Pith. sign in

Paper Citation Record · LEDGER

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

As of 7 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2608.00747.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.00747 v2

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T04:17:02.594840Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved26
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation bb170696-a993-47e8-ac53-8a7eea8e35f0 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Ignore Previous Prompt: Attack Techniques For Language Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.494770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.494770Z digest=sha256:e32b1792c865cf6004715fc91e272094a3f26c316ceb666102781d5401512d68

Observation e51ae8f8-dfe0-4058-aeab-bfe27432df12 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.499370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.499370Z digest=sha256:7072a630a84d51feb3a490c5b45d5c8b869e15c1611df2b87ed06ed1f1079c84

Observation 7c2b1b60-bd8f-485e-ba4e-d4076050b839 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.503427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.503427Z digest=sha256:9be29f7d107b72cac76bf4763b4b8a50f39d41eb2fb0fb05e3ed4a124b01f0ad

Observation ce38dc26-2af1-4fe8-ab2e-b556bf871fa2 · outbound

This paper cites A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A survey of llm-driven ai agent communication: Protocols, security risks, and defense countermeasures,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.507970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.507970Z digest=sha256:4ccfd5993f71e36337355ea51ab54875c52e035c8f92ac732ea2e65c804310ba

Observation b3b9ed97-2620-415b-96a6-711d66e37531 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt Injection Attack to Tool Selection in LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.512504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.512504Z digest=sha256:d9394f7d6a8cb4eb51b6a7960189c1bdee077b264cc59fcf0eb10eb37c7b2aba

Observation 558cf644-7c68-49fd-9844-57c81c380287 · outbound

This paper cites Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agentpoison: Red- teaming llm agents via poisoning memory or knowledge bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.516491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.516491Z digest=sha256:ced1124550ae5668b158cb093ce3977dc3814140e2c91ad089b72fe9adf1bcdd

Observation f5e615bf-34cc-4b35-992c-a4881832719f · outbound

This paper cites Memory injection attacks on llm agents via query-only interaction,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Memory injection attacks on llm agents via query-only interaction,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.520587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.520587Z digest=sha256:a3202af78b5f937817145623ceb9d14e79e55daa47c6b0981c1d4a486342e162

Observation b85e4991-a6ec-41a2-ab09-3bd45cd0dd9f · outbound

This paper cites Prompt infection: Llm-to-llm prompt injection within multi-agent systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Prompt infection: Llm-to-llm prompt injection within multi-agent systems,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.524559Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.524559Z digest=sha256:13b34fd22b9908ce0eeeb6cbb91bcd370e337b7cc4452a7877d571620096931a

Observation a13f49f7-e8f2-4232-9e0b-09ee727c3222 · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.527779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.527779Z digest=sha256:8da87cccd7ca1ec06bc56ab27457277d7f723d2437b1623e14748f3d127e5fb2

Observation d1181928-a6dd-4bc4-81e2-21c2891f11cb · outbound

This paper cites IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems IP Leakage Attacks Targeting LLM-Based Multi-Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.531826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.531826Z digest=sha256:a736dce6069f51f5795da352544973948d926fb4c41b6a470c49a05a3cb7e80c

Observation df05d453-c18f-46f1-af60-291b8c858210 · outbound

This paper cites Multi-Agent Systems Execute Arbitrary Malicious Code.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Multi-Agent Systems Execute Arbitrary Malicious Code

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.535609Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.535609Z digest=sha256:1d705fffce82813a8850ac23936e20a655ad8400bab11cea24829a339c720590

Observation a261c141-7ae3-4579-b997-dfd297475108 · outbound

This paper cites Red-teaming llm multi-agent systems via communication attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Red-teaming llm multi-agent systems via communication attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.539306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.539306Z digest=sha256:b9701287716e1c0047934ddd437acf51e7f501aaca85cdc20cb9faff353f1b2a

Observation 8af621a0-4dd1-4298-be2e-110119c99a48 · outbound

This paper cites Breaking agents: Compromising autonomous llm agents through malfunction amplification,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Breaking agents: Compromising autonomous llm agents through malfunction amplification,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.543199Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.543199Z digest=sha256:1af38f524da8fd1c9f07249d48668dde4642e0a9ec996a7e0c9f64ecd2bb77e4

Observation 59e1107c-10eb-4979-88e4-7a47f7bb4241 · outbound

This paper cites BadRobot: Jailbreaking Embodied LLM Agents in the Physical World.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems BadRobot: Jailbreaking Embodied LLM Agents in the Physical World

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.546665Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.546665Z digest=sha256:70b418f4f5daddd11821cccb5a081a254943b8ca22bdedc47c2110283c789c33

Observation 92ca83d1-8370-4254-a965-5d995bd50553 · outbound

This paper cites A study on prompt injection attack against llm-integrated mobile robotic systems,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems A study on prompt injection attack against llm-integrated mobile robotic systems,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.550312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.550312Z digest=sha256:3a381825ababb6bf01dd68b8881c11d11e798bf649414ea0f267c54f07216129

Observation 780ac79f-a127-4fe2-a6d8-35f377c52541 · outbound

This paper cites Long-horizon planning for multi- agent robots in partially observable environments,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Long-horizon planning for multi- agent robots in partially observable environments,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.553854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.553854Z digest=sha256:18dea2a667873cbca27e38fe0db871376046e485eb2859ef2b9ee12773b0259b

Observation b770397f-38d6-4569-a686-d40e456a5ef4 · outbound

This paper cites AI2-THOR: An Interactive 3D Environment for Visual AI,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems AI2-THOR: An Interactive 3D Environment for Visual AI,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.557683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.557683Z digest=sha256:39307075d8f93cb02f17df1f727af0508d23ab5eb5b7335095de8c693fee2b08

Observation 94a70e48-81f1-47a6-b2e5-c5d52ffe3948 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Formalizing and benchmarking prompt injection attacks and defenses,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.561146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.561146Z digest=sha256:151f2daca368b85e055f50775225cc733f4ea7cf08506ddcb4b2a5592164c3b3

Observation 5989c688-0522-4bc9-a1f1-35dda94cdeef · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.564492Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.564492Z digest=sha256:fe464221ba04aea2e79733b4bbb0102d891d130971bcaf71d9a8113b06fa9564

Observation c55359a1-2b3c-49f6-9650-7e85313e2762 · outbound

This paper cites Jailbreaking llm-controlled robots,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking llm-controlled robots,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.568841Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.568841Z digest=sha256:b0df2b97fc897c746358e0468769b303932d4a8eaa5be30ca323f9bdc9c5a015

Observation f0d232bb-7615-44f2-9eb3-c775250afb6d · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Jailbreaking black box large language models in twenty queries,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.573034Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.573034Z digest=sha256:88fed547419a2fd05ebc0583392181ec3b927fd39e54247e01972bd8a63c37cd

Observation ccb795ea-410c-463e-b843-18a3122bd09c · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.576515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.576515Z digest=sha256:606af2388c0e86b3c36ac12b9866f549b01543ee92c754c82289515365c77716

Observation 3a84d894-086c-40ad-9149-71cfca548d58 · outbound

This paper cites Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially Fast

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.580448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.580448Z digest=sha256:bb50231823eda9c7bf70ea78fb6147c17927da7ed24e50a80e43f6194ede9cd5

Observation f0902229-485e-4fd6-9b20-fbef892648d8 · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.584306Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.584306Z digest=sha256:c87499bf9a4723a1c648e5bf590ec0709660568cd7a55b5a9bbee5fb75c3db65

Observation 3b86aa3e-7ec1-4254-bdcd-bd320813b959 · outbound

This paper cites Sentence-bert: Sentence embeddings using siamese bert-networks,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Sentence-bert: Sentence embeddings using siamese bert-networks,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.587650Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.587650Z digest=sha256:2e9cf90c0c03e390ec58e55c09297decb8422ef0165eae5bb8a478153f8a8d9d

Observation f4472c28-19f9-4a15-a6fe-6d667a43d765 · outbound

This paper cites Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Image-based prompt injection: Hijacking multimodal llms through visually embed- ded adversarial instructions,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-05T04:17:02.591154Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.591154Z digest=sha256:822f6dea4b40b2d0d3eb0a8891c23c6dae070a6df500bcf9325a0076a23ca71a

Observation 7b3561d9-29b1-40cc-91cb-e557b307c12c · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-08-05T04:17:02.594840Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T04:17:02.594840Z digest=sha256:dc32765c116a562337c021f45e290e1d06be3cf0daafd8996264bb847f9d464b

Pith citing papers

No inbound Pith citation observations are available.