{"as_of":"2026-08-09T19:30:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:fed993fe146bc0c19bbec593717ed377b80dc5b9853c3092b286d6a25eba03b0","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":14,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":14,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":14,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":14,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T19:57:45.194846Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-07-02T21:27:24.512005Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-02T11:48:17.206729Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-05-12T10:59:30.728091Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2404.13208"},"observation_digest":"sha256:ed02e3987c90017132429ef860dedacdd2f64460869d0bbb261d621c6d65e7b4","observation_id":"cd290381-df30-48d8-868b-117460a444ed","resolution":{"observed_at":"2026-05-12T10:59:30.826587Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2406.13352","last_updated":"2024-11-24T22:04:23Z","snapshot_observed_at":"2026-07-06T18:33:32.806635Z","submitted_at":"2024-06-19T08:55:56Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","version":3},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-05-13T06:35:13.331872Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2406.13352"},"observation_digest":"sha256:8e20797de161197ad98125cbb1d0dd347c443fbb51c1ee65efc94f1398d1b152","observation_id":"12ec3800-2704-4bd4-a5a2-56b77f154a14","resolution":{"observed_at":"2026-05-13T06:35:13.433785Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2407.04295","last_updated":"2024-08-30T11:57:47Z","snapshot_observed_at":"2026-08-04T23:34:13.332065Z","submitted_at":"2024-07-05T06:57:30Z","title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-05-15T02:20:44.368219Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2407.04295"},"observation_digest":"sha256:3e98b2803fead426a39cb1a43f38f053f78259718b9cac24cde5974be9af08e2","observation_id":"0bc3445d-7ec7-4429-964c-af6cfaf3befd","resolution":{"observed_at":"2026-05-15T02:20:44.635844Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-08-07T19:57:45.194846Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.09974","last_updated":"2025-02-14T08:00:42Z","snapshot_observed_at":"2026-08-07T19:49:00.973991Z","submitted_at":"2025-02-14T08:00:42Z","title":"Has My System Prompt Been Used? Large Language Model Prompt Membership Inference","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-08-07T19:57:45.194846Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2502.09974"},"observation_digest":"sha256:16d6824f52a5b25c7fd52cce0deae0f1463ee0433ab5ea4b2345f8dbc77add57","observation_id":"57b01058-6c8b-42c8-9043-01a0ba6bcd20","resolution":{"observed_at":"2026-08-07T19:57:45.194846Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-08-07T12:35:38.140735Z","title":"Coercing llms to do and reveal (almost) anything, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.24832","last_updated":"2025-06-18T15:27:03Z","snapshot_observed_at":"2026-08-08T09:16:38.722740Z","submitted_at":"2025-05-30T17:34:03Z","title":"How much do language models memorize?","version":3},"reference_index":23,"source":"arxiv_source","source_observed_at":"2026-08-07T12:35:38.140735Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2505.24832"},"observation_digest":"sha256:40a4d41fcd3f12a2e399e40ab024a539450a084a66430d415ca742d0710f0b5a","observation_id":"92948dc0-135c-4145-8b20-f772f0df3aee","resolution":{"observed_at":"2026-08-07T12:35:38.140735Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2506.14493","last_updated":"2026-04-13T09:32:05Z","snapshot_observed_at":"2026-08-02T20:44:02.129321Z","submitted_at":"2025-06-17T13:14:55Z","title":"LingoLoop Attack: Trapping MLLMs via Linguistic Context and State Entrapment into Endless Loops","version":3},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-19T09:18:26.804728Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2506.14493"},"observation_digest":"sha256:49358820a9d35d2791dcae69707438d06c606f2559a70124c80a233df09fdcc9","observation_id":"09349338-0f64-4061-acc9-94f085aad380","resolution":{"observed_at":"2026-05-19T09:22:16.163991Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2507.12720","last_updated":"2026-05-13T15:04:08Z","snapshot_observed_at":"2026-08-03T04:43:10.143472Z","submitted_at":"2025-07-17T01:55:41Z","title":"FLEXITOKENS: Flexible Tokenization for Evolving Language Models","version":4},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-19T05:10:19.093601Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2507.12720"},"observation_digest":"sha256:614a1d3c2d8eaccd0e3e4c48f3bab3c3e2512df482a4bd49827469cb771ba35d","observation_id":"bca3bd7a-4616-4ea7-b834-2a00be8cf647","resolution":{"observed_at":"2026-05-19T05:12:05.171780Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-08-05T22:43:22.242905Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.06621","last_updated":"2025-08-08T18:10:03Z","snapshot_observed_at":"2026-08-08T21:16:30.433415Z","submitted_at":"2025-08-08T18:10:03Z","title":"Train It and Forget It: Merge Lists are Unnecessary for BPE Inference in Language Models","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-05T22:43:22.242905Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2508.06621"},"observation_digest":"sha256:ff76d823ecd731ae4aa6354f66dd2735cea2aae2bd84fca95bfa22dedd6efb33","observation_id":"cce640ef-1e5a-40f6-8868-169d6e4f26dd","resolution":{"observed_at":"2026-08-05T22:43:22.242905Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-08-04T09:25:40.590605Z","title":"Coercing llms to do and reveal (almost) anything.CoRR, abs/2402.14020, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2510.15476","last_updated":"2026-07-04T04:20:15Z","snapshot_observed_at":"2026-08-06T02:45:04.316908Z","submitted_at":"2025-10-17T09:38:54Z","title":"SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses","version":3},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-04T09:25:40.590605Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2510.15476"},"observation_digest":"sha256:a79cc099337c6491d372950b18ee371cbf68c541ec009bad58360cefa2384a37","observation_id":"a4c1acff-d1c7-4c9a-8f25-cb5f0c6c7363","resolution":{"observed_at":"2026-08-04T09:25:40.590605Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2604.08519","last_updated":"2026-04-09T17:55:50Z","snapshot_observed_at":"2026-07-06T22:57:35.435713Z","submitted_at":"2026-04-09T17:55:50Z","title":"Cram Less to Fit More: Training Data Pruning Improves Memorization of Facts","version":1},"reference_index":28,"source":"arxiv_source","source_observed_at":"2026-05-10T17:42:31.465077Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2604.08519"},"observation_digest":"sha256:b8eab2e9d52301b75ec7c3587b8c5f04728e34828acee53a90acae951c0031f7","observation_id":"79aef304-9d93-4235-ae5f-604d7b8bcbe0","resolution":{"observed_at":"2026-05-11T06:15:59.157070Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2605.00236","last_updated":"2026-04-30T21:15:38Z","snapshot_observed_at":"2026-07-06T23:13:42.661364Z","submitted_at":"2026-04-30T21:15:38Z","title":"Attention Is Where You Attack","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-05-09T19:54:41.445447Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2605.00236"},"observation_digest":"sha256:9ac1a24febfa960d991477cc516667f9db2c2ba690e55cf875c23945ed01771b","observation_id":"28274681-124a-4cd6-90b5-0873dad029a5","resolution":{"observed_at":"2026-05-11T15:31:05.088730Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2605.05116","last_updated":"2026-05-06T16:47:07Z","snapshot_observed_at":"2026-07-06T23:17:48.161262Z","submitted_at":"2026-05-06T16:47:07Z","title":"On the Hardness of Junking LLMs","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-08T17:38:32.028947Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2605.05116"},"observation_digest":"sha256:1f410dceade27653658f06bdf9f7c5867941f8dcf9e59061528adbf034ba92f0","observation_id":"b0305075-457a-4fc8-bb2c-8f2b48a0aa0a","resolution":{"observed_at":"2026-05-11T17:21:10.172661Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2606.07943","last_updated":"2026-06-06T02:10:03Z","snapshot_observed_at":"2026-08-07T22:38:29.909628Z","submitted_at":"2026-06-06T02:10:03Z","title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","version":1},"reference_index":47,"source":"arxiv_source","source_observed_at":"2026-06-27T19:52:23.006490Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2606.07943"},"observation_digest":"sha256:708923f05ff69a25e9fac36af6d7c9162389c156291874695de24c45771027b4","observation_id":"e6d6199e-a474-4b31-a99b-b733d08f4d04","resolution":{"observed_at":"2026-07-02T21:17:24.414483Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything","version":1},"cited_work":{"arxiv_id":"2402.14020","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14020","snapshot_observed_at":"2026-07-02T21:27:24.512005Z","title":"Coercing llms to do and reveal (almost) anything","venue":null,"work_id":"19f05728-aabb-4e0d-b82d-9e42162fa940","year":2024},"citing_paper":{"arxiv_id":"2606.07968","last_updated":"2026-06-06T03:52:27Z","snapshot_observed_at":"2026-07-06T23:47:33.680573Z","submitted_at":"2026-06-06T03:52:27Z","title":"RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-06-27T19:45:30.671490Z"},"links":{"cited_paper":"/paper/2402.14020","citing_paper":"/paper/2606.07968"},"observation_digest":"sha256:4a20e908e99c606104528b0b7f5234cb26ca5d6e7e29f125bfccdf75d33b2640","observation_id":"ec6e5f5a-22ba-4800-820b-189843765a97","resolution":{"observed_at":"2026-07-02T21:27:24.513488Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2402.14020/citation-record","integrity":"/paper/2402.14020/integrity","json":"/paper/2402.14020/citation-record.json","paper":"/paper/2402.14020"},"outbound":[],"paper":{"arxiv_id":"2402.14020","last_updated":"2024-02-21T18:59:13Z","latest_version":1,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-06T09:19:29.384394Z","submitted_at":"2024-02-21T18:59:13Z","title":"Coercing LLMs to do and reveal (almost) anything"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 14 inbound Pith citation observations for arXiv:2402.14020."}