{"as_of":"2026-08-17T16:54:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:6bf2144f1cfd7dee1dc64be94661756d1deb0bfa1abc2de0729aea729e932feb","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":7,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":7,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-17T06:30:58.91139+00:00","state":"measured"},{"denominator":7,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":7,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-16T12:10:31.088250Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-23T04:42:33.844680Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-08-12T15:48:29.699922Z","title":"Enhancing jailbreak attack against large language models through silent tokens","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.14502","last_updated":"2024-11-21T08:20:31Z","snapshot_observed_at":"2026-08-16T05:00:14.504726Z","submitted_at":"2024-11-21T08:20:31Z","title":"Global Challenge for Safe and Secure LLMs Track 1","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T15:48:29.699922Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2411.14502"},"observation_digest":"sha256:dd8ddd6316d99e11a2a16b4700b593d0dcecd7b829e8437f4a28a45928e5161d","observation_id":"78708a62-0cfa-4d54-b0c8-91f6714eae4c","resolution":{"observed_at":"2026-08-12T15:48:29.699922Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-08-11T20:30:10.330931Z","title":"Enhancing jailbreak attack against large language models through silent tokens","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2412.05734","last_updated":"2025-08-08T09:27:21Z","snapshot_observed_at":"2026-08-15T09:43:09.015019Z","submitted_at":"2024-12-07T20:09:01Z","title":"LeakAgent: RL-based Red-teaming Agent for LLM Privacy Leakage","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-11T20:30:10.330931Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2412.05734"},"observation_digest":"sha256:7ee3fb4d77c7cc654513366135fcf4e92fc8ce07f9ff941d3bac75051d1ec776","observation_id":"3704a8bc-9454-447f-929a-3d2959eb0187","resolution":{"observed_at":"2026-08-11T20:30:10.330931Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":"2405.20653","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Enhancing jailbreak attack against large language models through silent tokens","venue":null,"work_id":"c631bee8-b687-4d33-acd2-127688801b28","year":2024},"citing_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-08-15T21:07:34.234107Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"reference_index":87,"source":"pdf_text","source_observed_at":"2026-05-23T04:39:04.591722Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2502.05206"},"observation_digest":"sha256:8d1ea667cc48dd9eab53651d86275b7c9da8841782dc89014c64bcab236261f4","observation_id":"7758fee1-dae0-4588-b025-05dce8dcbdc1","resolution":{"observed_at":"2026-05-23T04:42:33.848607Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-08-16T12:10:31.088250Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2504.13562","last_updated":"2025-04-18T09:02:12Z","snapshot_observed_at":"2026-08-17T15:26:10.256287Z","submitted_at":"2025-04-18T09:02:12Z","title":"DETAM: Defending LLMs Against Jailbreak Attacks via Targeted Attention Modification","version":1},"reference_index":41,"source":"arxiv_source","source_observed_at":"2026-08-16T12:10:31.088250Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2504.13562"},"observation_digest":"sha256:e2a18ef665c9fda71f3725aa1ce287c2998186eb93d45b742a4eb1a6bf2c0808","observation_id":"5fa10b5e-15c8-4546-b981-9aa37f58c252","resolution":{"observed_at":"2026-08-16T12:10:31.088250Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-08-07T15:08:13.604580Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.16241","last_updated":"2025-05-26T02:28:07Z","snapshot_observed_at":"2026-08-14T06:52:38.334219Z","submitted_at":"2025-05-22T05:19:42Z","title":"Three Minds, One Legend: Jailbreak Large Reasoning Model with Adaptive Stacked Ciphers","version":3},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-08-07T15:08:13.604580Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2505.16241"},"observation_digest":"sha256:406910ff7f54836b4553f8d4ce5bd79f5b51114f0564a773956d8fb0349a885d","observation_id":"4f20adc8-4015-4d0d-8edb-b81a6092d858","resolution":{"observed_at":"2026-08-07T15:08:13.604580Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-08-05T20:31:40.072419Z","title":"Enhancing jailbreak attack against large language models through silent tokens","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-15T19:14:10.464568Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:40.072419Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:36f389c396beecbd0e21998b87066487c974e3f83c40767d58386559f89f185c","observation_id":"fa6d8ef1-779b-4e8f-956b-f105db6f570c","resolution":{"observed_at":"2026-08-05T20:31:40.072419Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries","version":3},"cited_work":{"arxiv_id":"2405.20653","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2405.20653","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Enhancing jailbreak attack against large language models through silent tokens","venue":null,"work_id":"c631bee8-b687-4d33-acd2-127688801b28","year":2024},"citing_paper":{"arxiv_id":"2604.20994","last_updated":"2026-04-22T18:32:38Z","snapshot_observed_at":"2026-08-12T23:58:48.774745Z","submitted_at":"2026-04-22T18:32:38Z","title":"Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-05-10T00:02:35.167281Z"},"links":{"cited_paper":"/paper/2405.20653","citing_paper":"/paper/2604.20994"},"observation_digest":"sha256:b3978bda84dbe54215358a27c0ffd951dd810d0047338ed36b007b8a6b4d7cbc","observation_id":"f64c2241-ab4f-42e4-8de0-401a934a4e77","resolution":{"observed_at":"2026-05-10T00:29:47.739027Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2405.20653/citation-record","integrity":"/paper/2405.20653/integrity","json":"/paper/2405.20653/citation-record.json","paper":"/paper/2405.20653"},"outbound":[],"paper":{"arxiv_id":"2405.20653","last_updated":"2025-06-17T03:03:45Z","latest_version":3,"primary_category":"cs.AI","snapshot_observed_at":"2026-08-16T13:47:29.916757Z","submitted_at":"2024-05-31T07:41:03Z","title":"Mind the Inconspicuous: Revealing the Hidden Weakness in Aligned LLMs' Refusal Boundaries"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"thesis":"As of 17 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 7 inbound Pith citation observations for arXiv:2405.20653."}