Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-11T10:24:27.048790Z
Paper Citation Record · LEDGER
As of 11 August 2026, this Paper Citation Record lists 38 of 38 outbound references and 13 inbound Pith citation observations for arXiv:2412.16682.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-11T10:24:27.048790Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-07T14:55:01.117692Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-07-03T16:58:43.565621Z
38 of 38 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation bcf99d7c-016a-465b-b6a2-abde8f1a0ebf · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents online" 'onlinestring :=
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d93e7f28-cce8-4484-8ec3-5fa9af4ee8b3 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents write newline
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ea47b1c7-24b8-4abb-90f2-2016884e6940 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 484e8516-d9db-4fbd-96ea-2ececb9cd542 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents StruQ: Defending Against Prompt Injection with Structured Queries
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 76a685bd-7663-4b7f-b311-84a73ec55477 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b6a45ef-dd91-41d8-8544-dea7e7acb896 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 17d38585-9607-462f-8001-04814cf78fb6 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation d2c0925e-10e3-4ba1-a904-89ee26259d3e · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df98e536-0949-4705-b6bc-dbe534cd74d0 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Gupta, Niloofar Mireshghallah, Taylor Berg-Kirkpatrick, and Earlence Fernandes
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 94c3276b-a666-4d26-874f-525a1df8a0b2 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3acd4214-4126-4989-98aa-89fc8f5aace1 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 71c654a6-5307-4ad3-a490-f176f40a7b23 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1bc17b03-a4cb-4959-a64c-72f72af03d4f · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Recommender AI Agent: Integrating Large Language Models for Interactive Recommendations
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a6560390-5104-41cf-abbd-bcaa6a2448c5 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Palisade -- Prompt Injection Detection Framework
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 3f040989-1353-46fc-8b8f-160540a97800 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Whom to Trust? Elective Learning for Distributed Gaussian Process Regression
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation cfd0bb1c-cbae-4a4b-88d2-a9b016e901dd · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Prompt Injection attack against LLM-integrated Applications
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 65e2677d-278b-4aef-8373-35f3e37dde80 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation ee2b5907-d90b-4b39-b78b-a01cdc9f2b8a · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 6a7f2124-6096-4d18-90ca-e2a2afef1ffa · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation a34672dd-4f90-4939-86b7-59ed44be8df7 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 5f6c73d7-a0bb-442a-ada1-117515891602 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 36386400-ab38-442b-b3e9-6cc1530b7097 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Gorilla: Large Language Model Connected with Massive APIs
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aa91ded2-6669-44ff-9d59-e17902d476c8 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Ignore Previous Prompt: Attack Techniques For Language Models
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 746e4891-1d42-4be8-8177-c845af83407e · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Jatmo: Prompt Injection Defense by Task-Specific Finetuning
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bf6a7214-f7d6-44f4-898f-053be29809e6 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 56d2b729-8275-4768-b4b9-341bb4a6f248 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79913162-26e2-469c-8b01-b941dc1a52bf · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ac53856-199a-472b-84e5-3a53171bb034 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation db738dc8-08bb-4e65-a7b9-132119b530d8 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 72f79fa5-3b0f-41fe-82ff-65ea438f2905 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Llama 2: Open Foundation and Fine-Tuned Chat Models
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dcc648a0-67f7-4a86-9803-ebf7a875a12f · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6bf1c9c8-fa8b-4ae4-afea-1f963c6ab16d · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 925909bd-96d6-4f78-814d-59dfd0e55d5d · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Beyond the Imitation Game: Quantifying and extrapolating the capabilities of language models
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fbe276cd-bc22-4a66-a1cd-42eccb588a63 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Instructional Segment Embedding: Improving LLM Safety with Instruction Hierarchy
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 55a100af-990e-4bbc-b180-2afb7374885a · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1c845cf5-c9c7-4bbb-9a99-e69d44e5aae2 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents Unresolved cited work
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 968de845-c1d1-46e8-b04c-6436f9478028 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation caf73733-d20f-40e8-8442-d013003c7282 · outbound
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents RepViT: Revisiting Mobile CNN From ViT Perspective
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7c6505b0-d9e2-4deb-afc8-d38971922780 · inbound
Large Language Model Agent: A Survey on Methodology, Applications and Challenges The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 209
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation a24a8668-3f8e-4800-b980-9aad03164431 · inbound
Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f61e6893-03d9-438a-b98e-1c47a1604f0f · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 202
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 602dcf49-7c87-4618-aee3-8e8aa34947ed · inbound
The LLMbda Calculus: AI Agents, Conversations, and Information Flow The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a5dfe640-3403-4a92-88f1-f6a84b0f2533 · inbound
CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 39f11dd9-3835-454e-9e1f-23ecd168e821 · inbound
AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation ae4b724b-a685-4486-a15a-d71460f0ac21 · inbound
No More, No Less: Task Alignment in Terminal Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation 16d9ff76-c4db-40cd-8254-d77fbc15726d · inbound
Web Agents Should Adopt the Plan-Then-Execute Paradigm The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation a6441a34-ccbf-405e-8d1a-f9ffdf08b84e · inbound
Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation b97fe467-b2be-45b0-a54e-1ecf87f86479 · inbound
From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.
Observation a937b614-d959-4866-b85a-e7f590837ba4 · inbound
MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 464c419e-90e4-4deb-995a-229b9da82332 · inbound
RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1847c81d-a1bd-4925-8204-fb4336c41cec · inbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.