{"as_of":"2026-08-16T21:27:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:d0cb4fd8e23758c9a8d728a68814dea97355cf4b9c690ae3fa42058891339b70","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":16,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":16,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-16T06:30:59.297886+00:00","state":"measured"},{"denominator":16,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":16,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T20:41:29.390915Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":9,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-12T12:56:34.444010Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.16642","last_updated":"2024-11-25T18:23:58Z","snapshot_observed_at":"2026-08-16T04:31:15.591318Z","submitted_at":"2024-11-25T18:23:58Z","title":"Preventing Jailbreak Prompts as Malicious Tools for Cybercriminals: A Cyber Defense Perspective","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-08-12T12:56:34.444010Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2411.16642"},"observation_digest":"sha256:24cc0b711123fc35779ecb0c4adeeccfd9f7a953d99cec31dc19248f03e0a845","observation_id":"c3b568ca-b80e-445a-a1d4-714cfde7fb99","resolution":{"observed_at":"2026-08-12T12:56:34.444010Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-11T18:18:55.164615Z","title":"Don't listen to me: Understanding and exploring jailbreak prompts of large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.08099","last_updated":"2025-03-12T21:35:52Z","snapshot_observed_at":"2026-08-15T15:28:56.958291Z","submitted_at":"2024-12-11T04:53:15Z","title":"Adversarial Vulnerabilities in Large Language Models for Time Series Forecasting","version":4},"reference_index":39,"source":"arxiv_source","source_observed_at":"2026-08-11T18:18:55.164615Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2412.08099"},"observation_digest":"sha256:e4d6bd9e251e4c5ef3b45560bec7b5666681be5b200ecc20d097440ca73d5334","observation_id":"030cfff3-074c-4bab-a16d-1ef9d471dd33","resolution":{"observed_at":"2026-08-11T18:18:55.164615Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-11T10:32:28.420193Z","title":"Don’t listen to me: Understanding and exploring jailbreak prompts of large language models.arXiv preprint arXiv:2403.17336, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.16555","last_updated":"2025-05-29T14:05:50Z","snapshot_observed_at":"2026-08-14T17:42:53.132697Z","submitted_at":"2024-12-21T09:43:51Z","title":"Divide and Conquer: A Hybrid Strategy Defeats Multimodal Large Language Models","version":3},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-11T10:32:28.420193Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2412.16555"},"observation_digest":"sha256:5300ba58a7b349fff2588eb0643bace981d8eea2d7b03127f6efcea9676e43f6","observation_id":"059ddbfa-d110-4a22-be44-c8fe724cc05b","resolution":{"observed_at":"2026-08-11T10:32:28.420193Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-10T20:18:54.641017Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.08814","last_updated":"2025-03-28T04:46:04Z","snapshot_observed_at":"2026-08-15T16:38:24.724832Z","submitted_at":"2025-01-15T14:12:38Z","title":"SAIF: A Comprehensive Framework for Evaluating the Risks of Generative AI in the Public Sector","version":2},"reference_index":44,"source":"arxiv_source","source_observed_at":"2026-08-10T20:18:54.641017Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2501.08814"},"observation_digest":"sha256:841cea34c4a9129c46825918e652a570dfe92937781095fa963951244393ec82","observation_id":"10dacf47-59a6-453e-929f-9e242db97b28","resolution":{"observed_at":"2026-08-10T20:18:54.641017Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-09T18:31:14.095655Z","title":"Don’t listen to me: Understanding and exploring jailbreak prompts of large language models.arXiv preprint arXiv:2403.17336, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.00580","last_updated":"2025-02-01T22:26:30Z","snapshot_observed_at":"2026-08-11T14:52:49.480062Z","submitted_at":"2025-02-01T22:26:30Z","title":"Defense Against the Dark Prompts: Mitigating Best-of-N Jailbreaking with Prompt Evaluation","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-09T18:31:14.095655Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2502.00580"},"observation_digest":"sha256:29a87ee5be69855cca6348e11bbad26e0811feb7da890df92d7da63be2ed7019","observation_id":"52f07ae2-6466-4927-92f7-1b219248bd14","resolution":{"observed_at":"2026-08-09T18:31:14.095655Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-09T17:58:57.376374Z","title":"Don’t listen to me: Understanding and exploring jailbreak prompts of large language models,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.00735","last_updated":"2025-05-18T07:29:41Z","snapshot_observed_at":"2026-08-14T05:16:58.161080Z","submitted_at":"2025-02-02T10:05:08Z","title":"`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs","version":3},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-09T17:58:57.376374Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2502.00735"},"observation_digest":"sha256:d5fd95d3f98d34bc9e53711652d96650c98b4c425b38a6b20b4fee4576df31ae","observation_id":"3a95f555-62dc-410a-a983-8c5710fda03a","resolution":{"observed_at":"2026-08-09T17:58:57.376374Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-15T20:41:29.390915Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.12287","last_updated":"2025-05-18T07:51:19Z","snapshot_observed_at":"2026-08-16T15:35:30.606101Z","submitted_at":"2025-05-18T07:51:19Z","title":"The Tower of Babel Revisited: Multilingual Jailbreak Prompts on Closed-Source Large Language Models","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-15T20:41:29.390915Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2505.12287"},"observation_digest":"sha256:d9723afd942de30d33e90f5592d87d530d603a066a44efe5006e6d8c1add9e7c","observation_id":"4cb2e071-80e6-4698-a207-d308253a6951","resolution":{"observed_at":"2026-08-15T20:41:29.390915Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-07T15:41:13.951926Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.14316","last_updated":"2025-05-20T13:03:15Z","snapshot_observed_at":"2026-08-15T09:51:49.089726Z","submitted_at":"2025-05-20T13:03:15Z","title":"Exploring Jailbreak Attacks on LLMs through Intent Concealment and Diversion","version":1},"reference_index":38,"source":"arxiv_source","source_observed_at":"2026-08-07T15:41:13.951926Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2505.14316"},"observation_digest":"sha256:b37c4b080e317d03a1a8becd37639fca1f4b6197a3e91c5769575f66701e1121","observation_id":"dd31bf90-2ece-4b14-b6bb-cf33b411627b","resolution":{"observed_at":"2026-08-07T15:41:13.951926Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-07T10:54:53.691095Z","title":"Don’t listen to me: Understanding and exploring jailbreak prompts of large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.04036","last_updated":"2025-06-04T14:58:29Z","snapshot_observed_at":"2026-08-16T00:45:40.240361Z","submitted_at":"2025-06-04T14:58:29Z","title":"Privacy and Security Threat for OpenAI GPTs","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T10:54:53.691095Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2506.04036"},"observation_digest":"sha256:8b26090eb02a8e3a2fe1ee678fbd9629716220f2e405751ed6dc7a79146f3436","observation_id":"1d91adde-3ac8-4cea-9a5b-0dd0e7258cba","resolution":{"observed_at":"2026-08-07T10:54:53.691095Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-06T21:34:39.370338Z","title":"Don’t listen to me: Understanding and exploring jailbreak prompts of large language models,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.23930","last_updated":"2025-06-30T14:59:25Z","snapshot_observed_at":"2026-08-16T09:01:03.392163Z","submitted_at":"2025-06-30T14:59:25Z","title":"Leveraging the Potential of Prompt Engineering for Hate Speech Detection in Low-Resource Languages","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-06T21:34:39.370338Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2506.23930"},"observation_digest":"sha256:dcb35d03b257bcd9b50ae45d98c442dbb1269d6b77cbd7b5fffeb4a02e95d462","observation_id":"b14625b6-8bce-4ea8-a972-2cfa29434d39","resolution":{"observed_at":"2026-08-06T21:34:39.370338Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-06T20:03:52.621598Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.05288","last_updated":"2025-07-05T09:52:21Z","snapshot_observed_at":"2026-08-16T15:53:12.498101Z","submitted_at":"2025-07-05T09:52:21Z","title":"A Survey on Proactive Defense Strategies Against Misinformation in Large Language Models","version":1},"reference_index":69,"source":"arxiv_source","source_observed_at":"2026-08-06T20:03:52.621598Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2507.05288"},"observation_digest":"sha256:781b4a845e7c60784f9fdf411894c9ac65bb99efab3dea7918036c9a5bf0c35a","observation_id":"f9221f2d-a6ed-466d-b91c-99086eca6f70","resolution":{"observed_at":"2026-08-06T20:03:52.621598Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-15T16:25:35.760832Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.08000","last_updated":"2025-09-06T16:03:07Z","snapshot_observed_at":"2026-08-16T18:08:21.756485Z","submitted_at":"2025-09-06T16:03:07Z","title":"AntiDote: Bi-level Adversarial Training for Tamper-Resistant LLMs","version":1},"reference_index":92,"source":"arxiv_source","source_observed_at":"2026-08-15T16:25:35.760832Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2509.08000"},"observation_digest":"sha256:92fb1322e023b9373855b46137a90e8a627c1ae19cfcd34b690d2cbbaf7b4d45","observation_id":"c7c025be-ad8a-434b-ab31-d3acc0e091cb","resolution":{"observed_at":"2026-08-15T16:25:35.760832Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":"2403.17336","doi":"10.48550/arxiv.2403.17336","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ArXiv abs/2403.17336(2024)","venue":"arXiv (Cornell University)","work_id":"75a2e458-803b-4d83-9e5e-2fad5ddeca4a","year":2024},"citing_paper":{"arxiv_id":"2604.07727","last_updated":"2026-04-09T02:22:44Z","snapshot_observed_at":"2026-08-11T01:30:41.906955Z","submitted_at":"2026-04-09T02:22:44Z","title":"TrajGuard: Streaming Hidden-state Trajectory Detection for Decoding-time Jailbreak Defense","version":1},"reference_index":43,"source":"arxiv_source","source_observed_at":"2026-05-10T18:26:19.922383Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2604.07727"},"observation_digest":"sha256:570139d584c425fcc30f7cf04a78c3bd5f581fbfe4e60b152014f90edba56f70","observation_id":"45c8d090-ad95-4678-bd09-ac656e721543","resolution":{"observed_at":"2026-05-11T00:35:50.870841Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":"2403.17336","doi":"10.48550/arxiv.2403.17336","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ArXiv abs/2403.17336(2024)","venue":"arXiv (Cornell University)","work_id":"75a2e458-803b-4d83-9e5e-2fad5ddeca4a","year":2024},"citing_paper":{"arxiv_id":"2604.28053","last_updated":"2026-04-30T16:00:52Z","snapshot_observed_at":"2026-08-11T15:41:37.646967Z","submitted_at":"2026-04-30T16:00:52Z","title":"To Build or Not to Build? Factors that Lead to Non-Development or Abandonment of AI Systems","version":1},"reference_index":176,"source":"pdf_text","source_observed_at":"2026-05-07T06:44:14.093749Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2604.28053"},"observation_digest":"sha256:9392d8e1fa8d2d3aebbcdc77c9ac9239378e8d0b24c62c2211ba300ddfd0fb6f","observation_id":"7bdcea2c-a1c3-4427-b6cb-6721a40118b2","resolution":{"observed_at":"2026-05-09T04:55:11.193993Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":"2403.17336","doi":"10.48550/arxiv.2403.17336","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ArXiv abs/2403.17336(2024)","venue":"arXiv (Cornell University)","work_id":"75a2e458-803b-4d83-9e5e-2fad5ddeca4a","year":2024},"citing_paper":{"arxiv_id":"2605.11229","last_updated":"2026-05-11T20:45:31Z","snapshot_observed_at":"2026-08-12T22:54:04.141487Z","submitted_at":"2026-05-11T20:45:31Z","title":"Comment and Control: Hijacking Agentic Workflows via Context-Grounded Evolution","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-05-13T01:54:22.921939Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2605.11229"},"observation_digest":"sha256:67fe64e13f2887288f99240da10b5d96ae575432b642b2c806f633c76a08be70","observation_id":"c26050cc-5ab3-446a-a03b-201ce0e19e9b","resolution":{"observed_at":"2026-05-13T01:57:05.432158Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.17336","snapshot_observed_at":"2026-08-01T15:40:11.063678Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.18232","last_updated":"2026-07-22T15:51:58Z","snapshot_observed_at":"2026-08-12T11:45:41.211466Z","submitted_at":"2026-07-20T17:58:31Z","title":"It's Not What You Say, It's How You Say It: Evaluating LLM Responses to Expressions of Belief","version":2},"reference_index":44,"source":"arxiv_source","source_observed_at":"2026-08-01T15:40:11.063678Z"},"links":{"cited_paper":"/paper/2403.17336","citing_paper":"/paper/2607.18232"},"observation_digest":"sha256:f1fd818f12276f2d69d53ef41348094f502685633218e0e7b9c5d2ff838a86a4","observation_id":"a20747fc-6c91-48a5-b3a1-1c2eff8f816e","resolution":{"observed_at":"2026-08-01T15:40:11.063678Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2403.17336/citation-record","integrity":"/paper/2403.17336/integrity","json":"/paper/2403.17336/citation-record.json","paper":"/paper/2403.17336"},"outbound":[],"paper":{"arxiv_id":"2403.17336","last_updated":"2024-09-30T21:25:23Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-16T14:06:26.505656Z","submitted_at":"2024-03-26T02:47:42Z","title":"Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"thesis":"As of 16 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 16 inbound Pith citation observations for arXiv:2403.17336."}