1. Green, B., & Leo, G. (2026). LLMs Do Not Emulate Populations.

  2. Liu, Y., Zhao, X., Kruegel, C., et al. (2025). In-Context Watermarks for Large Language Models.

    Note: Indirect prompt injection to get LLMs to watermark their own output.