Pith. sign in

Paper Citation Record · LEDGER

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior

As of 7 August 2026, this Paper Citation Record lists 24 of 24 outbound references and 1 inbound Pith citation observation for arXiv:2508.19287.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2508.19287 v1

Coverage vector

measured 24 of 24 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T16:50:30.164447Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-05-16T20:35:26.913297Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-16T20:38:24.771300Z

Reference resolution

24 of 24 outbound references displayed

  • verified exact0
  • verified fuzzy12
  • unresolved12
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 51f4e2e7-c5d4-42f7-afdd-3afe1c2a4c52 · outbound

This paper cites ACM transactions on intelligent systems and technology15(3), 1–45 (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior ACM transactions on intelligent systems and technology15(3), 1–45 (2024)

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:27.494758Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:27.494758Z digest=sha256:85f47b01eddd8896e044f20f4b1858fdc2e549d943273295538e578c25123ca7

Observation de5726b3-e7be-433a-93fa-166858f3d9f7 · outbound

This paper cites A Survey on Large Language Models for Critical Societal Domains: Finance, Healthcare, and Law.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior A Survey on Large Language Models for Critical Societal Domains: Finance, Healthcare, and Law

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:27.634779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:27.634779Z digest=sha256:a37482c437c83845dbf9dd65a35474709f005da3cfdeffae53da207832e4706c

Observation 2a63a6e7-42f6-4b35-aa27-26ada5b07f9c · outbound

This paper cites In: 2024 IEEE International Con- ference on Big Data (BigData).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior In: 2024 IEEE International Con- ference on Big Data (BigData)

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:33.494758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:27.723080Z digest=sha256:6889cb884609c2794f0d88e88736804f1cd8683d4e115774e6f7a4928e50ba25

Observation 9425f9b0-6670-4106-ac45-82dab32a6e95 · outbound

This paper cites ACM Computing Surveys57(6), 1–39 (2025).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior ACM Computing Surveys57(6), 1–39 (2025)

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:33.273793Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:27.794401Z digest=sha256:c5d4971fa8e1536d27d1aa3072bf63f758e00ceff39cd75ee4d779de0e70d558

Observation 403147c1-9106-4219-b38b-f80faf053944 · outbound

This paper cites Cybersecurity 7(1), 70 (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Cybersecurity 7(1), 70 (2024)

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:33.091436Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:27.954346Z digest=sha256:4f758ea58efe7d5a94dfaddc477775c1db9636a999f73df395480b932d6549c9

Observation feb22126-f6bb-44ed-8bc7-a351c3db93b0 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:28.069437Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:28.069437Z digest=sha256:81ce145d27ce1c3c01d725081b1ba2b0a2341d966b8db422cf78dff4aef45a84

Observation ff8cef0a-4330-4753-93d2-389d03bf037a · outbound

This paper cites Advancing Transformer Architecture in Long-Context Large Language Models: A Comprehensive Survey.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Advancing Transformer Architecture in Long-Context Large Language Models: A Comprehensive Survey

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:28.169744Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:28.169744Z digest=sha256:7fbe52311d0601c0c4d1aded0eb953869a1180c70a35f94ee72016c4ce079c98

Observation 3d5cf4f4-7742-48fa-bdb3-4c6ab5f5e6f6 · outbound

This paper cites Learning and individual differences103, 102274 (2023).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Learning and individual differences103, 102274 (2023)

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:28.278771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:28.278771Z digest=sha256:144d518d954426aefc704b12234f7b35fbb095420f5e22a24999115ac4063812

Observation c70fa357-aa86-4b2e-ac33-2bb0ded3bc52 · outbound

This paper cites Authorea Preprints (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Authorea Preprints (2024)

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:32.767031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:28.481789Z digest=sha256:ae7f1ea00964e0a5ce4d73cf266efbb7af2660a1af73133efadc3182a9603500

Observation e4a18588-d5ed-480c-846e-b7310ed07eb6 · outbound

This paper cites AI Open (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior AI Open (2024)

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:32.644754Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:28.627107Z digest=sha256:a7e93fb890908ab7745fb30137d1facb4aa95871abe6b27dfba03484fe30507f

Observation a5848cdb-b43b-41a8-93ca-942c2cec5a0f · outbound

This paper cites In: Proceedings of the Extended Abstracts of the CHI Conference on Human Factors in Computing Systems.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior In: Proceedings of the Extended Abstracts of the CHI Conference on Human Factors in Computing Systems

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:32.410186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:28.690824Z digest=sha256:38e147ffb27048ed59b26afecd7bdd4aafd6ed45e700f1725bb9fc3f991e4aff

Observation 3d6c04de-94bf-46a0-8d38-b9f81cb1466a · outbound

This paper cites Advances in Neural Information Processing Systems36, 4952–4984 (2023).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Advances in Neural Information Processing Systems36, 4952–4984 (2023)

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:32.093373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:28.824029Z digest=sha256:4d1eb9d30a7273b01fbc9c48f0188db2248c6b49b26c67e5be080314cd7660b9

Observation 4b2a9e2e-c0a5-44ec-8b75-efc62a07db9b · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:28.896342Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:28.896342Z digest=sha256:9525e1663338d4afb6f5226a2925cf06c64a147713a71b09d96368c36c0afd2e

Observation cde4d3ad-3e5c-4a5a-980c-90e767a3682e · outbound

This paper cites In: 33rd USENIX Security Symposium (USENIX Security 24).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior In: 33rd USENIX Security Symposium (USENIX Security 24)

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:31.854751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:28.974766Z digest=sha256:06cf8413d6e087e89d80e46aedc618464575b687bb467d8f28876c766c178944

Observation 82aeb5b6-db47-4b5d-bf7e-3e10af776f8b · outbound

This paper cites International Journal of Open Information Technologies12(5), 39– 48 (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior International Journal of Open Information Technologies12(5), 39– 48 (2024)

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:31.524753Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:29.059844Z digest=sha256:1bb471d24e73816989aaaba17c388441fd82087a12928255e8452007da4c17fe

Observation f8b6f0db-3eef-4e6d-8105-3ddec786ad55 · outbound

This paper cites Cluster Computing 27(1), 1–26 (2024).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Cluster Computing 27(1), 1–26 (2024)

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:31.195817Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:29.139588Z digest=sha256:d8d110de3fba57e4f0b0caa851d9e3e56d5ec8585c1d07868f32c9f4799c3484

Observation 96a786cc-3e7a-40cb-bea5-4d75596676d6 · outbound

This paper cites Available at SSRN 5017385.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Available at SSRN 5017385

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:30.922498Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:29.274754Z digest=sha256:ec21fe07be5bb043a2ab2c898299cfa534975daa8c584926503d4b918cf3b379

Observation f37e7852-2c04-42ea-a321-2f6e4f3ebbb5 · outbound

This paper cites In: 2024 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC).

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior In: 2024 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T16:50:30.774749Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:29.420157Z digest=sha256:5adfa40545b48e54743ad88ffed34642ca3655494b295bbd0d10303c4542bfd7

Observation 93c46095-eab8-44ac-a4ca-608cc6f2cda2 · outbound

This paper cites Safeguarding Crowdsourcing Surveys from ChatGPT with Prompt Injection.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Safeguarding Crowdsourcing Surveys from ChatGPT with Prompt Injection

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.576676Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.576676Z digest=sha256:8ec7b2cc0bf51807a2b97774235e9b04ea63e30aa53bbad027f87a221ca403be

Observation 72435f72-57a9-4523-bade-16d154b3f501 · outbound

This paper cites FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.700036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.700036Z digest=sha256:567087f15c608bd9e1d0de505f460e275a817272053574c6ecbcbf9a9b04a1e7

Observation 4ed72736-4654-47a2-8294-25c22ec8fd0e · outbound

This paper cites A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.805387Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.805387Z digest=sha256:45cb7f6183558668fce90ac26a17b3557fd1db198e9bec606f54d1e4b0723703

Observation f3cba737-1295-4552-94ac-1eadc91f1413 · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:29.954752Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:29.954752Z digest=sha256:e1500921048f0658dba9455b7bdf1e2694433c7a7d45cc529e4f6fa56b3607b1

Observation fc15fc42-8896-4481-8e38-5ef69530383c · outbound

This paper cites Goal-guided Generative Prompt Injection Attack on Large Language Models.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Goal-guided Generative Prompt Injection Attack on Large Language Models

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-05T16:50:30.014754Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T16:50:30.014754Z digest=sha256:35f2271d529cd0773da732b3009e74457438b1a52380caa2dccb21598d5752db

Observation 0e909c49-7e05-45ab-9c3e-2c0063b2b161 · outbound

This paper cites an unresolved cited work.

Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Unresolved cited work

Reference 24

Resolution
unresolved
raw_fallback, observed 2026-08-05T16:50:30.574959Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-05T16:50:30.164447Z digest=sha256:84583b3a1e41f8b355bf7076379810e518d1a84bfde65888616fd5be5d5459b4

Pith citing papers

Observation 8b997909-ea2a-4798-a6bb-7b9687af6c4d · inbound

ChatGPT: Excellent Paper! Accept It. Editor: Imposter Found! Review Rejected cites this paper.

ChatGPT: Excellent Paper! Accept It. Editor: Imposter Found! Review Rejected Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-16T20:38:24.772785Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-16T20:35:26.913297Z digest=sha256:01eca8335c1921976233f72a262b1c04fe7d57708681769f5c16dd633594dcf3