Pith. sign in

Paper Citation Record · LEDGER

Multi-step Jailbreaking Privacy Attacks on ChatGPT

As of 10 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 31 inbound Pith citation observations for arXiv:2304.05197.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2304.05197 v3

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 31 of 31 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 31 of 31 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-10T00:12:04.892253Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

23
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 204da7a1-74fc-4dbf-8820-6ce367f02093 · inbound

Jailbroken: How Does LLM Safety Training Fail? cites this paper.

Jailbroken: How Does LLM Safety Training Fail? Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-05-14T18:17:42.875300Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-14T18:17:42.752997Z digest=sha256:3db5d881dc6f829a88b27845d8c21f642b8b0d8597fdab1f3747396ef24d7adc

Observation 491ec865-d4aa-4cee-a1d3-67c6f26efb66 · inbound

"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models cites this paper.

"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-17T08:39:28.187529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-17T08:39:28.047394Z digest=sha256:55c9ed98d50d365bca7758aa7f87b4c7e783546ff9a1184fa070346d0c2843f2

Observation 22aa7f8a-75c6-4e1c-8bb8-b3e5138b9891 · inbound

Baseline Defenses for Adversarial Attacks Against Aligned Language Models cites this paper.

Baseline Defenses for Adversarial Attacks Against Aligned Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-13T23:24:40.042862Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-13T23:24:39.835347Z digest=sha256:a6dacb7f6a07429765cc22246a295b2c2b764de344aa3e16cbafe01c56042ea7

Observation 87765850-f45c-4693-8675-f0980c4c5c32 · inbound

GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts cites this paper.

GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-15T06:25:21.059948Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-15T06:25:20.966510Z digest=sha256:0d749b9bc6707ada3c8286b26a6e20465a6086ea91986eb29d76312ba4b13c20

Observation 0208d8b9-342c-45c0-b777-fadf982d748a · inbound

Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation cites this paper.

Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-16T22:00:51.560693Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-16T22:00:51.487120Z digest=sha256:1aa0fb1000e0b05b2467373510d41271288e9c169a1764ce401d571e37f07261

Observation 26fc97cf-6200-4b3e-b9f1-a3940bb92306 · inbound

TrustLLM: Trustworthiness in Large Language Models cites this paper.

TrustLLM: Trustworthiness in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 277

Resolution
verified exact
arxiv_id, observed 2026-05-18T11:17:08.792092Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-18T11:17:08.108565Z digest=sha256:80bd5a53bba50ae2e455c8ba37a6eaffdb74481c02988be37a0eb54088fc7ffc

Observation 2af2417c-cfaa-4663-8bfb-f254c35ef1df · inbound

Jailbreak Attacks and Defenses Against Large Language Models: A Survey cites this paper.

Jailbreak Attacks and Defenses Against Large Language Models: A Survey Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:20:44.714757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-15T02:20:44.368219Z digest=sha256:a4a3c2b11d45bca9a059ffacb83fac5a891fd18c4449f6e0096d8862bcdd9bb5

Observation 94499c3c-ab81-4945-b5b5-750891f5101e · inbound

Jailbreaking LLMs' Safeguard with Universal Magic Words for Text Embedding Models cites this paper.

Jailbreaking LLMs' Safeguard with Universal Magic Words for Text Embedding Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-10T00:12:04.892253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T00:12:04.892253Z digest=sha256:c1c252861d004a1788f9920063cf539494cf4e2a44a9fb563ba7d9ffc4774886

Observation 2df84383-6af1-4717-a0b3-27be0b89e95e · inbound

Peering Behind the Shield: Guardrail Identification in Large Language Models cites this paper.

Peering Behind the Shield: Guardrail Identification in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-23T03:45:21.377951Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-23T03:45:14.234545Z digest=sha256:462e4a0aa6675f6336622ea26f1c0ef49f0135b1fe7f5cf2fd178298a86a410f

Observation 9c9bf0fe-1e48-4a6d-87d3-56f181b44334 · inbound

Large Language Model Adversarial Landscape Through the Lens of Attack Objectives cites this paper.

Large Language Model Adversarial Landscape Through the Lens of Attack Objectives Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-09T10:29:50.045250Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T10:29:50.045250Z digest=sha256:732dcbb4dcd19548e7e8f15b922748b9391759485f93c2585b13385f84d3de7b

Observation 34cecc57-b2a0-49b9-9b31-80218f7f3585 · inbound

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation cites this paper.

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-09T05:31:14.325060Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T05:31:14.325060Z digest=sha256:8587dc87bcf300f5e1d4652406ee4f8f6e921ac4e31df102f73203e5ea2dfdbc

Observation 69c29d1a-8897-4304-9e63-78f6bb46e2ba · inbound

KDA: A Knowledge-Distilled Attacker for Generating Diverse Prompts to Jailbreak LLMs cites this paper.

KDA: A Knowledge-Distilled Attacker for Generating Diverse Prompts to Jailbreak LLMs Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-09T04:22:00.471038Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-09T04:22:00.471038Z digest=sha256:d08120413eac8e2127d84d8b9d19a84657bd8ea89cba48c5fb31f21525d1c2fa

Observation f7e18a7c-af09-43e7-a55d-7dc2e77a5963 · inbound

Context Reasoner: Incentivizing Reasoning Capability for Contextualized Privacy and Safety Compliance via Reinforcement Learning cites this paper.

Context Reasoner: Incentivizing Reasoning Capability for Contextualized Privacy and Safety Compliance via Reinforcement Learning Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T15:37:27.312304Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:37:27.312304Z digest=sha256:ae76e82ed66f687f963c8bdb09bcb913aa25b246d1897099d80fdfefae7c75c8

Observation f0a5b696-8e6d-41ff-a1ee-460b73b5c2e8 · inbound

Audio Jailbreak Attacks: Exposing Vulnerabilities in SpeechGPT in a White-Box Framework cites this paper.

Audio Jailbreak Attacks: Exposing Vulnerabilities in SpeechGPT in a White-Box Framework Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T14:27:05.763058Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:27:05.763058Z digest=sha256:012b9ee7ea11c8734b329e54d8d1b3452c7d8f345d13f635ee5a8920f65cb1ca

Observation 227d56cf-4a72-4ca8-954f-adc32a8a8f80 · inbound

System Prompt Extraction Attacks and Defenses in Large Language Models cites this paper.

System Prompt Extraction Attacks and Defenses in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T13:28:17.454592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:28:17.454592Z digest=sha256:79b2a4e2aba095dafb4e96d6c211c1b3ef271472ef7d7101091600706d3be5b4

Observation b71f90d3-ed83-411a-953f-8f89b9ec73c1 · inbound

From Hallucinations to Jailbreaks: Rethinking the Vulnerability of Large Foundation Models cites this paper.

From Hallucinations to Jailbreaks: Rethinking the Vulnerability of Large Foundation Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:34:34.521629Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:34:34.521629Z digest=sha256:3e08bc4ec3126fd8d5ee7c0b4b23cb6ce930244d6c646a3617fca3239acb7db8

Observation 8ee003a4-d249-40a4-8d2b-ffcf7a084972 · inbound

SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and Mitigation cites this paper.

SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and Mitigation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T00:46:10.159449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:46:10.159449Z digest=sha256:0cb2241b386e1eefd4b77860ea93c53218a3f12998295df6a8cd4eb3442bf41f

Observation 2ec64b4f-08f6-42c6-a595-c514a2f21e81 · inbound

SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models cites this paper.

SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T23:20:53.545039Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:20:53.545039Z digest=sha256:e141a183529767f7dc01e18babeda2e4f83e5c42b6a110162ccdcba7704b1fdd

Observation 40754a9e-14de-4b14-8c84-e60493fb549b · inbound

Context-Aware CodeLLM Eviction for AI-assisted Coding cites this paper.

Context-Aware CodeLLM Eviction for AI-assisted Coding Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-06T23:20:21.849271Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:20:21.849271Z digest=sha256:ae5521afcb74d235ebb0a68c98e00d144f85362653a94fb788384a65a9e05775

Observation 56c20140-73a0-4ff4-9ef4-3d80d0683b38 · inbound

PII Jailbreaking in LLMs via Activation Steering Reveals Personal Information Leakage cites this paper.

PII Jailbreaking in LLMs via Activation Steering Reveals Personal Information Leakage Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T20:36:46.757676Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T20:36:46.757676Z digest=sha256:b9b5291a165b219786bed8a071182e6f3403d83667a6acea0213ddaaef21c1d7

Observation 3284897d-dcb6-4f19-94b1-f3889c235309 · inbound

`For Argument's Sake, Show Me How to Harm Myself!': Jailbreaking LLMs in Suicide and Self-Harm Contexts cites this paper.

`For Argument's Sake, Show Me How to Harm Myself!': Jailbreaking LLMs in Suicide and Self-Harm Contexts Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-06T21:05:19.409556Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:05:19.409556Z digest=sha256:a4ee63abbb568ee5cdf4da86b238c5d0ee380b7b331f33de129aae0a2b07a98d

Observation dff63c40-38df-4b90-87f7-1e84646346d8 · inbound

ASSURE: Metamorphic Testing for AI-powered Browser Extensions cites this paper.

ASSURE: Metamorphic Testing for AI-powered Browser Extensions Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T19:43:28.259535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:43:28.259535Z digest=sha256:11b574001f7c6c1a2b55e4086d091f3ce3b508e60a7db849505459609d710a83

Observation 71226ad7-b208-4b86-9b7a-fdf73dd78354 · inbound

MOCHA: Are Code Language Models Robust Against Multi-Turn Malicious Coding Prompts? cites this paper.

MOCHA: Are Code Language Models Robust Against Multi-Turn Malicious Coding Prompts? Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T14:17:34.033208Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T14:17:34.033208Z digest=sha256:3d3413fc1f353e2425c332005abb3db3460730880d465f06fb99cfcb5d10467d

Observation 5e00bf6b-3ea3-49c7-8290-047fa9be4ff3 · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 125

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:44.379657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:44.379657Z digest=sha256:dd7d965943cf2257da14a97ce00a97a5f718ad6dd0bc56f9222c57a754c1546e

Observation ef35f386-b49d-4051-89c1-c0d2990413b2 · inbound

GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs cites this paper.

GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 20

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T21:36:52.522996Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-18T21:34:51.665401Z digest=sha256:8d67fc566518c339570b3adead419bbd12800f530434c76d0c386747f1e60b25

Observation 0531ff80-7e34-4b9b-9aa5-b094f3650f56 · inbound

The Resurgence of GCG Adversarial Attacks on Large Language Models cites this paper.

The Resurgence of GCG Adversarial Attacks on Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T13:42:42.111230Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T13:42:42.111230Z digest=sha256:df441ad7fac5c068b7d8e4f947771e85f1d4aa152f9013e351cc81dfc46de7ad

Observation 1fc3e1a8-895c-4e0f-8215-22f8b45590cc · inbound

Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain cites this paper.

Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-05T10:44:10.497463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T10:44:10.497463Z digest=sha256:abfae33902d87d52642f460552014b14fe0bcac13792f4ad6b8bb2c2ebbcdb57

Observation eae64ffb-36c8-45b9-9b02-97bbad674b2b · inbound

A First Look at the Security Issues in the Model Context Protocol Ecosystem cites this paper.

A First Look at the Security Issues in the Model Context Protocol Ecosystem Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-18T06:12:26.285817Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-18T06:10:58.928119Z digest=sha256:fb27ccbf2e93bc93ae503cb6857f73116bbaf3029135a188ffd16404282cb0d0

Observation a8cd7965-2239-46e6-80de-95c139b66f82 · inbound

Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks cites this paper.

Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 55

Resolution
verified exact
arxiv_id, observed 2026-05-21T12:10:06.533915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-21T12:09:55.500940Z digest=sha256:c65fe5db513a8750b305a08a66df0ece5ff6635c24f2d26f91692425cae8a60d

Observation 9704c824-fe30-4529-a2bf-ebd943e2ca1c · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 108

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.876166Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:f717a36bb6ce69ab721b4ca3e953d34d6821d73a9588ba66e070218a85b54636

Observation cea1207f-3ba8-4970-8da3-33735677e940 · inbound

Probing Memorization of Tabular In-Context Learning cites this paper.

Probing Memorization of Tabular In-Context Learning Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 46

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T09:25:40.859090Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-07-01T06:37:44.328625Z digest=sha256:f861b182f76d9686681e8474e460f13619ecf06971723afbb0de6f5822e73975