[ impact // evidence_of_use ]

Where the work went

A sweep of public references to Shrewd research identified 100 distinct traces across technical media, practitioner guidance, scholarly literature, implementations, and multilingual research coverage. We grade every trace by how independently the work was used — because a hundred mentions is not the same as a hundred people building on the idea.

A26
Independent invocation

Another author or engineer invoked, implemented, or used the idea inside their own argument or system — doing something with the work, not merely noting it exists.

B16
Substantive coverage

Independent media, blog, newsletter, or explainer coverage with real analytical content.

C13
Scholarly / institutional adoption

Downstream citation or adoption in surveys, formal frameworks, standards drafts, and other research.

D45
Discoverability

Localization, review services, index pages, and coauthor amplification — evidence of international reach rather than independent intellectual adoption.

[ what_matters ]

The signal, not the noise

The important number isn't 100 — it's the 26 cases where somebody is doing something with the idea rather than merely saying the paper exists. Five clusters stand out.

ETDI

Strongest engineering uptake

Trail of Bits compared its own security architecture directly against ETDI; FlowVerify incorporated it into production-security guidance; Glama treats it as an MCP security primitive; an independent MCP security specification ships an ETDIValidator; fuzzd cites it; and both an ACM survey and MCPSHIELD fold it into the MCP defense literature.

Defense Trilemma

Strongest conceptual propagation

Other researchers use the named result to explain something else: AgentDyn, contextual integrity, layered guardrails, lifelong safety adaptation. That is closer to a concept entering the vocabulary than to normal paper coverage.

LPCI

Behaving like a vulnerability-class name

PointGuard, Samyoga, Teleskope, CSA/AAGATE and independent commentators use “LPCI” descriptively without reintroducing the paper. AAGATE goes further and builds explicit LPCI controls into a separate governance architecture.

Go-Explore

Propagating as experimental methodology

Others are extracting the scientifically useful result — seed variance, causal exploit verification, and the danger of confusing diverse findings with verified vulnerabilities. The Kaggle reuse is an independent application of the experimental lesson to a different evaluation setting.

Manifold of Failure

Becoming evaluation vocabulary

Failure basins, vulnerability landscapes, topology — maps rather than isolated jailbreaks. The Weather Report and Emergent Mind are the cleanest outside examples of the framing being reused.

[ full_ledger // 100_traces ]

The ledger

Every traced reference, grouped by work. Multilingual review services (Moonlight, ChatPaper, alphaXiv) count as international discoverability, not as independent foreign coverage. The footprint runs through security trade media, engineering blogs, newsletters, governance bodies, and downstream scholarship — not mainstream mass media.

Defense Trilemma

18 traces
  • BLLM-HackingThe Defense Trilemma: why prompt-injection wrappers can't be completeEN
  • ARodelaThe layered guardrails trap; uses the trilemma to reason about correlated defense failureEN
  • ABayesian Sapien / cere-broLiSA; explicitly designs around rather than “defeating” the trilemmaEN
  • ADenis KimAI Security Digest; frames a “post-wrapper” security model with itEN
  • ALLM-HackingAgentDyn; interprets another benchmark through the Defense TrilemmaEN
  • ALLM-HackingContextual Integrity; relates a separate impossibility result to the theoremEN
  • ALLM-HackingDefensive Misdirection; situates a different defense against the trilemmaEN
  • BOwn Your AIEnterprise-oriented Defense Trilemma analysisEN
  • BRichlyAIWhy Prompt Injection Defense Wrappers Often FailEN
  • BThe Guardrail Weekly DigestPicked among its top AI-safety papers that weekEN
  • DKen HuangThe Computational Wall; synthesis with computational-hardness argumentsEN
  • DChatPaperSpanish editionES
  • DChatPaperSimplified Chinese editionZH
  • DChatPaperPortuguese editionPT
  • DChatPaperFrench editionFR
  • DChatPaperGerman editionDE
  • DChatPaperJapanese editionJA
  • DalphaXivPublic paper pageEN

Manifold of Failure

10 traces
  • BThe Weather ReportIndependent article on the MAP-Elites red-teaming workEN
  • AEmergent MindGPT-OSS safety analysis invokes behavioral manifolds/basinsEN
  • AStart With WCPGWArgues security should look beyond individual jailbreak promptsEN
  • DKen HuangWe've Been Testing AI Safety WrongEN
  • DIdan HablerSubstantial public explanation of the basin/topology ideaEN
  • BGist.SciencePlain-language technical deep diveEN
  • DalphaXivEnglish overviewEN
  • DalphaXivKorean overviewKO
  • DalphaXivSpanish overviewES
  • DDeepLearnPaper explainer/indexEN

Go-Explore

10 traces
  • BOSINT Team / MediumIndependent article deriving a “simplicity paradox” from the experimentsEN
  • AEmergent MindSelf-Play Security Testing; uses the results to motivate seed control and causal verificationEN
  • AKaggleWhat a Score Knows; applies the findings-vs-verified-attacks distinctionEN
  • AKaggle61st-place solution states its methodology follows the Go-Explore studyEN
  • BML Security Papers / AISpaperDetailed technical decompositionEN
  • DalphaXivEnglish pageEN
  • DalphaXivChinese pageZH
  • DChatPaperReview/summaryEN
  • DSciRateListing/discussion surfaceEN
  • DAIModels.fyiResearch profile surfaces and summarizes the studyEN

ETDI

30 traces
  • ATrail of Bits“We built the security layer MCP always needed”; compares its architecture directly to ETDIEN
  • ATrail of BitsMCP-security resources page includes ETDI as a security approachEN
  • BTrail of Bits / ContrastMCP Security Deep Dive webinar featuring ETDIEN
  • AFlowVerifyProduction MCP security guide; dedicated ETDI section and deployment adviceEN
  • AGlamaEdge AI/MCP security article recommends ETDI-style signing/versioningEN
  • AGlamaProduction MCP observability/security architecture includes ETDIEN
  • AGlamaMCP/cloud-services explainer invokes ETDI cryptographic definitions and policy constraintsEN
  • AGlamaMCP model/dashboard integration recommends oversight controls including ETDIEN
  • AModel Context Protocol SecurityTool Metadata Specification includes an actual ETDIValidator implementationEN
  • BVulnerableMCPFull ETDI Security Framework and implementation guideEN
  • AfuzzdMCP security scanner cites ETDI as cryptographic mitigation for rug pullsEN
  • Amcp-etdi (PyPI)Implementation makes the architecture consumable as softwareEN
  • DMoonlightFull ETDI literature review — EnglishEN
  • DMoonlightETDI — SpanishES
  • DMoonlightETDI — GermanDE
  • DMoonlightETDI — FrenchFR
  • DMoonlightETDI — JapaneseJA
  • DMoonlightETDI — KoreanKO
  • DMoonlightETDI — Simplified ChineseZH
  • DMoonlightETDI — Traditional Chinese/TaiwanZH-TW
  • DalphaXivSpanish ETDI pageES
  • DalphaXivEnglish ETDI pageEN
  • DHugging Face PapersETDI pageEN
  • DEurekaMagETDI conference/research summaryEN
  • CACM TOSEMMCP landscape survey describes ETDI as OAuth identity + policy access control against squatting/rug pullsEN
  • CMCPSHIELDFormal MCP-security framework evaluates ETDI as one of 12 existing defense mechanismsEN
  • C2026 poisoning-attacks surveyDescribes ETDI's cryptographic identity, immutable definitions and OAuth controlsEN
  • CUnicode TAG-block MCP paperExplicitly calls ETDI complementary to its own defenseEN
  • CIETF draftCross-domain agent authorization draft cites ETDI in its normative research backgroundEN
  • DArxivLensETDI pageEN

LPCI

16 traces
  • BCloud Security AllianceDedicated LPCI articleEN
  • APointGuard AILogic Layer Prompt Injection: Exploiting AI Memory treats LPCI as a newly defined vulnerability classEN
  • ASamyogaDefending Autonomous AI uses LPCI as a core threat category in its identity-control argumentEN
  • ATeleskopeUADP security FAQ defines LPCI as a distinct autonomous-agent threatEN
  • BPawan S.Independent explainer calling LPCI a new attack categoryEN
  • BRobert E. LeeDiscussion of LPCI among emerging AI-safety/security risksEN
  • BRock LambrosDetailed LPCI threat explainerEN
  • ACloud Security AllianceAAGATE governance architecture incorporates LPCI defensesEN
  • CMoonlightReview of AAGATE describes its integration of LPCI taint tracking/sanitizationEN
  • CMoonlightAAGATE/LPCI coverage — Traditional ChineseZH-TW
  • CMoonlightAAGATE/LPCI coverage — Simplified ChineseZH
  • CMoonlightAAGATE/LPCI coverage — KoreanKO
  • CMoonlightAAGATE/LPCI coverage — JapaneseJA
  • CMoonlightKorean review of an industry-agents survey identifies LPCI as an emerging security challengeKO
  • CPreprintsFollow-on LPCI work extends the vulnerability classEN
  • CHugging Facegenai-incidents dataset includes LPCI/LAAF in its incident/research taxonomyEN

COALESCE

5 traces
  • DMoonlightFull COALESCE review — EnglishEN
  • DMoonlightCOALESCE — SpanishES
  • DMoonlightCOALESCE — Simplified ChineseZH
  • DMoonlightCOALESCE — Traditional Chinese/TaiwanZH-TW
  • DMoonlightCOALESCE — JapaneseJA

MAIF

5 traces
  • DMoonlightFull MAIF review — EnglishEN
  • DMoonlightMAIF — SpanishES
  • DMoonlightMAIF — FrenchFR
  • DMoonlightMAIF — JapaneseJA
  • DMoonlightMAIF — KoreanKO

Bhatt Conjectures

3 traces
  • ALacuna by Tiptree SystemsBenchmarking Social Intelligence in Multi-Agent Systems uses Bhatt Conjectures to argue for causal-fidelity/metacognitive benchmarksEN
  • BArxiv DayChinese-language summary and framingZH
  • DFugu-MTJapanese translation/summaryJA

QFIRE

3 traces
  • BAI for Health HubSubstantial QFIRE healthcare-security coverageEN
  • DScietyPublic research/activity page surfaces QFIRE and its central healthcare findingEN
  • DGitHubQFIRE's public implementation/reproduction ecosystemEN
[ method ]

This ledger counts public references, not impact by itself. The honest summary: a survey identified 100 public references across technical media, practitioner guidance, scholarly literature, implementations, and multilingual research coverage — including more than 26 cases where independent authors or engineers operationalized or invoked the work in a new context. If you trace a reference we've missed, send it over.

Read the underlying papers