b7c38266ed3cf7a65869e0863e10c93eaf8a731e8ecaaf463

Observation 4e0f8e47-dc08-487c-af06-d08f1e1e2669 · inbound

MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication cites this paper.

MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T22:13:21.497262Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T22:13:21.497262Z digest=sha256:748dded0fbf9978c161f0cc72f6acbabe04d0002c819bd5718bee2175ce2f098

Observation 6bc4f208-44ae-4ffd-991b-98915cc36574 · inbound

Robust Context-Aware Detection of Malicious Instructions in Text cites this paper.

Robust Context-Aware Detection of Malicious Instructions in Text Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-08T13:19:01.961178Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T13:19:01.961178Z digest=sha256:d4c1039ed8bfd3a0d811f3697fb08dc6c8516ad4e8431cc5621bfc9df14a9cdc