Pith. sign in

Paper Citation Record · LEDGER

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

As of 9 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 24 inbound Pith citation observations for arXiv:2502.08586.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.08586 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.867597Z

measured 51 of 51 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 24 of 24 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T14:34:34.815687Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-03T15:48:35.883148Z

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy2
  • unresolved25
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation c7440ac4-45e3-4bb7-a91f-820a2aed8b14 · outbound

This paper cites Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.268054Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.268054Z digest=sha256:5deeb7dd0d39c0aedb4c5d05e099b5fb2820499d19a057c156e7b13bd31d4dac

Observation e852125b-d6ff-4489-a04b-a77da23ae6c3 · outbound

This paper cites Tianyu Cui, Yanling Wang, Chuanpu Fu, Yong Xiao, Sijia Li, Xinhao Deng, Yunpeng Liu, Qinglin Zhang, Ziyi Qiu, Peiyang Li, et al.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Tianyu Cui, Yanling Wang, Chuanpu Fu, Yong Xiao, Sijia Li, Xinhao Deng, Yunpeng Liu, Qinglin Zhang, Ziyi Qiu, Peiyang Li, et al

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.368156Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.368156Z digest=sha256:2c44b1d9481db05b4cb688ad3795dab772a5f285485f825c80376941f73df2e4

Observation 9480e77a-efff-4347-abae-590188524f7c · outbound

This paper cites Security and Privacy Challenges of Large Language Models: A Survey.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Security and Privacy Challenges of Large Language Models: A Survey

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.371361Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.371361Z digest=sha256:912be72205057210297b63012b6040185ee01d740c67e16afd0dafeb9e0df30f

Observation bbfe858a-5d44-41c9-b60b-bc90690c4f1b · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.375477Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.375477Z digest=sha256:337b43638b32729c2b72776970881dcc35b624cfebbe2869ad719fdc05c7ece4

Observation bc7e9b01-f2a8-4054-9ba0-f5b095ca68cf · outbound

This paper cites RLPrompt: Optimizing Discrete Text Prompts with Reinforcement Learning.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks RLPrompt: Optimizing Discrete Text Prompts with Reinforcement Learning

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.378324Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.378324Z digest=sha256:7a09e6b4997c5f2de3957a4057982da95d4a2a71230f5cab5a86d9c38ddcad91

Observation 684061cc-aec2-4e2a-b6d7-3144133a965a · outbound

This paper cites Feng He, Tianqing Zhu, Dayong Ye, Bo Liu, Wanlei Zhou, and Philip S Yu.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Feng He, Tianqing Zhu, Dayong Ye, Bo Liu, Wanlei Zhou, and Philip S Yu

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.385457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.385457Z digest=sha256:af646ac5c1cb7a998129fe4af0dd950cfc9fa5a1bbb3e9dbba9b3d411c15a0c9

Observation 98431140-7e89-4d59-ab0a-9a96b91afff6 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.388533Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.388533Z digest=sha256:0ed00f9f28ff54bcee0c2d1a3c3c3c3207b0756452aa2149e7e8bab3306a1eb5

Observation 7a1455d9-0caa-4766-8dd8-7b9a09263566 · outbound

This paper cites Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.391836Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.391836Z digest=sha256:147020d13714441f6a814bb34c3c7bb267695e49f6d63d1fd97dbc6935a301d3

Observation a1327166-0d8e-46ff-ab58-1c332a735972 · outbound

This paper cites Red Teaming Language Models with Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Red Teaming Language Models with Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.406491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.406491Z digest=sha256:20175773860ea5f37092b521ea9fd002bd88ff90cf6456bab2f643b75f7c79f8

Observation 7334860c-ab06-4cda-ae72-f58a63806e3b · outbound

This paper cites Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.463591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.463591Z digest=sha256:20b966b78849bcd5a0cb9322be81fa908e9b85b94d6c14f26773e862b69a66b1

Observation 8cde1543-df87-4c5d-817a-1cfe0574c2f7 · outbound

This paper cites Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.522854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.522854Z digest=sha256:06c49a1eab867f14876f23188bb3f6a7840b054c6de06291ec41b393d9f38339

Observation 0d2695b8-6189-4fba-a967-dad5b534717a · outbound

This paper cites Language agents achieve superhuman synthesis of scientific knowledge.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Language agents achieve superhuman synthesis of scientific knowledge

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.580674Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.580674Z digest=sha256:01c699c856bab77e9695d1bdc1667bb9dd806da458ec569b6842dcb96fbb106c

Observation eda3da75-5be5-4065-9e7c-fa974e876269 · outbound

This paper cites Evil Geniuses: Delving into the Safety of LLM-based Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Evil Geniuses: Delving into the Safety of LLM-based Agents

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.636620Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.636620Z digest=sha256:4ba24bc3917e60f8f91dfb1606ea6c9f0de41e59daecd2d4299a871b651ac7af

Observation 0d3f6b33-8f2f-4906-9e14-19c0ec4db78b · outbound

This paper cites Data poisoning attacks against federated learn- ing systems.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Data poisoning attacks against federated learn- ing systems

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T04:37:29.230122Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-08T04:37:28.666591Z digest=sha256:4e873208e1f735304d406588fe6b5ab21592de1c2bf9fd4ab3ee433361ebfe1d

Observation 662ad39e-bce8-4c2a-9cfd-0c3fe35e30f1 · outbound

This paper cites Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B¨ol¨oni, and Qian Lou.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B¨ol¨oni, and Qian Lou

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T04:37:29.220363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-08T04:37:28.734617Z digest=sha256:aa92f1236bf9bc3f452987e46d5851602033e2c8bf3c2d3200a55dec083d0743

Observation 1f68dc76-45a4-4ecf-8a2c-213780f94de8 · outbound

This paper cites Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.771627Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.771627Z digest=sha256:4709a274350c6acb0e169e16c0043bf3b2149a9ee1f065496f3922d903a914a8

Observation 7efd6251-11e5-49d5-8b67-2007d2b53ac3 · outbound

This paper cites The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG).

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.809380Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.809380Z digest=sha256:ff718f6cbe764fc4cca404e7b01461dc66f541398f4bd5917d1009ce05524395

Observation 75e283ae-38ba-4953-92f4-67cd737699ad · outbound

This paper cites Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.833682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.833682Z digest=sha256:9a838d5753435208f9b4ce3867d59c488242f842d91d963f53ba13af231d6dc3

Observation eaaceb16-a8fe-4fb8-8a94-57705e2572ee · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.861187Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.861187Z digest=sha256:719d78ca4c096f77285be9c4c5310cb094db8fcb6562f22d8f4991f7149a4d5c

Observation 1f195015-f753-4464-a947-6a6c78bc07e5 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.864419Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.864419Z digest=sha256:38df0d488ccdd9fca4e02705068b22582ac23f39cd90fe32881e30afd3e19319

Observation e82cbe66-f7fa-4f7e-89ff-287c47565931 · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.867597Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.867597Z digest=sha256:6b13482910a9069b70db26b1922a8c9907f9d3da766a2b88af78cc45cd9d4e78

Observation 7d3be1a2-b8fb-4a6e-849c-808561abf87a · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2017

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.364091Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.364091Z digest=sha256:1de62ad7911d97cc1cdce5504f984736fcf294c79b8b6bfd167de99551fa97b7

Observation 6b8f9803-dfee-4eb5-832e-dde61e6a10e5 · outbound

This paper cites BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents

Reference 2020

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.696356Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.696356Z digest=sha256:dfc2e887fed434b0d951cbd310dde800abc6b464635d42da939ecdecea9b79e5

Observation 71d462d9-5a9b-43a1-aea4-39010fe76e3e · outbound

This paper cites A Real-World WebAgent with Planning, Long Context Understanding, and Program Synthesis.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks A Real-World WebAgent with Planning, Long Context Understanding, and Program Synthesis

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.381640Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.381640Z digest=sha256:edaacbc1381eb5c7f29fdff92cabce12a2ee43563d0943240c58a0a827f9b048

Observation c78bb0e7-56c5-4300-8fbf-19f51297f658 · outbound

This paper cites Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.330264Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.330264Z digest=sha256:60254391e1ad221b99d0ab08d196954157bde6b939bae43fedda8fddab2055a4

Observation 86005911-1a78-45d4-baa8-42fdf1046c33 · outbound

This paper cites ChemCrow: Augmenting large-language models with chemistry tools.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks ChemCrow: Augmenting large-language models with chemistry tools

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.294013Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.294013Z digest=sha256:240e0b349577f400b4cb1f930f4114cd25825cb45e85b4c2146e197b2e3b4ca8

Observation b0ddb43a-d175-449f-ae19-ea1f7c0025f3 · outbound

This paper cites Scalable Extraction of Training Data from (Production) Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Scalable Extraction of Training Data from (Production) Language Models

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.394855Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.394855Z digest=sha256:f9d580d080a4ca13fe0ddebbe0fd1b10fe45e3ac9fbc4442d562af7cbbc47d33

Pith citing papers

Observation 253b84ab-1d66-4a3a-9997-cb0a75bd596f · inbound

Large Language Model Agent: A Survey on Methodology, Applications and Challenges cites this paper.

Large Language Model Agent: A Survey on Methodology, Applications and Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 175

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:52:10.416569Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T21:51:34.309870Z digest=sha256:3286ae3ebeb59453ffff3bca1b49c3534d528a7c4c8206c51bf7c5c85f2c5370

Observation be51e42f-0e70-476d-9a6d-26463ffa2c86 · inbound

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services cites this paper.

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T14:34:34.815687Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:34:34.815687Z digest=sha256:605302a925a41ef9d9305d6a229a79c525b05b5633de11956c751635012c4e94

Observation 4de0b938-f923-4b0a-8e57-4b32cf438f03 · inbound

MLA-Trust: Benchmarking Trustworthiness of Multimodal LLM Agents in GUI Environments cites this paper.

MLA-Trust: Benchmarking Trustworthiness of Multimodal LLM Agents in GUI Environments Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T11:42:33.151323Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:42:33.151323Z digest=sha256:e74f23e37c9be6ac118426a7945713a057751b86fe74f9258d32581f90164312

Observation 5f9b130e-a6b8-4e84-a6b8-d2fa89e8e789 · inbound

A Red Teaming Roadmap Towards System-Level Safety cites this paper.

A Red Teaming Roadmap Towards System-Level Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:11:20.746079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:11:20.746079Z digest=sha256:ef6b3fd3b6c71ff229aa8555cce52b0aaceefd2b35e5f859a1e1c7556c2d8f20

Observation d2036883-0a11-4792-ba90-bc10698481e9 · inbound

Levels of Autonomy for AI Agents cites this paper.

Levels of Autonomy for AI Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T00:52:41.842278Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:52:41.842278Z digest=sha256:96ffa6784f63a9e50b3d621538ef2cbfbcaf7dc25d2739214c67a2869e361b3a

Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.575227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.575227Z digest=sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9

Observation 26006061-4145-4732-9dd9-8613a9c4af73 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:41.058806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:41.058806Z digest=sha256:86e202e3e56405ffbf58270427b85fe3cd11432d82e1b6d37e303f8ac15103c3

Observation f34403d8-64b3-4b77-bb38-3907e4f94c74 · inbound

Throttling Web Agents Using Reasoning Gates cites this paper.

Throttling Web Agents Using Reasoning Gates Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-05T12:28:04.262824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:28:04.262824Z digest=sha256:cfcd0a0c1219e8c335592f3cc411bd6e545ad26023cf7bae889e2a7a95a40f4a

Observation f01aec10-85e1-4790-83b8-2ae442ff8fba · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:11.330207Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:11.330207Z digest=sha256:0681b6f29ee324263550f29e04181f694afa9589281f38f4fb5e8ac14b67efa9

Observation 0f547531-39aa-44f7-bad3-35e3f742389d · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.464757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:ec82b4a01990b520a6af6b0fd3d3966d821265996d0613f336c80bcca4b735b4

Observation e36b5551-e79c-4033-9e44-68fbdd28bc08 · inbound

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels cites this paper.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.041872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.041872Z digest=sha256:aba8589669404d082b92cc3a05cef44d47b6c41dcf026a538f0cb6fbda3783a4

Observation eae352de-994f-46ac-b9b6-3eb072c67fb0 · inbound

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents cites this paper.

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-03T10:32:31.300703Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:32:31.300703Z digest=sha256:7cd569ed0e5cee50c16ad85c1e0692a81529c5e0f1b243a6e8b1dd1960736927

Observation 98b32e61-f9b1-48ef-955d-d23a9baee00c · inbound

Agents at Risk: How Users Unwittingly Undermine LLM Safety cites this paper.

Agents at Risk: How Users Unwittingly Undermine LLM Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:18.132433Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:18.132433Z digest=sha256:de9254ce0f0672c57a460064e6f30449b4711a311d7fc31b35fa3aad460f644a

Observation 74e5a25f-89fd-455c-b8cd-06a8e35d706f · inbound

LLM-AutoDP: Automatic Data Processing via LLM Agents for Model Fine-tuning cites this paper.

LLM-AutoDP: Automatic Data Processing via LLM Agents for Model Fine-tuning Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-16T10:57:46.854305Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-16T10:54:22.183741Z digest=sha256:08350dad967874006e21f57f4d68c7552af279768570c91649153460ee891870

Observation 6353e071-8de9-4ae8-bddb-063f71c72e15 · inbound

OS-SPEAR: A Toolkit for the Safety, Performance,Efficiency, and Robustness Analysis of OS Agents cites this paper.

OS-SPEAR: A Toolkit for the Safety, Performance,Efficiency, and Robustness Analysis of OS Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-11T21:56:11.842563Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-08T03:51:54.310805Z digest=sha256:9735db505446dbe15c7edb0d49f0af2cea8874df9c6dfb227578c0e77aa729ed

Observation b563fa63-c81c-4092-865f-be3c916bf6c8 · inbound

Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security cites this paper.

Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 99

Resolution
verified exact
arxiv_id, observed 2026-06-30T19:45:01.661562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-30T19:18:40.244556Z digest=sha256:e9170f68c2f7579c78e3d986584851dc2591d8dc9e66b2e1a21ebaaab70a197a

Observation 28206dc5-9048-4a28-8234-857c0250edde · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-06-30T16:24:55.140269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:06f08dbaee6870e17093b1261b092653eba8ab964425d7b296714e32f0ad2255

Observation feca9d20-b067-4135-afa2-fb5e6e604f1d · inbound

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents cites this paper.

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-03T15:48:35.884551Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T06:20:04.789341Z digest=sha256:ec4e75382879881d6e7f1735522c9a07aae1fb70013462ee6fce71c572c117c0

Observation 88883738-429d-418b-9449-9a44d034f077 · inbound

Why Trust Your Agent? Empirical Security Gains from TRiSM-Guided Agentic Workflows in Healthcare cites this paper.

Why Trust Your Agent? Empirical Security Gains from TRiSM-Guided Agentic Workflows in Healthcare Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-06-30T12:44:39.617898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-30T10:17:02.425849Z digest=sha256:2120dcfc630b536560efeb60b923c622641eb32ccf8cbb5d1ff73f2268e22b89

Observation 82e558c9-e23d-48c4-ae91-8a16c5ac1b37 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 268

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.602164Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.602164Z digest=sha256:f39efeb3b52fd2246a35245999c48241e85cb1ed8b3d10b74ef21bb223bce584

Observation 6c261576-7405-40f9-bbb1-2588d573b740 · inbound

One Anchor for All: Unified Multilingual and Multimodal Safety Alignment for LVLMs cites this paper.

One Anchor for All: Unified Multilingual and Multimodal Safety Alignment for LVLMs Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-31T23:07:37.594638Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-31T23:07:37.594638Z digest=sha256:0161c67803cdbb349636e0ed67f27417dc059980a15ab5169711f7d526848f9f

Observation b5d24510-d72f-4e28-a4a8-9a1a0f87e169 · inbound

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents cites this paper.

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-04T16:36:53.593030Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T16:36:53.593030Z digest=sha256:8e43b222de7e649244d474661cdb46b40236a3e67046ac365deeb25992de12ab

Observation f9c7f59c-9fc1-4e6e-b474-ad1fb264f142 · inbound

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents cites this paper.

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T00:59:39.874950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:59:39.874950Z digest=sha256:eb104aca3de5b4522790c471fdea808f94f43e1baeaf9bdf06c849f1d9626759

Observation 39a8ec91-4374-48f9-80f7-73e24dbbf8c2 · inbound

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure cites this paper.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.371881Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.371881Z digest=sha256:c84fbba609ae29d1720eddb10d7116d9ae672c2eacee5603024ed3f85d7e9b32