Pith. sign in

Paper Citation Record · LEDGER

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents

As of 9 August 2026, this Paper Citation Record lists 69 of 69 outbound references and 0 inbound Pith citation observations for arXiv:2607.14651.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.14651 v1

Coverage vector

measured 69 of 69 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T01:34:16.274037Z

measured 69 of 69 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

69 of 69 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved69
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation efb1544f-4945-4656-b4e8-d9142f5b2b0c · outbound

This paper cites GPT-4 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.350835Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.350835Z digest=sha256:c460fdac9491f8e9ef3d44e4558b4031b2b791e0741ef0d5abc6324da855cc75

Observation a16b1393-4bed-48d8-a45e-8dfb1a9a37d1 · outbound

This paper cites Security in LLM-as-a-Judge: A Comprehensive SoK.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Security in LLM-as-a-Judge: A Comprehensive SoK

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.462689Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.462689Z digest=sha256:fdae7b36237182ed261681ef88dbbfd003798908b0d2a35158cb225983a57266

Observation 02f83907-c1ef-45eb-a03b-56d8ef9170db · outbound

This paper cites Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Ipiguard: A novel tool dependency graph-based defense against indirect prompt injection in llm agents

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.573233Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.573233Z digest=sha256:33d330195c854035db007aec8ec74d8321efa5785873390365c18bf430814f09

Observation 23885b22-d53c-4feb-a2c2-3214076d8a0b · outbound

This paper cites One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.633226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.633226Z digest=sha256:6eb4a31018e8b9460b2a5e12a3a4656768e6ca1303b4ea4254f520557feb91ae

Observation 899b38ee-2629-4b4c-b43a-835346108d79 · outbound

This paper cites {StruQ}: Defending against prompt injection with structured queries.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents {StruQ}: Defending against prompt injection with structured queries

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.702664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.702664Z digest=sha256:25a8e1e6476e71c2f883037a054f1c9d20490442add86b59c0e7fb178cad25b1

Observation 7500767e-94d2-45fa-b1f7-0b16d9e7e005 · outbound

This paper cites Defense Against Prompt Injection Attack by Leveraging Attack Techniques.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Defense Against Prompt Injection Attack by Leveraging Attack Techniques

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.793732Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.793732Z digest=sha256:73e144d9293107be548038a8af5bc0f08bfdceb80cd12878354bdf1341085097

Observation fb56b482-d5b2-45c1-8983-a331492f9308 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37: 130185–130213, 2024

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.887486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.887486Z digest=sha256:d40ea7b80816a99729643bd0f5d8f9238b04b57fe7cfe6c604add69eec8740d8

Observation 55026f67-9df0-46e6-a444-49abfc50e492 · outbound

This paper cites Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Contextcite: Attributing model generation to context.Advances in Neural Information Processing Systems, 37:95764–95807, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:09.994388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:09.994388Z digest=sha256:5afcd04555520114df96768731f31d72376944c77932b53f49cf9d1e751592cf

Observation efc735da-d2f6-41ab-a156-335d952c04aa · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.059236Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.059236Z digest=sha256:ba35988cf4b326d8afe2ef2a248b03737e827e04468f630ac057591a46ac7bc1

Observation c120fc0d-d989-4756-b503-0bd6675f7431 · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory injection attacks on llm agents via query-only interaction.arXiv preprint arXiv:2503.03704, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.167616Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.167616Z digest=sha256:510f20fb7e137212d7f852255423876d124836f3bb290e8d4ee0f9df65ea5801

Observation 16582e86-54e5-40b3-aaec-3d6c699ee57f · outbound

This paper cites A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A practical memory injection attack against llm agents.arXiv e-prints, pages arXiv–2503, 2025

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.271092Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.271092Z digest=sha256:c3d860a73e00f71064c846dd4a5806bcd8f27ad55c4202f4870d5e2ea0053a07

Observation c0b78879-f55a-49a5-b2f3-82b9cba460b2 · outbound

This paper cites Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory for autonomous llm agents: Mechanisms, evaluation, and emerging frontiers.arXiv preprint arXiv:2603.07670, 2026

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.368923Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.368923Z digest=sha256:eeb166384554641803c3fe339a1ae0bf680d644177141118b39bfc73c51c7e88

Observation b52b464b-ad90-4bc9-a7c8-1f005b15d842 · outbound

This paper cites Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Backdooragent: A unified framework for backdoor attacks on llm-based agents.arXiv preprint arXiv:2601.04566, 2026

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.453299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.453299Z digest=sha256:b69faf8f4487a009ded23e085657548a5df4f0a897ae7e771f0ae71cee9c6f0e

Observation 83c2cbb1-59ac-4a51-8518-4b3fc2388519 · outbound

This paper cites ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.541857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.541857Z digest=sha256:73c424225ed382ae841dbf6b9ac74d2df9638167ef97fa3929d4056a54c810d5

Observation 8440165c-5f2e-4d67-a00c-9f88677dacda · outbound

This paper cites Gemini api documentation.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Gemini api documentation

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.611404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.611404Z digest=sha256:329034df03a4b107eeea45e79935fb212047e13ef76b99ea0f4f57457a57a69a

Observation 059abb50-3316-47b0-a20e-74ededbc0ab1 · outbound

This paper cites The Llama 3 Herd of Models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The Llama 3 Herd of Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.671967Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.671967Z digest=sha256:786a024337c3c92d34ec6fe0a7c6f2d5c84f1c5ca68fa186750fd7042d91ac1a

Observation 2ec1c44d-63e1-4917-8d9f-61c102c43e99 · outbound

This paper cites A survey on llm-as-a-judge.The Innovation, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on llm-as-a-judge.The Innovation, 2024

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.776015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.776015Z digest=sha256:324e5eeeb441d8b7ad43102449b2da45063c145ba4c110a98e69ef45581e9653

Observation afa007e4-dfd9-4410-9512-eba3d15c3ffb · outbound

This paper cites The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The emerged security and privacy of llm agent: A survey with case studies.ACM Computing Surveys, 58(6):1–36, 2025

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.831346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.831346Z digest=sha256:49ac1c906b530efd53e2970f12d76717020aaefdd65944b85c0ec361142d7c1c

Observation 0b553bd3-21fc-473c-9d75-8839b2b7c32c · outbound

This paper cites Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.887333Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.887333Z digest=sha256:3a2fa17e481c7e2729f0ada1c72e79aa65cdd3122d0281106e4bcd6310cd756d

Observation 82fcbff8-f1e7-481f-964f-cad1ddfca6a6 · outbound

This paper cites Retrieval- augmented generation with estimation of source reliability.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Retrieval- augmented generation with estimation of source reliability

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.951513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.951513Z digest=sha256:1e1ef3dbb6094cd428e4cd130f5d5cb6e0309315252b9b91a8b1ff15e00f234a

Observation 02c2249e-63c4-4c56-85f9-fddacacfac84 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:10.996715Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:10.996715Z digest=sha256:4c0b1276249faf91c3f3762461c6e15f56f4afc0d9dff3c67adb9a2c7d193f46

Observation 82c12249-9869-49e3-af51-8748428f3423 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.069663Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.069663Z digest=sha256:7c0a41845de651e5103ca0a9cf2045623b7940dc3376cf5eb1e512d8ced80bc6

Observation a7e9a3dd-8055-45bc-b155-a4f2613bbed2 · outbound

This paper cites Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Swe-bench: Can language models resolve real-world github issues? InThe twelfth international conference on learning representations, 2023

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.160512Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.160512Z digest=sha256:bef99c50da905dcc27ebf6ae82b90991b8a3de29e316648011ad15d6761d71da

Observation 4f54209b-39ae-4118-8ba6-1a9d344c7a2e · outbound

This paper cites Memory os of ai agent.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory os of ai agent

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.223600Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.223600Z digest=sha256:c5dbeddecc5b3b3ace4943fafc14beda76c18c443a70d240ee588dc31dbf8246

Observation 6ca8f49f-5d36-498f-aaf9-9beb9e4c8a40 · outbound

This paper cites Certifying LLM Safety against Adversarial Prompting.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Certifying LLM Safety against Adversarial Prompting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.280395Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.280395Z digest=sha256:e5941014aad808b805bec3fc85d94e1db08375c7341789a06b00a11965d6d993

Observation bf7399f4-f221-4ddf-a3eb-ba67ebea20e0 · outbound

This paper cites A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.340723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.340723Z digest=sha256:657613ffb56cc719b2cc672213da2e22611397e4557af99ae9590e2c0380ad88

Observation 43fadf10-30fb-4f29-b8d8-6bcd5169fb13 · outbound

This paper cites DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.398735Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.398735Z digest=sha256:43d9912ce580f4c11b64d1c9f49258f331fb6a3673c3146ab045e96059d19f05

Observation 293ca6f7-b29d-41c7-9bfd-71b0100d51d5 · outbound

This paper cites DeepSeek-V3 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents DeepSeek-V3 Technical Report

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.457582Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.457582Z digest=sha256:3068dcc4dd040c09d7c689b12eac573fd3a98dbd6615e1c8d451f4ad5c513f76

Observation 87fafa08-223b-4569-84d6-8ec1e5486ee0 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Formalizing and benchmarking prompt injection attacks and defenses

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.522427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.522427Z digest=sha256:831af16bedfdb8b6b18b03e2072bee0623c59ffa61693b96c80ae5f2ff286a5f

Observation 346e16d3-252a-4336-9bdb-d4cc6974ce70 · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Datasentinel: A game-theoretic detection of prompt injection attacks

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.614142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.614142Z digest=sha256:d0ac784155d350b7471308205f5ec444fb375f2a2309b7125b59f489675e339c

Observation 16249de5-45d1-4d97-b630-bd34820475e4 · outbound

This paper cites Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.697836Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.697836Z digest=sha256:40b80c86ec9dd045a5d27be5feaf3b698e1dfcd3420298d48a6f5a3d991d482e

Observation 579581fd-396e-42e2-a371-16af1cc54dd4 · outbound

This paper cites Prompt-guard-86m: A classifier model for detecting prompt attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Prompt-guard-86m: A classifier model for detecting prompt attacks

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.754997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.754997Z digest=sha256:81bc7b8c19d39bab8185297daca0dfcb14964f68456ea04aee081ad7492b69bd

Observation c7f9ee4d-815c-46a7-9c18-3ea70c40d69e · outbound

This paper cites Towards lifelong dialogue agents via timeline-based memory management.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Towards lifelong dialogue agents via timeline-based memory management

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.819294Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.819294Z digest=sha256:ee62b6d45468aecae1a3cdcd295de59f445ddc07d1652865b8ca3b4171307612

Observation cc4ee84f-140b-499e-b585-63e6d0cc97db · outbound

This paper cites Memgpt: towards llms as operating systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memgpt: towards llms as operating systems

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.873849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.873849Z digest=sha256:387ecd0a2a9e8b857462ae00a73817f69e681d35b7a994e4bb71fe9a4e0d8b79

Observation d27938c0-b181-402b-95a3-9da8334ed102 · outbound

This paper cites Generative agents: Interactive simulacra of human behavior.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Generative agents: Interactive simulacra of human behavior

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.936398Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.936398Z digest=sha256:9f1034a556ee871e150f979f7d0d635d86737e971f2ce47cb840dc8611d3ee78

Observation 849b30c4-d735-4143-ba6d-9f15ca477d56 · outbound

This paper cites The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The berkeley function calling leaderboard (bfcl): From tool use to agentic evaluation of large language models

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:11.976036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:11.976036Z digest=sha256:1c90f43eaf91681b4b0d3168ecd09f71fb249253d4f88d8234ec5f491debe36b

Observation 362c6fdb-3e3e-4d7d-b9aa-48d86805e5b1 · outbound

This paper cites The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents The why behind the action: Unveiling internal drivers via agentic attribution.arXiv preprint arXiv:2601.15075, 2026

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.062003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.062003Z digest=sha256:6a245fdb618113082cc6c64074f078381fd4f66d27499c6d4cdbd873a2442bfd

Observation 9fd0ca62-34f2-4e1b-808b-0bcfc5047ac1 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Toolllm: Facilitating large language models to master 16000+ real-world apis, 2023

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.121949Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.121949Z digest=sha256:237db51655a19a82ebb32eabdae085af85bff52cd2ac3eb4c07ca4c00fca9e50

Observation 52db8d48-94bf-45bb-94b9-deb16acafb7d · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.201286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.201286Z digest=sha256:989d78f3a2d8c6dd835a950b91725e0cb74e62affd9e7b260fe74f9d740e7f42

Observation e868fda4-cf0d-444b-9bd6-e666565699c6 · outbound

This paper cites Evaluating Memory Structure in LLM Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Evaluating Memory Structure in LLM Agents

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.248312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.248312Z digest=sha256:61e2e4ee738402935b2d7f03760b8f38f32470bea81806cfc1f5686e048abb53

Observation c1b06b0f-111c-49b5-b599-615b192fd5e8 · outbound

This paper cites OpenAI GPT-5 System Card.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents OpenAI GPT-5 System Card

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.314535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.314535Z digest=sha256:7408eb70fec7646ea6315c7554586fb1d32be99f5775a79f7311b810a3d1d9e0

Observation 10b60ffa-218f-4542-8754-7862088de365 · outbound

This paper cites Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memorygraft: Persistent compromise of llm agents via poisoned experience retrieval.arXiv preprint arXiv:2512.16962, 2025

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.426621Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.426621Z digest=sha256:adebf04cd676dc9f79697b6145de2b6bec2564b531c781981bdffae30d7b98c5

Observation b71f3248-c4b8-4034-961e-497c3c4634a0 · outbound

This paper cites Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning attack and defense on memory based llm-agents.arXiv preprint arXiv:2601.05504, 2026

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.590292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.590292Z digest=sha256:a229a4101094216cdbc9119b7659a53a0ec25dad28e607d04de8ba09e1816329

Observation a5e3e748-0d2d-4e75-8c52-dd05a557b735 · outbound

This paper cites Membench: Towards more comprehensive evaluation on the memory of llm-based agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Membench: Towards more comprehensive evaluation on the memory of llm-based agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:12.917754Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:12.917754Z digest=sha256:cc3cc860523c309104087174108968003c8a0d1a6819c4b17d6ec92cc1fb4a9f

Observation 92944e81-a041-401b-8bb5-220526e741ed · outbound

This paper cites RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.121805Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.121805Z digest=sha256:a7a6de886c934b373bbcf492a306cba1d8f606aba423109c2137cffaaba49cf5

Observation 5a3a6e97-80e6-46e1-b767-4a1ac706cc97 · outbound

This paper cites In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents In prospect and retrospect: Reflective memory management for long-term per- sonalized dialogue agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.276252Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.276252Z digest=sha256:4df30921a6bb99455e9d5a39e593c404916d4103985b954d7998a5a771c90a27

Observation 047b3bea-3a53-43f8-b81a-d196d496aa46 · outbound

This paper cites Injecmem: Memory injection attack on llm agent memory systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.530907Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.530907Z digest=sha256:95e01048bb1638da070f6ac11025623b42540846503755e5b69c66754e83b213

Observation 80a9a459-ee93-4e71-8f5a-86718df94357 · outbound

This paper cites Injecmem: Memory injection attack on llm agent memory systems.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecmem: Memory injection attack on llm agent memory systems

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.705785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.705785Z digest=sha256:4214fe63777145cf6b0d74828727081633ecfad552f3f6baa373a7bc3e2db98b

Observation df01ad7e-7082-4b78-b5b4-ef1160df2dcb · outbound

This paper cites Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Memory poisoning and secure multi-agent systems.arXiv preprint arXiv:2603.20357, 2026

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:13.873278Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:13.873278Z digest=sha256:8d4e919ed25b8e7d671b65e12262e15c9a2625a5a5b38aa5c7a7bc1cb0357737

Observation c5f1adff-74f3-42b3-8aab-02e0106ad9d2 · outbound

This paper cites Unveiling privacy risks in llm agent memory.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unveiling privacy risks in llm agent memory

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.048192Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.048192Z digest=sha256:4065eae14d16e1265c56e77ff864e41116fed924976580d85efd619668a19f84

Observation 876712ef-fdda-4d18-99f1-5e966dce468f · outbound

This paper cites Badagent: Inserting and activating backdoor attacks in llm agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Badagent: Inserting and activating backdoor attacks in llm agents

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.211428Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.211428Z digest=sha256:4d438b6bffdfac01d5f11442ff7257adca046646654dad1bc4e2d90b7d78f8d4

Observation c3e2e727-36c2-4e6f-8d96-777960f3524b · outbound

This paper cites A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A-memguard: A proactive defense framework for llm-based agent memory.arXiv preprint arXiv:2510.02373, 2025

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.466738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.466738Z digest=sha256:df4afe3c224220ac701d5881c2c018a01a37296d5afbe22f1634ee688227dcb6

Observation 82b6d6ba-3647-4f94-b88b-14bc2e4e6090 · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.Advances in Neural Information Processing Systems, 37: 52040–52094, 2024

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.714004Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.714004Z digest=sha256:193a631df78101a1f0117110b567eab4d8892bdbab30bd3847fd4bb278456e9f

Observation 6515615e-6a8f-4969-b4d3-e622d0e6c7f9 · outbound

This paper cites TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:14.888330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:14.888330Z digest=sha256:c6594bd76c3578eabef146758495d06b1bc1011784ffd5b9576a6fb3cd52f6d4

Observation cc7fd6a9-b07f-41db-9747-5a38fc858013 · outbound

This paper cites Qwen3 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen3 Technical Report

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.040513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.040513Z digest=sha256:627ca3ec58490be1306b42f1794d0ef8be4abcb2f677807799dc3561bd09d177

Observation 7108c89a-f2b8-407b-a2c8-bc0c1e275ef2 · outbound

This paper cites Qwen2.5 Technical Report.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Qwen2.5 Technical Report

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.185128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.185128Z digest=sha256:1da077261d436c8f602136726926c1f4c0725e7c23e0b381eaf660414dc5953a

Observation b9f9abd6-c324-4231-9331-7a2829d983e2 · outbound

This paper cites Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Shieldrag: Safeguarding retrieval-augmented generation from untrusted knowledge bases

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.324713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.324713Z digest=sha256:558ba95a6ba5ec06e8ef6b192dd8d1086f036f571164a3dffd9d988b93207daf

Observation 03afb3c0-344e-426a-97f4-dc452860c5c2 · outbound

This paper cites Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Watch out for your agents! investigating backdoor threats to llm-based agents.Advances in Neural Information Processing Systems, 37:100938–100964, 2024

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.394297Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.394297Z digest=sha256:27dd09d0dbb3611943de93ebe2f60ce511d14d2556ae8ed0ae8c9ecd4bee74f0

Observation 8fb362eb-347a-4ab8-8738-19a31ef43ab1 · outbound

This paper cites Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections.arXiv preprint arXiv:2602.15654, 2026

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.468500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.468500Z digest=sha256:2e64916759cf4cea6a34c02639ca3615cfc469135f1e9a67abc65d815a9d1516

Observation 24de91c5-82a8-4523-8f3c-da6301a92f30 · outbound

This paper cites $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.551445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.551445Z digest=sha256:f6aa552e9ce897a71dbd26139a96a4af50deb688172b065de703e1d643c86fbb

Observation e4219fa4-fa52-40af-9e37-97625fbcc785 · outbound

This paper cites an unresolved cited work.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Unresolved cited work

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.637578Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.637578Z digest=sha256:150b72d2d35bba9042147f8724afea07a74654f96a5fdc590a283f470075dc52

Observation f0618914-3d92-438a-abbb-8906a7a2e0f0 · outbound

This paper cites A survey on trustworthy llm agents: Threats and countermeasures.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A survey on trustworthy llm agents: Threats and countermeasures

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.701912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.701912Z digest=sha256:a417098a49294d8067553e4958824f445980d6b81ad9d364bd178acb52f025c7

Observation 3cd06f6e-8d1a-4ffe-822c-7ccfb03ddae0 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.780493Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.780493Z digest=sha256:f867a9b171bf0076916bb3b06295afe17de5f6bf3e5b5101895eddc57ce8520d

Observation 07bce797-16cb-4213-b2ba-8a92532579f1 · outbound

This paper cites Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Who taught the lie? responsibility attribution for poisoned knowledge in retrieval-augmented generation.arXiv preprint arXiv:2509.13772, 2025

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.854510Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.854510Z digest=sha256:a5762d59d78f7619d1b21af1a8c8f2cfc3ca0aa29a47fb85354ec43c20721a49

Observation 56c1e3e7-ccbc-4a82-9b88-1c7ee188afd6 · outbound

This paper cites Traceback of poisoning attacks to retrieval-augmented generation.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Traceback of poisoning attacks to retrieval-augmented generation

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:15.939036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:15.939036Z digest=sha256:7c559ca91cc15570b57da6af735a407f6844a105f4c920cca2c7e6892d21b842

Observation 5f5d9c08-2fe4-495f-bbb6-56a7c896eafc · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.008911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.008911Z digest=sha256:55a7e92f7808f97a4b95028d337bb8b8c06b71e09643216fbab35783ae89c0d6

Observation 9cc15a56-5bf4-4b03-a668-3bf0cee45f8e · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.107470Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.107470Z digest=sha256:9fb663175545c5e9d819f2f9429180626bd9de640af38fbd5dfadfbe2f02c45a

Observation 39fe3ff0-ba5a-4d15-be70-f549458eed3c · outbound

This paper cites Judging llm-as-a-judge with mt-bench and chatbot arena.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Judging llm-as-a-judge with mt-bench and chatbot arena

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.185613Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.185613Z digest=sha256:935c407057746dc29f3068a7cc0d8c9d94d3171366eb4732deab22588b678c62

Observation b2a5ba85-6a29-48de-bcc2-04b52117f3b0 · outbound

This paper cites Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents.

MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-02T01:34:16.274037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:34:16.274037Z digest=sha256:a3d3ab1997c8dcf27f5dae1b8be10562cef3da632e01f7c74832545d11487db6

Pith citing papers

No inbound Pith citation observations are available.