Pith. sign in

Paper Citation Record · LEDGER

LLM Agents Should Employ Security Principles

As of 9 August 2026, this Paper Citation Record lists 90 of 90 outbound references and 18 inbound Pith citation observations for arXiv:2505.24019.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.24019 v1

Coverage vector

measured 90 of 90 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T12:42:18.393562Z

measured 108 of 108 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 18 of 18 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T04:33:17.074410Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

90 of 90 outbound references displayed

  • verified exact0
  • verified fuzzy23
  • unresolved67
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation bd985b7c-b0df-459b-8000-298db5310957 · outbound

This paper cites Firewalls to Secure Dynamic LLM Agentic Networks.

LLM Agents Should Employ Security Principles Firewalls to Secure Dynamic LLM Agentic Networks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.530457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.530457Z digest=sha256:e3c21561c6ca7366df9ac755bd0c8b912ce407f18d56f29cb697fc6a0c095f98

Observation d5d6c0d8-f456-42ec-a9f2-834243d80537 · outbound

This paper cites Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press.

LLM Agents Should Employ Security Principles Jimenez, Farshad Khorrami, Prashanth Krishnamurthy, Brendan Dolan-Gavitt, Muhammad Shafique, Karthik Narasimhan, Ramesh Karri, and Ofir Press

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.608335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.608335Z digest=sha256:7e02b29a6e4eee8fc0239807fb39f3cf03cdd0c5760a49157167643fab5ce396

Observation cdec2bb5-bbf7-450e-a9ff-048260c07d27 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

LLM Agents Should Employ Security Principles Detecting Language Model Attacks with Perplexity

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.698195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.698195Z digest=sha256:c16f8864223096028a82d4cf833350c099b6b64990eabf58f0917bf9fe5d2e9a

Observation d05109fa-289d-4952-ad75-ecd264b038e0 · outbound

This paper cites Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/.

LLM Agents Should Employ Security Principles Generative AI on AWS.https://aws.amazon.com/ai/generative-ai/

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.809393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.809393Z digest=sha256:8194fc0344a5aa398d3ec65522a1abe69e90e3dc1e2e5d28f0d818e260709c37

Observation 089e5c0d-478b-43ef-bfa3-b3b54410e83b · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

LLM Agents Should Employ Security Principles AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:10.942106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:10.942106Z digest=sha256:ddeb3d368e8e5eaa18298b865834372e7ff0efc3964ca832834a9baf3e890442

Observation dd089303-22eb-46fd-9132-1b9724232760 · outbound

This paper cites Monitoring computer use via hierarchical summarization.

LLM Agents Should Employ Security Principles Monitoring computer use via hierarchical summarization

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.032707Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.032707Z digest=sha256:9f2a7f15552f84193591ebee69a6be628f41f282f8fe01fef3c93b489278d6d5

Observation 9ff1aaba-0123-4546-9680-1d68c64f885f · outbound

This paper cites Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol.

LLM Agents Should Employ Security Principles Introducing the Model Context Protocol, 2024.https://www.anthropic.com/news/model-context-protocol

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.133502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.133502Z digest=sha256:1d66eb958acf0f787c60d43f2b46b8f5e9e38425f6b151aefb58f9d1c245c974

Observation be791b63-2bd7-4f41-afd4-8331c45673cb · outbound

This paper cites https://github.com/microsoft/autogen/.

LLM Agents Should Employ Security Principles https://github.com/microsoft/autogen/

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.217203Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.217203Z digest=sha256:380534f699bcad0cc4e7630e626fadddc094b9fc0737f554c2875d18f1ce52c2

Observation d65cd2b0-10c3-4be9-bb2e-824e744adbb6 · outbound

This paper cites AirGapAgent: Protecting privacy-conscious conversational agents.

LLM Agents Should Employ Security Principles AirGapAgent: Protecting privacy-conscious conversational agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.321358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.321358Z digest=sha256:afd7017c818781d7914c489444463d4b72a60da34718ba2709e072d74627b891

Observation d64ee457-9957-4055-8516-91b05dfbe8bd · outbound

This paper cites International AI Safety Report.

LLM Agents Should Employ Security Principles International AI Safety Report

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.396694Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.396694Z digest=sha256:34b462cd16e36220f387834fd04237bc208ab66def96361d789d7de53e0747a4

Observation dbcb2b21-ad46-4d62-a163-76dcfe37b233 · outbound

This paper cites Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment.

LLM Agents Should Employ Security Principles Red-Teaming Large Language Models using Chain of Utterances for Safety-Alignment

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.476447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.476447Z digest=sha256:66e4bbf5e0e77dea6ddfc606c53c64554768677ea5ed9af1d3b36f7f2d498747

Observation bd117973-b3e8-4121-a09d-423378211520 · outbound

This paper cites Computer Security: Art and Science.

LLM Agents Should Employ Security Principles Computer Security: Art and Science

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.571062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.571062Z digest=sha256:f2c6570e7a8f9a806715eba1d180e1beedd9e57c409606df920aede30c02404a

Observation 8d9940fd-8a91-4caa-9895-691e6f6f76d3 · outbound

This paper cites Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020.

LLM Agents Should Employ Security Principles Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.674312Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.674312Z digest=sha256:7f0559a494d8a9f05250b9de13a22b2ce9117b7de3baba331b3119e63f3e4324

Observation d347328e-ca07-425f-b855-b3af2492b132 · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

LLM Agents Should Employ Security Principles Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.749191Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.749191Z digest=sha256:ef67c7fc50024b54388e328d60dc7731ae367dc3b8049187f09d0ab659a36222

Observation 867af2a8-de4d-4a33-8869-65aa2047e972 · outbound

This paper cites Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024.

LLM Agents Should Employ Security Principles Agentpoison: Red-teaming LLM agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2024

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.823955Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.823955Z digest=sha256:cc6b7f538945d2c6dfc6a82cc8d59e7fc87bcd653d0c8918b8af9b4e32c983ed

Observation 596ee284-0ea0-4129-8f46-0a457afe19d0 · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

LLM Agents Should Employ Security Principles LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:11.956892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:11.956892Z digest=sha256:2e3a9060487abba759ead9fea974fe63ab4b9505625ba8689872fd24a5df51c4

Observation 2892f98d-6ca6-4c1c-a487-fc9581d063d9 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

LLM Agents Should Employ Security Principles Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.078265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.078265Z digest=sha256:3be774b57124d91c4dcb4275a905fdeed7053ca032c170d8cddd51300ea29d9b

Observation 4fcb89fa-0184-401d-bb07-7ef9b69a6a92 · outbound

This paper cites LLMs for Customer Service and Support.

LLM Agents Should Employ Security Principles LLMs for Customer Service and Support

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.185759Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.185759Z digest=sha256:887aa086e943f1c6a6d940b69a89f3aad88be975eaea8d77406c8d902d1dd85e

Observation ceb442c8-68b9-40a3-8631-22abaefc089f · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

LLM Agents Should Employ Security Principles AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.263611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.263611Z digest=sha256:67c25b3827b99dd806c50cc710c7d9442775fccdf1eab1b33cf591a6dbc8a546

Observation 25525d58-b3c5-4ba9-805e-03c7bf4cf5dc · outbound

This paper cites A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025.

LLM Agents Should Employ Security Principles A practical memory injection attack against LLM agents.arXiv preprint arXiv:2503.03704, 2025

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.351103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.351103Z digest=sha256:93075b0e737b5f09d5a7b5c59535f9a7f49544e507816b12a002d7e90d54322c

Observation daed623c-b688-44db-a438-1e84c1d74c33 · outbound

This paper cites LLM Agents can Autonomously Hack Websites.

LLM Agents Should Employ Security Principles LLM Agents can Autonomously Hack Websites

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.460789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.460789Z digest=sha256:d23864e11be0b5b40f9c18db097f89ad0f71491b46ff55ba1a2182c82019eda1

Observation b98b3fef-4049-4ffc-ac4c-0154f96d31d3 · outbound

This paper cites Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms.

LLM Agents Should Employ Security Principles Papillon: Efficient and stealthy fuzz testing-powered jailbreaks for llms

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.991712Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:12.564782Z digest=sha256:92251d6965891c16b3549c0fc7f6a82ecd84a3ca7e7751453539a2afb465b61f

Observation 59849ad6-626a-4837-baa2-6e83386a7dcd · outbound

This paper cites Announcing the Agent2Agent Protocol (A2A), 2025.

LLM Agents Should Employ Security Principles Announcing the Agent2Agent Protocol (A2A), 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.889907Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:12.637148Z digest=sha256:25d809e0d14d03694afe9caad1cbe724501859417235b4d95772742b973a0ce7

Observation eef13c70-b45a-442e-ae02-560f42321cae · outbound

This paper cites Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024.

LLM Agents Should Employ Security Principles Redcode: Risky code execution and generation benchmark for code agents.Advances in Neural Information Processing Systems, 37:106190–106236, 2024

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.790524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:12.733210Z digest=sha256:99d19c47b96deebad2d89eddc2e210bb407f4a91bdee72572aaa0bf1448076e5

Observation 96993d6c-dce1-4cbf-b163-c9a0afd3c2b9 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

LLM Agents Should Employ Security Principles Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.836704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.836704Z digest=sha256:013528343bad6ef2668bbfe324824be853a4a556b1cd96dc299f75ccd56b7918

Observation 83cb01ea-f7e7-4ada-a985-5faed646f991 · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

LLM Agents Should Employ Security Principles TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:12.942186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:12.942186Z digest=sha256:1cde8abf73b9ea345b9f5181ba58bd89518006ece633e59031b410ddbb0d96b2

Observation 1c1f3d12-d2ea-4e88-a032-f246d074d031 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

LLM Agents Should Employ Security Principles Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.041837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.041837Z digest=sha256:d58c11b3c1a5bd5f90055420d7d077776bd0c539718c1c1a93a9db402ac99c67

Observation e070e8a2-7038-46cc-8d1e-ec256ef640c2 · outbound

This paper cites DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines.

LLM Agents Should Employ Security Principles DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.159532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.159532Z digest=sha256:a2622e22d39bb3748a11415bf04499764ef8cd6134687286ac556349fee73c5b

Observation 30dc0c33-a749-4094-8680-eaa2a1479476 · outbound

This paper cites https://github.com/langchain-ai/langchain.

LLM Agents Should Employ Security Principles https://github.com/langchain-ai/langchain

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.630328Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:13.243542Z digest=sha256:567c25011a8c103a0fe8c55441b809282e5661061c1975ca594804733ac8a465

Observation 03efd940-4c6a-4584-833c-436b070c380c · outbound

This paper cites Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems.

LLM Agents Should Employ Security Principles Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.333338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.333338Z digest=sha256:380e6271f5d68fc017efe7c39ef6e57c1271c0feeb60b107f6b5e1defe66de46

Observation 9961eabc-da01-4075-8d8c-7ca6e07d3d7a · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

LLM Agents Should Employ Security Principles DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.406934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.406934Z digest=sha256:c2a85967bdfaf90a07b3840a2e074ab9fdb2fe9c04c6e91cc333705e64e8d726

Observation 9efe313b-f1dc-4273-a168-662a114e3017 · outbound

This paper cites RAIN: Your language models can align themselves without finetuning.

LLM Agents Should Employ Security Principles RAIN: Your language models can align themselves without finetuning

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.448589Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:13.445643Z digest=sha256:39507457bc6bd1d043f3b190b14bdf3216d2357a11f2f4a8d93f3c4873a6d6b1

Observation ef746f30-99ce-46c0-b78d-883f9882a0a9 · outbound

This paper cites Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025.

LLM Agents Should Employ Security Principles Agentorca: A dual-system framework to evaluate language agents on operational routine and constraint adherence, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.310516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:13.503135Z digest=sha256:2de257515c89b32bf65009cbd5a3d94710a3959d45df2065ab1fccbb942e6e59

Observation c56f5cee-ca82-4ebd-9976-a68fe5bcdde3 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

LLM Agents Should Employ Security Principles AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.581416Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.581416Z digest=sha256:0c9bfb5e4a6496685293fc1ff5f8bd8199f20904528ded3494330b405030944f

Observation 4ba3acef-79e5-48ee-86b5-c7196eac569b · outbound

This paper cites Automatic and Universal Prompt Injection Attacks against Large Language Models.

LLM Agents Should Employ Security Principles Automatic and Universal Prompt Injection Attacks against Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.656779Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.656779Z digest=sha256:172d64858ca031480bb76d2f1dda6797f430a471675148a82d4682dc8fa09bb2

Observation 94717349-e1fe-4ad4-a098-bb4a1eefcca5 · outbound

This paper cites Prompt Injection attack against LLM-integrated Applications.

LLM Agents Should Employ Security Principles Prompt Injection attack against LLM-integrated Applications

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.736788Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.736788Z digest=sha256:aae86b4a5ab6865a583d7debd64f76098f35804298d6c767dfb6a09c92bd6b99

Observation 4076bcf0-2259-46ef-b7b3-4336c42dee73 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

LLM Agents Should Employ Security Principles Formalizing and benchmarking prompt injection attacks and defenses

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:13.810103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:13.810103Z digest=sha256:fd74cbad7a2dae855547da91f828f3d77a55f704893f6f97bd5924099282ebe7

Observation 63ce2e3b-8681-4ef4-932a-ae59ee8ac81d · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024.

LLM Agents Should Employ Security Principles Tree of attacks: Jailbreaking black-box llms automatically.NeurIPS, 2024

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:25.058794Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:13.859636Z digest=sha256:c87a6700679963e0b166653db658e085f256f750da19273cb03933a1a4678f80

Observation 58de7286-4c36-43da-907b-85ec38fcfd78 · outbound

This paper cites Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data.

LLM Agents Should Employ Security Principles Secure data with zero trust.https://learn.microsoft.com/en-us/security/zero-trust/deploy/data

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.926146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:13.934623Z digest=sha256:3c2fb4150a37965fc767582428859d0a63d75e497d92e657b2bb472ea13e3c95

Observation 01f8cddd-f5a4-45f6-9135-eaae55082fa6 · outbound

This paper cites GPT-4 technical report, 2023.

LLM Agents Should Employ Security Principles GPT-4 technical report, 2023

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.016657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.016657Z digest=sha256:fdeeac45b22c901e6279b4f82174974b4c93820c07f965c56eab0faf7a2c1b4f

Observation b3203619-4d85-4a8c-ab2a-f8420dd879cf · outbound

This paper cites Optimizing instructions and demonstrations for multi-stage language model programs.

LLM Agents Should Employ Security Principles Optimizing instructions and demonstrations for multi-stage language model programs

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.731074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.102885Z digest=sha256:d5dc61da2a616cdac6cae540e82698ceb9afa2a34632623758a540c69b56bac1

Observation b6d67e25-53c6-461b-aa1d-e997e1b703d6 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

LLM Agents Should Employ Security Principles Ignore Previous Prompt: Attack Techniques For Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.183326Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.183326Z digest=sha256:eb573cc13e33f4e07a96416867c1c121cb393d64ebbb905ff701ece8017c570a

Observation 8526a788-4653-4897-8018-f8bda732c331 · outbound

This paper cites The sandwich defense, 2024.

LLM Agents Should Employ Security Principles The sandwich defense, 2024

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.609888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.231663Z digest=sha256:d7c3c4ab87aa40a965e060f7a5d5f3e7b06d26a30761b612cb281009bb5096a8

Observation 6a19f497-1e9f-4732-8da4-fc51e0ab031d · outbound

This paper cites Fine-tuned deberta-v3-base for prompt injection detection, 2024.

LLM Agents Should Employ Security Principles Fine-tuned deberta-v3-base for prompt injection detection, 2024

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.391206Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.309044Z digest=sha256:e967aa0d1b1e0e931ff48c4042f9415833996ed08f9f0eb94d6b2075a74282cc

Observation 39a7815c-9f5a-4977-b7ee-6fcf06d14461 · outbound

This paper cites Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024.

LLM Agents Should Employ Security Principles Llm-based agentic systems in medicine and healthcare.Nature Machine Intelligence, 6(12):1418–1420, 2024

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.349072Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.349072Z digest=sha256:8ba6a6b3940d1a9fc0a7f27186f68d344c099e6812d2a55577537e7891a7ae14

Observation cf62a05f-e636-4597-af89-a63000ad4fd1 · outbound

This paper cites Improving language understanding by generative pre-training.

LLM Agents Should Employ Security Principles Improving language understanding by generative pre-training

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.458743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.458743Z digest=sha256:018886bf506fc31d021a6585b342cabfdd90c0fe2f63d435d1212d77f786430b

Observation b095827c-cbd0-499c-9369-795dbcd17625 · outbound

This paper cites Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019.

LLM Agents Should Employ Security Principles Language models are unsupervised multitask learners.OpenAI blog, 1(8):9, 2019

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:24.067470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.532396Z digest=sha256:7bcbe1b3cddbeed2f4b36accb8f29780d7719224279b17a33c4b209f82db989a

Observation e92c744a-dbb5-4a26-ab6a-45083317a23a · outbound

This paper cites Identifying the risks of lm agents with an lm-emulated sandbox.

LLM Agents Should Employ Security Principles Identifying the risks of lm agents with an lm-emulated sandbox

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.597041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.597041Z digest=sha256:9d57e739c67d504983e09ffb644d0da93fc4bf990588cbe13b147fe11dd44177

Observation 5ea5a6d0-fd10-4acd-97a8-9e32e13e4d39 · outbound

This paper cites Saltzer and Michael D.

LLM Agents Should Employ Security Principles Saltzer and Michael D

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.926538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.704723Z digest=sha256:e9719a06d6ad0929aae968052cd0ca9b8f9026afb2ead055f12533f74787a055

Observation 12f99703-4403-4662-8a8c-f52513336761 · outbound

This paper cites Scalable and transferable black-box jailbreaks for language models via persona modulation.

LLM Agents Should Employ Security Principles Scalable and transferable black-box jailbreaks for language models via persona modulation

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.847173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.809955Z digest=sha256:dac7dad6bd7ce387e79b60c019555605594f64b16cd91ee49ec1bfcd8f420995

Observation 2c2bde08-6264-4a0e-8f08-47e16c10a20c · outbound

This paper cites PrivacyLens: Evaluating privacy norm awareness of language models in action.

LLM Agents Should Employ Security Principles PrivacyLens: Evaluating privacy norm awareness of language models in action

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.711449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:14.862141Z digest=sha256:b02a1e8a6e32cf6ba5aa1627fda78c9f372d1d39ee4f79a8f1a8f24ced4e0909

Observation ed2e0c91-b822-4f97-aeaf-90334fe082a8 · outbound

This paper cites Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024.

LLM Agents Should Employ Security Principles Collaborative gym: A framework for enabling and evaluating human-agent collaboration.arXiv preprint arXiv:2412.15701, 2024

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:14.965587Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:14.965587Z digest=sha256:d066d3f2496a1499cc68f5eab3d4df94d7e2195589cf869bbc4c385c6eff1f51

Observation 490b3d32-0aaf-4692-91a5-47f4cf418e97 · outbound

This paper cites "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.

LLM Agents Should Employ Security Principles "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.041346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.041346Z digest=sha256:8d2f34287be8ca8769363a6f033a7c87e38ffdbcc9d23bd7c0680e2ce0bc2ba3

Observation 7913acda-421d-4cda-b47a-e7e91e03b39d · outbound

This paper cites Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn.

LLM Agents Should Employ Security Principles Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, and John "Four" Flynn

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.568018Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:15.133715Z digest=sha256:c1bc71eb7aa73ba777489a55c74bfba0b9510f3d9c6ac6360580462e12a119ba

Observation 62a2d446-309d-4e3a-bdec-858410c0b0e0 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

LLM Agents Should Employ Security Principles Progent: Securing AI Agents with Privilege Control

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.258181Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.258181Z digest=sha256:5cead9ce2d96e218b5b2b2426f4bba693c79293a7231c8ed93bc19ec478d5a46

Observation 66496283-4700-425d-8a6a-d96b84f88a3d · outbound

This paper cites Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles.

LLM Agents Should Employ Security Principles Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.340645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.340645Z digest=sha256:ede49c0279c93676a72b431e5a2670fb20a992d6b18f9f694794b7b6a5794c6c

Observation 7e370c83-7e1d-49cb-bf5a-fd9b142233aa · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

LLM Agents Should Employ Security Principles LLaMA: Open and Efficient Foundation Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.374992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.374992Z digest=sha256:da368b67c92cc8cc5d0d89eb7a90d6d5545b2abad8cd62d67ac334da8030013d

Observation 49bcb3ce-1f1a-4aa2-b8ed-f22c0a351464 · outbound

This paper cites Contextual Agent Security: A Policy for Every Purpose.

LLM Agents Should Employ Security Principles Contextual Agent Security: A Policy for Every Purpose

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.456892Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.456892Z digest=sha256:a12e44100d7874f838023776c7c8d36d531c605d23562cc61816032ae03c247b

Observation ccc84b4b-c405-43f6-a854-5b58edeb97bc · outbound

This paper cites Unveiling Privacy Risks in LLM Agent Memory.

LLM Agents Should Employ Security Principles Unveiling Privacy Risks in LLM Agent Memory

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.532647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.532647Z digest=sha256:e6d26f1ac979214068a7336de1260ae1e297bdadfad06f66a65792f7e034686a

Observation b2416549-9e07-4fe0-a7c2-c50da359fe7e · outbound

This paper cites Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models.

LLM Agents Should Employ Security Principles Gradient-Based Word Substitution for Obstinate Adversarial Examples Generation in Language Models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.631370Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.631370Z digest=sha256:aa323425b519e964d0887a2f28c724b0ffbbfc8866a099ac21513585d3a09d17

Observation 6e96c548-5365-4c4e-a1c9-ae934e9cf4fd · outbound

This paper cites Jailbroken: How does LLM safety training fail? InNeurIPS, 2023.

LLM Agents Should Employ Security Principles Jailbroken: How does LLM safety training fail? InNeurIPS, 2023

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.471413Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:15.706109Z digest=sha256:929c72f5080459c83743fc915d07a6e32644458c668e7011b69e45ccc2773f5b

Observation 002ddea9-086d-45ec-b623-7ae8f92a9849 · outbound

This paper cites IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.

LLM Agents Should Employ Security Principles IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.770833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.770833Z digest=sha256:f0143780f610485e54eaa80df8afa1b7b4256435ca0d5cdfc64622c693529136

Observation 501d3fa2-9165-4f6f-9a3a-612981623685 · outbound

This paper cites Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023.

LLM Agents Should Employ Security Principles Chatarena: Multi-agent language game environments for large language models.https://github.com/chatarena/chatarena, 2023

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.297070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:15.848097Z digest=sha256:02d0dfa14cdbd9b72066e618e93927498de83bb2db1120675137bcc2c6af333f

Observation 33867e88-cbca-4552-8a3e-9e4b7474d0df · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024.

LLM Agents Should Employ Security Principles Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments, 2024

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.919093Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.919093Z digest=sha256:847c5d15e26f1c2182ce986aadef77876613de88053e285c794becacd368bdb6

Observation 54353bad-a6dc-49d0-b7fd-50f97b2bc4ab · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

LLM Agents Should Employ Security Principles Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:15.984482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:15.984482Z digest=sha256:123e05aeec13f18c2afefe71b4d883a6f0986461eec5342acfe58e98b7203fed

Observation ba5b2bdf-6dcb-42ea-9e6d-51a56a1db8fc · outbound

This paper cites GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts.

LLM Agents Should Employ Security Principles GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.057577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.057577Z digest=sha256:9e0b9740f884261885ade7c406cc6942c03e0048dd60e3e2ccac4ce3ec2570d3

Observation a35ad4c9-6bde-41a7-aa1a-c4a918fbf45e · outbound

This paper cites LLM-Fuzzer: Scaling assessment of large language model jailbreaks.

LLM Agents Should Employ Security Principles LLM-Fuzzer: Scaling assessment of large language model jailbreaks

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:23.038320Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:16.121597Z digest=sha256:81eecbba4cb19af07b9d49458a1579405905a930a3a1c723c345695c005f13f9

Observation 9ecd6738-1a77-4f90-b57a-10e3daf71070 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 68

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.780421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:16.201346Z digest=sha256:cc9fe4474dbfaccbd3ee0e6f2e66b2ccb9305cf45f8015a680edbf9ee2bb3e6f

Observation 8971b96f-62de-484e-9f31-5cfc8ebf7e08 · outbound

This paper cites R-Judge: Benchmarking Safety Risk Awareness for LLM Agents.

LLM Agents Should Employ Security Principles R-Judge: Benchmarking Safety Risk Awareness for LLM Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.267748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.267748Z digest=sha256:4d7b450d8c79fbae3e8d37137d7acbb36e39f9dd7dfe0e9b5d34aa31636ad0ab

Observation b55ef027-4d4d-46ce-81ce-066aa0603d52 · outbound

This paper cites GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher.

LLM Agents Should Employ Security Principles GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.601536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:16.345626Z digest=sha256:38cccb4b5a78630ff0775f38f2123523aba9cfe118f1e8105a54f5fee3b9200c

Observation 5dc51e68-0ae0-474a-82ae-456547c0ebde · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

LLM Agents Should Employ Security Principles InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.461006Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.461006Z digest=sha256:56f2de2b0f25d8b602079a8098a2be3c98647ad9ea3ce0c9f3bd54b63c9ec1e9

Observation 8ac99a43-caa9-4b74-a84e-8675f8bc3679 · outbound

This paper cites Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y.

LLM Agents Should Employ Security Principles Zhang, Joey Ji, Celeste Menders, Riya Dulepet, Thomas Qin, Ron Y

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.440904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:16.557915Z digest=sha256:a744337eef70259e2b11c80a19637dbbcdf510e7435a83b85aba2fd57a533658

Observation 4adf505c-776b-47ab-bae3-822d609394ca · outbound

This paper cites Goal-guided Generative Prompt Injection Attack on Large Language Models.

LLM Agents Should Employ Security Principles Goal-guided Generative Prompt Injection Attack on Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.635079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.635079Z digest=sha256:213b6e01008a6cdd0881fa2916692e341c109826a718c2119d8345a9a6caf59e

Observation b10c2da8-b53b-4941-aedf-cac699e19392 · outbound

This paper cites Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents.

LLM Agents Should Employ Security Principles Agent security bench (ASB): Formalizing and benchmarking attacks and defenses in LLM-based agents

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:22.322556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:16.733672Z digest=sha256:71fb50002e3d68237623e1e3d014b3fbdb969fb0764461f197ad70fbbe1906bc

Observation 6bd88959-2a42-4211-9da3-316e90d52851 · outbound

This paper cites Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction.

LLM Agents Should Employ Security Principles Holistic Automated Red Teaming for Large Language Models through Top-Down Test Case Generation and Multi-turn Interaction

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.802912Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.802912Z digest=sha256:0e508d704e6bcc65b070eca2826af67a512318e51f406de500609e042e2d0cd9

Observation 9c4055af-829d-4ce2-946d-b7ff3dcb3103 · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

LLM Agents Should Employ Security Principles Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.878014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.878014Z digest=sha256:2d274432159c9109befad1d74ac0ef01f3f6dd34f3c575589b11685bb873f4d7

Observation b4aec45b-fb05-4462-b4da-1ef170ba4aa4 · outbound

This paper cites Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025.

LLM Agents Should Employ Security Principles Agentdam: Privacy leakage evaluation for autonomous web agents.arXiv preprint arXiv:2503.09780, 2025

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:16.979796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:16.979796Z digest=sha256:25f72cf08a98447a040ae37c37836ff236b91fe8688f38a2bf31530d7254c771

Observation 4755f0c4-0df9-493b-bc87-041b609ba668 · outbound

This paper cites RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage.

LLM Agents Should Employ Security Principles RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.059726Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.059726Z digest=sha256:c18c4f0caa34333095b57108c6b1ba42a549f02395868a133d886bdb87577012

Observation f9c6f5a0-b45e-4e3f-b09c-c24ef5337624 · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

LLM Agents Should Employ Security Principles WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.145765Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.145765Z digest=sha256:34753ee5b795693e866350bb5291e01b65a4af617e0066d28a1e23ab7c3b1d08

Observation 4e6c1294-ed3f-4e98-9bd1-d33b70975e5f · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

LLM Agents Should Employ Security Principles Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T12:42:17.234871Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:42:17.234871Z digest=sha256:3ae5a38472e0ba491beb34f58ece9b629da8b2a5aa0c7aa1981c6edf50b67817

Observation af664236-e50d-4876-a479-04426623bb7f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 81

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.222084Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:17.371158Z digest=sha256:35fef5700b3dbf2268ee6f5ec2a7cbd8d06963c1a68dd075310e3211024537e4

Observation d893c327-457a-43bb-a07b-23da90095d20 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 82

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:22.117728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:17.414088Z digest=sha256:b79aacf9bffc5e3632cdff31e7690d73496dcca2a957e382381ccb5ac18aa7fe

Observation 6d981ffe-26a1-4e16-a9c6-f9bd07cd4b93 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 83

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.981233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:17.513349Z digest=sha256:5389f3dcd0cfb41452d10088119d05c8d3e292e6bd22d3bb1157764e0e67280e

Observation 068bf66b-2211-4c74-a8f3-0b52c326865f · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 84

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.877047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:17.692770Z digest=sha256:21eaea7a76b2acc4a0b54b74b5e379a8fe7907983d0f724a516a42d76c0af12f

Observation d0b69c9e-f71d-4e53-8e62-b9548e2a0acd · outbound

This paper cites Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning.

LLM Agents Should Employ Security Principles Output your analysis in a structured JSON format that clearly states permissions for each tool based on the task context and provides DETAILED reasoning

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T12:42:21.708644Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:17.877754Z digest=sha256:23c8957e27ecd19484aa3016bf06a9602c7c106a25b04cd6ba0bc184a6468878

Observation 3379054e-420d-48f9-b4ee-1498a4230ae7 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 86

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.492939Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:18.044792Z digest=sha256:d7c9f058fc21981283a028672c542a9d58e0225413e5fa20501db076e3484c60

Observation fabc4ed9-d310-4eb0-a9bc-e162304cd1c5 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 87

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:21.276654Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:18.209326Z digest=sha256:2b0ddac728930c9b2e13106111ac6670d5dd7b9155f8535404601dd6588bd1d5

Observation a23379ba-d10b-4a84-8488-6a14c06a5562 · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 88

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.946610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:18.275656Z digest=sha256:fbfd7c9aa25417bcd6106b5f3ac7a58075778ee5485cc1cb08023f11d8cc9ff9

Observation 3bd0b09a-4f36-4946-aad4-d0ec73c114de · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 89

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.646846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:18.334643Z digest=sha256:a17f33d06713f41572fafc699aa8b5707eb3c4f18e35f6ee3a1163a303057ff3

Observation 3586a497-e439-41c5-bcb5-2bfc07e1b6ca · outbound

This paper cites an unresolved cited work.

LLM Agents Should Employ Security Principles Unresolved cited work

Reference 90

Resolution
unresolved
raw_fallback, observed 2026-08-07T12:42:20.381960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T12:42:18.393562Z digest=sha256:f1a333b3cdeca85d646d8b50dfb162b71bc4ecfefd00e875f84df8b935f66a2b

Pith citing papers

Observation 16f8fd0f-70db-4624-818d-15468c6f285e · inbound

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks cites this paper.

SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks LLM Agents Should Employ Security Principles

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T04:33:17.074410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:33:17.074410Z digest=sha256:5425aa9ef4add925df0c3874759ae47b92b017850a281202941713f020848603

Observation ac2932f3-7626-4f90-8d04-0933120e2807 · inbound

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance cites this paper.

LLMs are Capable of Misaligned Behavior Under Explicit Prohibition and Surveillance LLM Agents Should Employ Security Principles

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T21:22:59.187197Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:22:59.187197Z digest=sha256:88a7148f9d5bbb408931ae2ac2b697895e5c25eee6bbab0d88e0166dbfc99bfb

Observation 7c43d2ea-12ac-4812-93c2-e9bc600e31ab · inbound

Security Considerations for Artificial Intelligence Agents cites this paper.

Security Considerations for Artificial Intelligence Agents LLM Agents Should Employ Security Principles

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-15T12:40:00.295146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-15T12:37:27.153365Z digest=sha256:6e33740f5b3a6cfe42dc6ea891dc9d9e92ef2fdf17746bfa2b07717e1a2c8151

Observation 10df942f-6b11-48c7-a27b-d46eaacc960b · inbound

Parallax: Why AI Agents That Think Must Never Act cites this paper.

Parallax: Why AI Agents That Think Must Never Act LLM Agents Should Employ Security Principles

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:01:04.817173Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T15:13:07.178551Z digest=sha256:9f0ee16d008f08a8b58b6b384033f85f47f53cc2e478a9b18d5bbaa9987726a6

Observation a4819020-cad8-41ab-9560-085e22e71429 · inbound

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents cites this paper.

A Low-Latency Fraud Detection Layer for Detecting Adversarial Interaction Patterns in LLM-Powered Agents LLM Agents Should Employ Security Principles

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:01:14.315710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-09T18:56:12.400565Z digest=sha256:db747d4dd0166e9e46755d5502d1d5328101df934f4ede5dc681152f4ec24776

Observation e4e679a8-f1a2-420d-a7ab-a670893e7829 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T10:46:31.792945Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-07T02:12:30.086152Z digest=sha256:541bee65d837fde8f94932d043cd2fd9e23d17a70505b9a1ad798e1c0baa8a55

Observation cb51a1bf-cc9b-4d9b-b170-fe13e60abd32 · inbound

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI cites this paper.

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI LLM Agents Should Employ Security Principles

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-05-09T06:55:44.451126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-08T17:56:09.884837Z digest=sha256:d093f5246e879a0cbca96ad84dd66a0f5d48dfbcded2667bc14a59659a8e645a

Observation e4d2c026-00c6-45b8-b140-e16f5678ab00 · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks LLM Agents Should Employ Security Principles

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T08:01:33.084545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:dcc98fc8e09e7519164135c00909cecaa8621d2cd12f9ba85a1ff4b471923144

Observation 65f35965-3cb2-4e70-9c1f-4339f87c9b74 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:28:00.169507Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-14T21:23:48.061702Z digest=sha256:cd42f98cb73ce193cf23428178cb1e16abc48959cb703c654139f98f0d574252

Observation f948f307-afc6-420e-b662-4c12c1ff14cc · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-20T23:29:12.644850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-20T23:28:47.424991Z digest=sha256:22c7efcfa40f794a573031190eba2989c6a8319dad9f2911968e71a46ec71b21

Observation 0d2ef391-5e3f-409c-b30e-6059138001f7 · inbound

Ghost in the Context: Policy-Carriage Integrity in LLM Agents cites this paper.

Ghost in the Context: Policy-Carriage Integrity in LLM Agents LLM Agents Should Employ Security Principles

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-03T00:07:27.596565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-07-02T23:59:14.667099Z digest=sha256:bad54931dbcf57974503a2e2b05c6b398406abb2cdb317e8e18bc18e3200e93f

Observation 7c7b7853-fdc2-4fea-8023-43dc2990d156 · inbound

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI cites this paper.

Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI LLM Agents Should Employ Security Principles

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-02T03:26:29.052170Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-28T10:04:44.962968Z digest=sha256:05e9f977e8c7ec9501fb98b437023f54a30baa44f696f6faa50738f8da65b5e7

Observation 71e6500c-65af-4abf-8e9d-d28e894d7da6 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation LLM Agents Should Employ Security Principles

Reference 244

Resolution
verified exact
arxiv_id, observed 2026-06-27T13:20:57.050204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:d7e0196dde18a05c70db067febfbf8b49050e8be239932b967afd2fa8d7c0a5b

Observation 90a16c7c-2cd5-4ae4-86c9-ef72ddf6ee7f · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-07-04T18:00:00.381118Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-25T23:17:58.968269Z digest=sha256:c417eb0b5b50d8939c1fd68c66434d890bd205e94d1ff83c8b63b268f503115d

Observation 32bf28b6-f117-4c6b-8aa9-951c366ffe89 · inbound

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming cites this paper.

AutoSpec: Safety Rule Evolution for LLM Agents via Inductive Logic Programming LLM Agents Should Employ Security Principles

Reference 41

Resolution
unresolved
no resolver link, observed 2026-07-12T12:34:58.460933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T12:34:58.460933Z digest=sha256:de6ceb1fd140ec3d850d6c894a3035b0f9232e2a82e10911bd72c8c3ea64521a

Observation c8d7d5bb-4367-4626-a82c-7e3f4a68c151 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents LLM Agents Should Employ Security Principles

Reference 44

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T13:39:51.356324Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:d406f241bab0cdf254cdc0a3bd07fcee4573551bbec9fad61337a9556766567c

Observation 58d014e1-8893-40b7-9413-4900eec7ff11 · inbound

Safeguarding LLM Agents from Misalignment through Provenance Analysis cites this paper.

Safeguarding LLM Agents from Misalignment through Provenance Analysis LLM Agents Should Employ Security Principles

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-07-04T01:29:22.001648Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-07-04T01:26:25.858521Z digest=sha256:3dd04a8a74db9c2c7a28783caafb9e577338cb3d027a5665291421cc8831bbd9

Observation 2cc1333c-e2fb-42b6-9c5b-f243dd227d9f · inbound

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents cites this paper.

NEXUS: Structured Runtime Safety for Tool-Using LLM Agents LLM Agents Should Employ Security Principles

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-02T13:11:53.371921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:11:53.371921Z digest=sha256:022327755021938509a4a176f6cc7185af0105b2e733aae3ab470ee823434a87