{"as_of":"2026-08-11T05:45:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:57a4443e329632127ef76d0d686e7448741d6b0897d6807aaf57ce3b1121b4c7","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":9,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":9,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-10T06:31:04.303077+00:00","state":"measured"},{"denominator":9,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":9,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-10T22:11:59.976519Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":1,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":"2402.14857","doi":"10.48550/arxiv.2402.14857","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Is the system message really important to jailbreaks in large language models?","venue":"arXiv (Cornell University)","work_id":"17c11848-8842-4226-843a-072be2b10403","year":2024},"citing_paper":{"arxiv_id":"2407.04295","last_updated":"2024-08-30T11:57:47Z","snapshot_observed_at":"2026-08-04T23:34:13.332065Z","submitted_at":"2024-07-05T06:57:30Z","title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","version":2},"reference_index":126,"source":"pdf_text","source_observed_at":"2026-05-15T02:20:44.368219Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2407.04295"},"observation_digest":"sha256:beedf032656681c4d87cc75194478b9fdeb9b8679fe12503151ac5fe745fb4a8","observation_id":"b5f16fd1-37f5-45d7-b92a-57f060fad204","resolution":{"observed_at":"2026-05-15T02:20:44.411719Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-10T22:11:59.976519Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.02629","last_updated":"2025-02-12T04:55:19Z","snapshot_observed_at":"2026-08-10T22:06:02.163331Z","submitted_at":"2025-01-05T19:06:03Z","title":"Layer-Level Self-Exposure and Patch: Affirmative Token Mitigation for Jailbreak Attack Defense","version":2},"reference_index":57,"source":"arxiv_source","source_observed_at":"2026-08-10T22:11:59.976519Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2501.02629"},"observation_digest":"sha256:6a51767aee27fe961dfcaa4f92af7dd65809f1a3dd0d56ac81eba6a658f6b93c","observation_id":"ccd6187b-74d8-4d14-8759-126059ee0d5e","resolution":{"observed_at":"2026-08-10T22:11:59.976519Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":"2402.14857","doi":"10.48550/arxiv.2402.14857","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Is the system message really important to jailbreaks in large language models?","venue":"arXiv (Cornell University)","work_id":"17c11848-8842-4226-843a-072be2b10403","year":2024},"citing_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-05-23T04:39:04.591722Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2502.05206"},"observation_digest":"sha256:09d4133dd0fe8ddf1ed4e3784bbc01e7ea1bd0a50b88efb504f909c129ec69d7","observation_id":"1b9d4862-3607-430b-8c9c-ef8c5ce9d4c1","resolution":{"observed_at":"2026-05-23T04:42:34.075439Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-07T23:56:00.152804Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.08745","last_updated":"2025-03-26T20:35:30Z","snapshot_observed_at":"2026-08-10T21:47:46.935317Z","submitted_at":"2025-02-12T19:35:28Z","title":"IHEval: Evaluating Language Models on Following the Instruction Hierarchy","version":2},"reference_index":43,"source":"arxiv_source","source_observed_at":"2026-08-07T23:56:00.152804Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2502.08745"},"observation_digest":"sha256:26c22b257c269df434254c827ecf93a67f61e9367d1a9bf5ba3a2b603c6da03b","observation_id":"797463d9-e191-4211-92b4-57155cc17e58","resolution":{"observed_at":"2026-08-07T23:56:00.152804Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":"2402.14857","doi":"10.48550/arxiv.2402.14857","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Is the system message really important to jailbreaks in large language models?","venue":"arXiv (Cornell University)","work_id":"17c11848-8842-4226-843a-072be2b10403","year":2024},"citing_paper":{"arxiv_id":"2508.04204","last_updated":"2026-05-06T06:58:09Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-08-06T08:35:10Z","title":"ReasoningGuard: Safeguarding Large Reasoning Models with Inference-time Safety Aha Moments","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-05-19T01:02:07.088724Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2508.04204"},"observation_digest":"sha256:ff35e60e3411b1a3f4178f4f726013d14a67d2719faa1266323513c9728c9aae","observation_id":"d8e6c505-2833-45d9-acd6-d7446422dcb9","resolution":{"observed_at":"2026-05-19T01:02:54.738818Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T18:05:34.591168Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.15182","last_updated":"2025-08-21T02:39:14Z","snapshot_observed_at":"2026-08-08T01:21:32.994965Z","submitted_at":"2025-08-21T02:39:14Z","title":"SafeLLM: Unlearning Harmful Outputs from Large Language Models against Jailbreak Attacks","version":1},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-08-05T18:05:34.591168Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2508.15182"},"observation_digest":"sha256:9ef40f528f7f8cb052efff2de240468eca29bff852e3c74948d3d662b277dc27","observation_id":"632723a9-2fbf-4317-acb1-1f7bd921f3de","resolution":{"observed_at":"2026-08-05T18:05:34.591168Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-04T09:25:58.982902Z","title":"Is the system message really important to jailbreaks in large language models? CoRR, abs/2402.14857, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2510.15476","last_updated":"2026-07-04T04:20:15Z","snapshot_observed_at":"2026-08-06T02:45:04.316908Z","submitted_at":"2025-10-17T09:38:54Z","title":"SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses","version":3},"reference_index":253,"source":"pdf_text","source_observed_at":"2026-08-04T09:25:58.982902Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2510.15476"},"observation_digest":"sha256:0ed0d643a96ed8f5398c1bfedeeb84c1c5dc20f5293e6522cb1841c3277fb106","observation_id":"689d41c0-1712-4555-ba5a-d40afdde75a8","resolution":{"observed_at":"2026-08-04T09:25:58.982902Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":"2402.14857","doi":"10.48550/arxiv.2402.14857","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Is the system message really important to jailbreaks in large language models?","venue":"arXiv (Cornell University)","work_id":"17c11848-8842-4226-843a-072be2b10403","year":2024},"citing_paper":{"arxiv_id":"2606.09125","last_updated":"2026-06-08T07:19:42Z","snapshot_observed_at":"2026-07-06T23:48:30.569726Z","submitted_at":"2026-06-08T07:19:42Z","title":"Unveiling Privacy Risks in Multi-modal Large Language Models: Task-specific Vulnerabilities and Mitigation Challenges","version":1},"reference_index":113,"source":"arxiv_source","source_observed_at":"2026-06-27T16:33:28.848573Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2606.09125"},"observation_digest":"sha256:5ef53be219890168cc093b85743fe673f426ef13531558ddb8e7bfa59f04196f","observation_id":"6bc692c4-c497-4cc8-b3e0-7ddb536d3725","resolution":{"observed_at":"2026-07-03T01:27:31.049513Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?","version":2},"cited_work":{"arxiv_id":"2402.14857","doi":"10.48550/arxiv.2402.14857","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.14857","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Is the system message really important to jailbreaks in large language models?","venue":"arXiv (Cornell University)","work_id":"17c11848-8842-4226-843a-072be2b10403","year":2024},"citing_paper":{"arxiv_id":"2606.30783","last_updated":"2026-06-29T18:11:17Z","snapshot_observed_at":"2026-08-08T22:30:38.879886Z","submitted_at":"2026-06-29T18:11:17Z","title":"Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense","version":1},"reference_index":48,"source":"arxiv_source","source_observed_at":"2026-07-01T01:44:07.700127Z"},"links":{"cited_paper":"/paper/2402.14857","citing_paper":"/paper/2606.30783"},"observation_digest":"sha256:c47009c354076e13a166137f6fa7388be8e5e84b76708b7fc38fe10efa568f89","observation_id":"13ba6441-58a7-4fb4-9338-cde32984988d","resolution":{"observed_at":"2026-07-01T01:45:13.819045Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2402.14857/citation-record","integrity":"/paper/2402.14857/integrity","json":"/paper/2402.14857/citation-record.json","paper":"/paper/2402.14857"},"outbound":[],"paper":{"arxiv_id":"2402.14857","last_updated":"2024-06-18T19:22:19Z","latest_version":2,"primary_category":"cs.CL","snapshot_observed_at":"2026-08-06T10:55:38.873690Z","submitted_at":"2024-02-20T17:39:40Z","title":"Is the System Message Really Important to Jailbreaks in Large Language Models?"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"thesis":"As of 11 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 9 inbound Pith citation observations for arXiv:2402.14857."}