Pith. sign in

Paper Citation Record · LEDGER

Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 14 inbound Pith citation observations for arXiv:2503.00061.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2503.00061 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 14 of 14 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 14 of 14 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T15:41:21.733238Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T10:49:46.745286Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 8369a571-a0fd-49dc-a7f1-c3f6ce9a8943 · inbound

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks cites this paper.

EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T15:41:21.733238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:41:21.733238Z digest=sha256:034dbc07bb2006147f5fc7d10fe141ffb980ab513f6767820bff6330799e4a5b

Observation 51ccba5c-0fd9-4e72-a5ab-81c28a9ee95a · inbound

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models cites this paper.

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T23:01:04.689987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:01:04.689987Z digest=sha256:b27eed921fe40fa766c111187a176ef8954dbf910227da1954558ed3a5a94cbd

Observation 9ea67daa-1d07-4f90-9671-84575271cc77 · inbound

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree cites this paper.

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-06T15:52:56.834425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:52:56.834425Z digest=sha256:31ad2769d00b7837971e39a67902dbfdedd261843150bce759c2ec2981b37522

Observation 0a56cf42-0de8-4745-9800-6888724488e7 · inbound

Evaluation and Benchmarking of LLM Agents: A Survey cites this paper.

Evaluation and Benchmarking of LLM Agents: A Survey Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 113

Resolution
unresolved
no resolver link, observed 2026-08-06T12:44:21.855663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:44:21.855663Z digest=sha256:7962d44294cf0d9efeffceb7911ba384fe2aff94d4f60af7b5cd00a3a12ad81a

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · inbound

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment cites this paper.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:d7b0b8cbc79f1d3053bca422cfeaf20630806994b8b0fd10ebba48a6f4211b96

Observation aaefaa14-f0e5-4ae6-ae8c-704b169e0d45 · inbound

Prompt Injection as Role Confusion cites this paper.

Prompt Injection as Role Confusion Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T20:20:17.489468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-15T20:18:44.156726Z digest=sha256:9431dbf2941e45dcfa1b2568b27e4fac4dab509b0b13a888366849f2acdf47c7

Observation 4ba43b50-8c77-4efe-b4aa-401bbf253463 · inbound

Prompt Injection as Role Confusion cites this paper.

Prompt Injection as Role Confusion Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T21:46:13.122809Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T21:46:13.122809Z digest=sha256:a8d0096e6f75b43d93f29cebd5b0e9b4a2f5f58e0f4270b31f21462784510969

Observation 9a401447-f264-4022-b7b6-b7ad9e7d6c02 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-10T11:55:21.361407Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T04:42:33.450658Z digest=sha256:a79e32f2bdf5e40d143980961cba0919fd9acd9178f76cbeed2a8326d6991080

Observation 2f46234b-ec34-4284-b0e3-1f5d923705b6 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-21T00:53:53.069031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-21T00:51:22.907932Z digest=sha256:1ffb75659d95904312440dec92d0a96005b2aea790df4f72aa2a9fac131c64ee

Observation 8a1698d4-9ac6-4d00-906b-66f0ce2ae004 · inbound

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection cites this paper.

Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T15:56:48.909336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:56:48.909336Z digest=sha256:ded9edfa04beb080799670fa597f2ca0cb3186ae3b5472fa737a2234b2ada942

Observation 44b2861b-6791-41e5-a7f2-f7cb2cfe1322 · inbound

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults cites this paper.

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-06-28T20:52:38.007689Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-28T18:18:52.472535Z digest=sha256:ecee5d007937ecd0550142840f465457327f1eceffc0f172bffaedbf7d0931a9

Observation 7b3c326f-5f17-4e07-b878-cf799d84a27a · inbound

GIF: Locally Sound Geometric Information Flow Control for LLMs cites this paper.

GIF: Locally Sound Geometric Information Flow Control for LLMs Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 56

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:49:46.746919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-26T08:24:49.908288Z digest=sha256:6aba7e55029cb4fda8ac10a6be6d272c5afd65c0591df6708bfb13c63fc3b03f

Observation a693f6b7-cb2a-490e-9059-1d37a9adb93a · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 30

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.903048Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:74424b7d6ba714cec4262ce55f5b2f22075744fba54d9b2af36074641e03ddde

Observation c508a3db-130b-452a-958d-286fec2ad66b · inbound

ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments cites this paper.

ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 62

Resolution
unresolved
no resolver link, observed 2026-07-31T04:54:36.195909Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T04:54:36.195909Z digest=sha256:0251fff4b93252233e2d1f54fae966ffd0e3bb6617cbfc4d4927167c38c02fd2