Pith. sign in

Paper Citation Record · LEDGER

Context manipulation attacks : Web agents are susceptible to corrupted memory

As of 12 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 6 inbound Pith citation observations for arXiv:2506.17318.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.17318 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T23:59:59.384340Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00

measured 6 of 6 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-05T11:11:40.945299Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-08T00:24:22.457387Z

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy2
  • unresolved25
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6c110de6-a08c-425a-81ed-a4ffc0ed1515 · outbound

This paper cites Agent-E: From Autonomous Web Navigation to Foundational Design Principles in Agentic Systems.

Context manipulation attacks : Web agents are susceptible to corrupted memory Agent-E: From Autonomous Web Navigation to Foundational Design Principles in Agentic Systems

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.633517Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.633517Z digest=sha256:99c8c41469dfed6bfd6e720e61b483fbdf5218e32c84c4309b991415d9ce8c7f

Observation 32db510e-a853-437f-9d8a-d7bde270be68 · outbound

This paper cites Defeating Prompt Injections by Design.

Context manipulation attacks : Web agents are susceptible to corrupted memory Defeating Prompt Injections by Design

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.114750Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.114750Z digest=sha256:808934a58d23324ac3e762fafe545c89ba4dae693750a3c4bc9efb347a60d001

Observation 9c5b76c8-0fb1-40f1-8f00-36e9c8a21435 · outbound

This paper cites A practical memory injection attack against llm agents.arXiv preprint arXiv:2503.03704,.

Context manipulation attacks : Web agents are susceptible to corrupted memory A practical memory injection attack against llm agents.arXiv preprint arXiv:2503.03704,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.199362Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.199362Z digest=sha256:2623b8d6b3078e6b7d2c823728e0d6c4c5182fb3a9a02df2b98f066cfaf6b645

Observation c1667d30-140e-4145-985d-24abbef7fc40 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Context manipulation attacks : Web agents are susceptible to corrupted memory Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.399538Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.399538Z digest=sha256:52086d42181cd69343e0586a5de93026922bdabda2c0df11a8739e344edcb654

Observation 7e80cdd0-7a0d-4a06-b73c-57daa70636ec · outbound

This paper cites Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training.

Context manipulation attacks : Web agents are susceptible to corrupted memory Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.453507Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.453507Z digest=sha256:099adedc02d902d415fe7c12716bd0d1f64992d8c5b0e82d9471ba659f31f9ed

Observation 7ab7792c-e789-4154-a3b6-519601f1212d · outbound

This paper cites Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.578866Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.578866Z digest=sha256:e92c75e01813020a7e2c17720c84cb08085802c279900b6077db8ce73c756752

Observation 22a7d239-5c65-481a-ae70-947d5b649241 · outbound

This paper cites AutoGLM: Autonomous Foundation Agents for GUIs.

Context manipulation attacks : Web agents are susceptible to corrupted memory AutoGLM: Autonomous Foundation Agents for GUIs

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.655062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.655062Z digest=sha256:79cf9135848cc8766524179ac3e71caf4a4e6ffa58757847ad0992b486ca8f2c

Observation c400cb14-701a-429e-8ef4-b3292688f52d · outbound

This paper cites Accessed: 2025- 05-21.

Context manipulation attacks : Web agents are susceptible to corrupted memory Accessed: 2025- 05-21

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:00:00.657809Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-06T23:59:57.753830Z digest=sha256:9a9589961bff40e4b13766929a561476a702a3b7eabd3094ed11a95f47d1fe75

Observation d3b431d1-5f74-4b7d-b0a5-47b2ff5c9453 · outbound

This paper cites Nagli, G.

Context manipulation attacks : Web agents are susceptible to corrupted memory Nagli, G

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:00:00.419469Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-06T23:59:57.843937Z digest=sha256:40567eb9b3a305a4caff941bea40cca23c6ce0425763a2f134cb63eed0626eb0

Observation 0f711ea3-6b3e-41cf-8876-56db82a3083e · outbound

This paper cites Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In.

Context manipulation attacks : Web agents are susceptible to corrupted memory Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.968116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.968116Z digest=sha256:b00aadae17824d89d84d66b1e9df2a60f934f795a051b24605ec30e09e64eb01

Observation 97c31c83-b164-4164-8d32-1c6d4c0dcd73 · outbound

This paper cites Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.046495Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.046495Z digest=sha256:66e8d6b035c079dca37fa99734a2aeee6dc06397ebc5ee074a49117dd08e17f6

Observation c560ef41-3caf-492b-8d59-6ee5f40b70d6 · outbound

This paper cites Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.150222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.150222Z digest=sha256:cc42f6eab9db83a05c3e20a82db76c73a91a9eefaa270f78e82e3c9ea1af5562

Observation 854fd232-5147-4956-813f-04f42650ce18 · outbound

This paper cites NaviQAte: Functionality-Guided Web Application Navigation.

Context manipulation attacks : Web agents are susceptible to corrupted memory NaviQAte: Functionality-Guided Web Application Navigation

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.207154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.207154Z digest=sha256:d4132e777d708aa326a255dc903ba8962412cba0053f06516c1d7111298384f5

Observation e5eb8fc5-f132-4016-a889-12123a376cd2 · outbound

This paper cites ScribeAgent: Towards Specialized Web Agents Using Production-Scale Workflow Data.

Context manipulation attacks : Web agents are susceptible to corrupted memory ScribeAgent: Towards Specialized Web Agents Using Production-Scale Workflow Data

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.320838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.320838Z digest=sha256:b16df860ce904995413f6e8fa653a2afc188fd468d34a1cad44f838072f92d15

Observation ccae596f-1585-4b59-8a4e-918da8565249 · outbound

This paper cites Learn-by-interact: A Data-Centric Framework for Self-Adaptive Agents in Realistic Environments.

Context manipulation attacks : Web agents are susceptible to corrupted memory Learn-by-interact: A Data-Centric Framework for Self-Adaptive Agents in Realistic Environments

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.476318Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.476318Z digest=sha256:537421dda7ae40f4f730b8da40bfc3b129902c6d4089c80ac1c8691c431808ae

Observation 9a6b55bd-94b3-4536-acde-883b10d6bc7e · outbound

This paper cites Cognitive Architectures for Language Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Cognitive Architectures for Language Agents

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.569340Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.569340Z digest=sha256:421dd050a257e3d9f1484c24ebdd980a9709c34b4987da8dc893b925bf27aa97

Observation 2248a23a-f81a-4310-9ea8-e2998a16f579 · outbound

This paper cites OpenHands: An Open Platform for AI Software Developers as Generalist Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory OpenHands: An Open Platform for AI Software Developers as Generalist Agents

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.681501Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.681501Z digest=sha256:3449278a93137b1f3909ef144318b85fdd6ef601ddc6b56328238567b88eab22

Observation 8d6ba60c-0766-45ab-b2ca-771efd58fc12 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.834733Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.834733Z digest=sha256:44b66a41a12cbf47961ea70ccb5872272bd6a6a6566c64018c4ae6c4f6a83bda

Observation 2744fd10-c728-4929-859f-1aba7df71045 · outbound

This paper cites Effectively Controlling Reasoning Models through Thinking Intervention.

Context manipulation attacks : Web agents are susceptible to corrupted memory Effectively Controlling Reasoning Models through Thinking Intervention

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:58.885764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:58.885764Z digest=sha256:8b0b3ef1bbc1b925cb7e4a9a7444d596ffa324eca29925f5413bb764d1b5a1e0

Observation 62995c05-718c-492e-b6f1-297d1fe614b3 · outbound

This paper cites AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.024265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.024265Z digest=sha256:bed246c0844b571150e221a4794c4002e36cf811edb4b0521928c6891f9829b1

Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.158675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.158675Z digest=sha256:c99b7f82e1aee0a6226b9ba914148da5e4429f996e3518113d96731aa12c8353

Observation c888e957-68cf-4710-acc6-12e5f1948611 · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.304589Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.304589Z digest=sha256:b562b86df86dd0154e266cb0ee1d828686050c269d7051f9bddda69f091d9f19

Observation d51fba25-3e83-422d-a8e8-dd541d5accef · outbound

This paper cites GPT-4V(ision) is a Generalist Web Agent, if Grounded.

Context manipulation attacks : Web agents are susceptible to corrupted memory GPT-4V(ision) is a Generalist Web Agent, if Grounded

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:59.384340Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:59.384340Z digest=sha256:f1ca08bef3c195cfa01f7a74653fe8fb7628a866f9540b4f0b7f7bfbfdaf0936

Observation 1dcae755-f2e7-4186-a403-9fce4adccbfa · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

Context manipulation attacks : Web agents are susceptible to corrupted memory StruQ: Defending Against Prompt Injection with Structured Queries

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.849987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.849987Z digest=sha256:ffba4cd7f5a5246c2b3913580fe440b7a70e4026052ed4a6379f2962929bbec3

Observation dee9f153-8a10-4e6f-ad5b-794bda4ddd19 · outbound

This paper cites WebVoyager: Building an End-to-End Web Agent with Large Multimodal Models.

Context manipulation attacks : Web agents are susceptible to corrupted memory WebVoyager: Building an End-to-End Web Agent with Large Multimodal Models

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:57.316081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:57.316081Z digest=sha256:cf5ae83e37554d4d0a7b587d3bc128a94eb563a36913355aa2d9609e629d649b

Observation 2a2103e8-0b56-46a2-9c61-afed381238ed · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

Context manipulation attacks : Web agents are susceptible to corrupted memory Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.775981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.775981Z digest=sha256:10cc7340c0038ee284d151422e2815cddc01fdfbd695cc79dd5cb99fcb5c8146

Observation 0235cebc-d9cf-42b2-84c8-6fa715484961 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Context manipulation attacks : Web agents are susceptible to corrupted memory AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-06T23:59:56.937292Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:59:56.937292Z digest=sha256:531501ede04197e9767b2670ce2f1249013e5e2d7cc5eb9bf5358acdd64a5e86

Pith citing papers

Observation b0eed74a-d1e3-40ec-8f15-ffd3ad4cb840 · inbound

Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution cites this paper.

Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-15T00:58:26.262828Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-15T00:55:00.205075Z digest=sha256:6ad187d3e93f6c5878c5593e55624c2c853671222387e6b7e63232deaef639b1

Observation 8a349daf-1cd5-4ab3-85cd-5874eca60d1e · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 67

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:21:10.228512Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-09T17:13:47.722098Z digest=sha256:1a559ae4e84906f1620d405680b05160de02c4bde9f73578959259fc7c477051

Observation fb210899-fbf0-4cbf-b4e3-ff2401b488d9 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 66

Resolution
verified exact
arxiv_id, observed 2026-05-19T17:32:41.624005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-05-19T17:30:22.481943Z digest=sha256:73146e2020776548e680b24b11d8c0e42825b457c4cd108d8c7ceaae5e24d10d

Observation ab84a808-fa4c-414d-a6ee-ce1b41f44785 · inbound

ElephantAgent: Contextual State Continuity in Agentic Systems cites this paper.

ElephantAgent: Contextual State Continuity in Agentic Systems Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-07-03T14:08:21.374393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-03T14:06:04.996981Z digest=sha256:a0e0d6f10b954e2dec9e7e529ede605598703447afd27780bb93dd74cbfa246a

Observation 235bf3eb-2b0a-4441-a2dc-a1f1b23270b8 · inbound

When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents cites this paper.

When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 40

Resolution
verified exact
local_arxiv, observed 2026-07-08T00:24:22.459420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-08T00:18:55.016013Z digest=sha256:4eb601471391a9d5555708ca2856f8c8e606b35a05f7b95635c4adf1d9235eb2

Observation 88c2e2f8-c8e8-4f19-8a87-23e39c6d2a30 · inbound

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents cites this paper.

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents Context manipulation attacks : Web agents are susceptible to corrupted memory

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T11:11:40.945299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T11:11:40.945299Z digest=sha256:e2983c3ca6991eeaf63a2a6c0119a2b11ef413137ed47d6ecdd34c779b9da2fe