{"as_of":"2026-08-20T19:06:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:dd8c2a0e19b39f7920bdd27c2d4c8f6772f792422aeacaaa2ca4ffe116ac2285","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":10,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":10,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-20T06:33:59.587034+00:00","state":"measured"},{"denominator":10,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":10,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-16T11:34:05.971739Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-15T02:20:44.746080Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":"2402.18104","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","venue":null,"work_id":"8f3209de-7362-4677-9c71-e35e1dc57cbb","year":2024},"citing_paper":{"arxiv_id":"2407.04295","last_updated":"2024-08-30T11:57:47Z","snapshot_observed_at":"2026-08-12T17:45:10.384900Z","submitted_at":"2024-07-05T06:57:30Z","title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-05-15T02:20:44.368219Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2407.04295"},"observation_digest":"sha256:491172f8138ca47d51ae88446a03080845fd2aa9ccaadc491a6f239bba4abca9","observation_id":"cfa7e491-b079-4fc0-8d3f-dd8f6da43f78","resolution":{"observed_at":"2026-05-15T02:20:44.749063Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-12T20:36:02.100394Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.09523","last_updated":"2024-11-14T15:40:04Z","snapshot_observed_at":"2026-08-17T21:48:32.577209Z","submitted_at":"2024-11-14T15:40:04Z","title":"Navigating the Risks: A Survey of Security, Privacy, and Ethics Threats in LLM-Based Agents","version":1},"reference_index":167,"source":"pdf_text","source_observed_at":"2026-08-12T20:36:02.100394Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2411.09523"},"observation_digest":"sha256:8cf2e90e08dfbc9005a6090753729098d40dcc81829266c850baa887c526a10a","observation_id":"fd54ec90-da97-4263-bbf1-23b7d567b031","resolution":{"observed_at":"2026-08-12T20:36:02.100394Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-11T18:11:05.993725Z","title":"Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.08201","last_updated":"2024-12-11T08:44:15Z","snapshot_observed_at":"2026-08-15T09:51:52.666502Z","submitted_at":"2024-12-11T08:44:15Z","title":"Model-Editing-Based Jailbreak against Safety-aligned Large Language Models","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-11T18:11:05.993725Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2412.08201"},"observation_digest":"sha256:c01324931bf00f6e559bcf8d44bb68e0169e8d92d5bc250c39ba147e1756c0d5","observation_id":"706d9c35-ea39-43a2-b58f-7d8b1680a4c4","resolution":{"observed_at":"2026-08-11T18:11:05.993725Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-09T04:22:00.505854Z","title":"Making Them Ask and Answer : Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction , June 2024 a","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.05223","last_updated":"2025-02-05T21:50:34Z","snapshot_observed_at":"2026-08-18T18:29:30.078158Z","submitted_at":"2025-02-05T21:50:34Z","title":"KDA: A Knowledge-Distilled Attacker for Generating Diverse Prompts to Jailbreak LLMs","version":1},"reference_index":21,"source":"arxiv_source","source_observed_at":"2026-08-09T04:22:00.505854Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2502.05223"},"observation_digest":"sha256:65f99c647b41c449208e6683aeb105c2ee998984ebf2306a7399145ded37fce1","observation_id":"0b1b1209-5caa-4588-a0ba-a542ca732beb","resolution":{"observed_at":"2026-08-09T04:22:00.505854Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-16T11:34:05.971739Z","title":"arXiv preprint arXiv:2402.18104 (2024)","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00010","last_updated":"2025-04-21T16:54:35Z","snapshot_observed_at":"2026-08-18T20:49:22.036588Z","submitted_at":"2025-04-21T16:54:35Z","title":"Jailbreak Detection in Clinical Training LLMs Using Feature-Based Predictive Models","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-16T11:34:05.971739Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2505.00010"},"observation_digest":"sha256:8cd93880a5a541f7c40910260c4aa11a7f33c8b244b0099168c29a98002ff0c2","observation_id":"e20d42c4-07c8-4bfb-9e08-55bd51ca902f","resolution":{"observed_at":"2026-08-16T11:34:05.971739Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-07T00:46:10.197111Z","title":"arXiv preprint arXiv:2402.18104 (2024)","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.12699","last_updated":"2025-06-19T06:30:24Z","snapshot_observed_at":"2026-08-14T17:40:51.768214Z","submitted_at":"2025-06-15T03:14:03Z","title":"SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and Mitigation","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-07T00:46:10.197111Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2506.12699"},"observation_digest":"sha256:0848be723dedb7531e9f07db07feeb5c969d28f5211c99ad819056c93703ecd6","observation_id":"86072d83-b4f7-4e73-ae34-bf490e2b7dc0","resolution":{"observed_at":"2026-08-07T00:46:10.197111Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-06T14:17:34.069998Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.19598","last_updated":"2025-07-25T18:11:10Z","snapshot_observed_at":"2026-08-19T16:15:36.658562Z","submitted_at":"2025-07-25T18:11:10Z","title":"MOCHA: Are Code Language Models Robust Against Multi-Turn Malicious Coding Prompts?","version":1},"reference_index":33,"source":"arxiv_source","source_observed_at":"2026-08-06T14:17:34.069998Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2507.19598"},"observation_digest":"sha256:d1a3ee2550f701ffc59f55eee1e23143aa50dfed40fc522dfc595c64cd477b76","observation_id":"baa84667-355f-4ecc-a18b-25861e850d3b","resolution":{"observed_at":"2026-08-06T14:17:34.069998Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-05T20:31:40.561131Z","title":"Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-18T11:11:26.991132Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:40.561131Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:2616cfdcb952513bb188f2ce79e1c8182d7898722355043117fac2b5b0b8dcb2","observation_id":"14348ef6-23eb-4fc7-95c7-32497fdfcd76","resolution":{"observed_at":"2026-08-05T20:31:40.561131Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-05T05:29:20.697468Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.05471","last_updated":"2025-09-05T19:57:38Z","snapshot_observed_at":"2026-08-18T02:28:08.022702Z","submitted_at":"2025-09-05T19:57:38Z","title":"Behind the Mask: Benchmarking Camouflaged Jailbreaks in Large Language Models","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-05T05:29:20.697468Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2509.05471"},"observation_digest":"sha256:151e0ddfb2dcf4afa3ea07e837040a9a1335b0bf9ee105a14b37d502c83aa9f7","observation_id":"85e85fed-f946-4490-8a21-e8e5b09fb212","resolution":{"observed_at":"2026-08-05T05:29:20.697468Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.18104","snapshot_observed_at":"2026-08-15T16:25:35.786739Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.08000","last_updated":"2025-09-06T16:03:07Z","snapshot_observed_at":"2026-08-19T11:41:25.041979Z","submitted_at":"2025-09-06T16:03:07Z","title":"AntiDote: Bi-level Adversarial Training for Tamper-Resistant LLMs","version":1},"reference_index":98,"source":"arxiv_source","source_observed_at":"2026-08-15T16:25:35.786739Z"},"links":{"cited_paper":"/paper/2402.18104","citing_paper":"/paper/2509.08000"},"observation_digest":"sha256:b5239d803c81d1296c3b20c862d98d9b035d2ad9082ff7f5f3b7ef43eda84297","observation_id":"7d03a866-8998-4115-942f-ca7cbea3c008","resolution":{"observed_at":"2026-08-15T16:25:35.786739Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2402.18104/citation-record","integrity":"/paper/2402.18104/integrity","json":"/paper/2402.18104/citation-record.json","paper":"/paper/2402.18104"},"outbound":[],"paper":{"arxiv_id":"2402.18104","last_updated":"2024-06-10T11:20:43Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-16T18:08:19.232075Z","submitted_at":"2024-02-28T06:50:14Z","title":"Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"thesis":"As of 20 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 10 inbound Pith citation observations for arXiv:2402.18104."}