Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T23:59:59.384340Z
Paper Citation Record · LEDGER
As of 12 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 6 inbound Pith citation observations for arXiv:2506.17318.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T23:59:59.384340Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-05T11:11:40.945299Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-07-08T00:24:22.457387Z
27 of 27 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 6c110de6-a08c-425a-81ed-a4ffc0ed1515 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Agent-E: From Autonomous Web Navigation to Foundational Design Principles in Agentic Systems
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 32db510e-a853-437f-9d8a-d7bde270be68 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Defeating Prompt Injections by Design
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9c5b76c8-0fb1-40f1-8f00-36e9c8a21435 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory A practical memory injection attack against llm agents.arXiv preprint arXiv:2503.03704,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c1667d30-140e-4145-985d-24abbef7fc40 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e80cdd0-7a0d-4a06-b73c-57daa70636ec · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7ab7792c-e789-4154-a3b6-519601f1212d · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 22a7d239-5c65-481a-ae70-947d5b649241 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory AutoGLM: Autonomous Foundation Agents for GUIs
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c400cb14-701a-429e-8ef4-b3292688f52d · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Accessed: 2025- 05-21
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation d3b431d1-5f74-4b7d-b0a5-47b2ff5c9453 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Nagli, G
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 0f711ea3-6b3e-41cf-8876-56db82a3083e · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 97c31c83-b164-4164-8d32-1c6d4c0dcd73 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c560ef41-3caf-492b-8d59-6ee5f40b70d6 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 854fd232-5147-4956-813f-04f42650ce18 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory NaviQAte: Functionality-Guided Web Application Navigation
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e5eb8fc5-f132-4016-a889-12123a376cd2 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory ScribeAgent: Towards Specialized Web Agents Using Production-Scale Workflow Data
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ccae596f-1585-4b59-8a4e-918da8565249 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Learn-by-interact: A Data-Centric Framework for Self-Adaptive Agents in Realistic Environments
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9a6b55bd-94b3-4536-acde-883b10d6bc7e · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Cognitive Architectures for Language Agents
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2248a23a-f81a-4310-9ea8-e2998a16f579 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory OpenHands: An Open Platform for AI Software Developers as Generalist Agents
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8d6ba60c-0766-45ab-b2ca-771efd58fc12 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Dissecting Adversarial Robustness of Multimodal LM Agents
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2744fd10-c728-4929-859f-1aba7df71045 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Effectively Controlling Reasoning Models through Thinking Intervention
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 62995c05-718c-492e-b6f1-297d1fe614b3 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3acf0b93-0149-488e-824d-e8f5aa16dca9 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c888e957-68cf-4710-acc6-12e5f1948611 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d51fba25-3e83-422d-a8e8-dd541d5accef · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory GPT-4V(ision) is a Generalist Web Agent, if Grounded
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1dcae755-f2e7-4186-a403-9fce4adccbfa · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory StruQ: Defending Against Prompt Injection with Structured Queries
Reference 2022
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dee9f153-8a10-4e6f-ad5b-794bda4ddd19 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory WebVoyager: Building an End-to-End Web Agent with Large Multimodal Models
Reference 2023
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2a2103e8-0b56-46a2-9c61-afed381238ed · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0235cebc-d9cf-42b2-84c8-6fa715484961 · outbound
Context manipulation attacks : Web agents are susceptible to corrupted memory AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 2025
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0eed74a-d1e3-40ec-8f15-ffd3ad4cb840 · inbound
Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 8a349daf-1cd5-4ab3-85cd-5874eca60d1e · inbound
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 67
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation fb210899-fbf0-4cbf-b4e3-ff2401b488d9 · inbound
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation ab84a808-fa4c-414d-a6ee-ce1b41f44785 · inbound
ElephantAgent: Contextual State Continuity in Agentic Systems Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 235bf3eb-2b0a-4441-a2dc-a1f1b23270b8 · inbound
When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 88c2e2f8-c8e8-4f19-8a87-23e39c6d2a30 · inbound
MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents Context manipulation attacks : Web agents are susceptible to corrupted memory
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.