Pith. sign in

Paper Citation Record · LEDGER

Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

As of 10 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 25 inbound Pith citation observations for arXiv:2406.04031.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2406.04031 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 25 of 25 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-09T18:05:52.403894Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

1
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 30864464-a2bb-479a-9f5d-00825b8bef33 · inbound

Visual Adversarial Attack on Vision-Language Models for Autonomous Driving cites this paper.

Visual Adversarial Attack on Vision-Language Models for Autonomous Driving Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 58

Resolution
verified exact
arxiv_id, observed 2026-05-23T16:35:42.163051Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-23T16:35:24.063578Z digest=sha256:05c846bc5053c4a53f89419bb4789195993d3a4b54ee7608a61ad397e4f2b2ce

Observation 80ed813d-ef3c-4083-beec-a5ac8fd8c19d · inbound

"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models cites this paper.

"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-09T18:05:52.403894Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-09T18:05:52.403894Z digest=sha256:c7830a5aa3e9997980e78889efe51c6f5f98aac8e41434ae76de60b052326090

Observation 17617b06-e3ce-4470-8cd3-2e1a01db0ce9 · inbound

A Survey of Safety on Large Vision-Language Models: Attacks, Defenses and Evaluations cites this paper.

A Survey of Safety on Large Vision-Language Models: Attacks, Defenses and Evaluations Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 97

Resolution
unresolved
no resolver link, observed 2026-08-07T19:45:19.363130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T19:45:19.363130Z digest=sha256:6c3c2d8ccaf99ef2109ab704022958b05cf4bde1dc0da2aa4eccb5292177007e

Observation 44fc0931-9434-46b7-8d0d-cdbcfe1a0931 · inbound

Hierarchical Safety Realignment: Lightweight Restoration of Safety in Pruned Large Vision-Language Models cites this paper.

Hierarchical Safety Realignment: Lightweight Restoration of Safety in Pruned Large Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T15:11:05.926019Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:11:05.926019Z digest=sha256:b84f67d2832e8240c19691d63f46c65f3dd8a13f707c2ba256fef887b044d09e

Observation 0c0fbad8-071f-44db-a668-11ea5518a66c · inbound

Three Minds, One Legend: Jailbreak Large Reasoning Model with Adaptive Stacked Ciphers cites this paper.

Three Minds, One Legend: Jailbreak Large Reasoning Model with Adaptive Stacked Ciphers Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T15:08:13.366909Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:08:13.366909Z digest=sha256:00c5ee245bcbbebbc4c3cdf466d87d39c63dd27da10c03dcc1ff723fa63e67da

Observation 8cf43540-c992-4d50-a46c-a9d45d12c8bf · inbound

Breaking the Ceiling: Exploring the Potential of Jailbreak Attacks through Expanding Strategy Space cites this paper.

Breaking the Ceiling: Exploring the Potential of Jailbreak Attacks through Expanding Strategy Space Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T13:36:00.334024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T13:36:00.334024Z digest=sha256:794face8cf8abb27dcff62a79f5428247610d34b3ed4cb8e6ffdd846afe18193

Observation 2506fa70-0265-491c-9720-27f438d9d0da · inbound

Benign-to-Toxic Jailbreaking: Inducing Harmful Responses from Harmless Prompts cites this paper.

Benign-to-Toxic Jailbreaking: Inducing Harmful Responses from Harmless Prompts Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-07T14:01:11.165635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:01:11.165635Z digest=sha256:8379626b192fc2ef7850f6a4cfd471cdcf4f423611242cd78657db8d9203093e

Observation 22298515-bd24-4400-84c9-790d5dad6e67 · inbound

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models cites this paper.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.894561Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.894561Z digest=sha256:f8f8c6b5f40bad059c99e3428dade84714e5587435b1d53bb3d91dfcd1fb17b0

Observation 31c5f5a1-8f32-465e-965f-77fdacbc0fd4 · inbound

PRJ: Perception-Retrieval-Judgement for Generated Images cites this paper.

PRJ: Perception-Retrieval-Judgement for Generated Images Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T11:02:03.532221Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:02:03.532221Z digest=sha256:e9aef4026e376a0f4d9d6d1bf78772d982f34b76e4f9cc5fa9d9d41754030956

Observation 6195d26a-623c-434c-995a-39f5edcafdb9 · inbound

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models cites this paper.

VSF-Med:A Vulnerability Scoring Framework for Medical Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T23:01:04.686795Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:01:04.686795Z digest=sha256:6a3867acb6a58d20abfe2897a0c74ccbb5b7795eadd0106844b0a57947141b19

Observation 667e004a-1aaf-4620-82b6-ff1b3d6d6ffe · inbound

SafeMobile: Chain-level Jailbreak Detection and Automated Evaluation for Multimodal Mobile Agents cites this paper.

SafeMobile: Chain-level Jailbreak Detection and Automated Evaluation for Multimodal Mobile Agents Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T21:11:18.221976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:11:18.221976Z digest=sha256:680ec23c979802e9070982859b4ce53ac5f48623be5cb053882958c4c951f831

Observation 630d645b-ce3a-474b-bc30-f6c34f4e2371 · inbound

PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking cites this paper.

PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-19T03:37:01.063367Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-05-19T03:36:24.013477Z digest=sha256:7850bd625b061d2bc48e6952bb0264d1f7c666fc9921895be79d23d6d32f60af

Observation 1d3abdd7-d341-43bb-b3d4-21e9f885d2f3 · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 115

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:43.597526Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:43.597526Z digest=sha256:cb41d0a7d8acd4dded9baf0fd518036d2c3c38f84de305f8d38c5d582ef825eb

Observation 38b60e6e-d2e0-4de8-8ba2-edb6f8936389 · inbound

Empowering Multimodal LLMs with External Tools: A Comprehensive Survey cites this paper.

Empowering Multimodal LLMs with External Tools: A Comprehensive Survey Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 232

Resolution
unresolved
no resolver link, observed 2026-08-05T20:29:06.610465Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T20:29:06.610465Z digest=sha256:94dda1cf94239fb35119be11aa0d67680116c7851ef33a041ae2592a1373e409

Observation d2d09ee6-0988-4a21-afbd-8110667ce07d · inbound

On Surjectivity of Neural Networks: Can you elicit any behavior from your model? cites this paper.

On Surjectivity of Neural Networks: Can you elicit any behavior from your model? Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 108

Resolution
unresolved
no resolver link, observed 2026-08-05T16:00:52.253832Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T16:00:52.253832Z digest=sha256:e4e6ddcfe46d0a6d0c4631e14cdb4d8795e6567c674dc835c50fed36771312bd

Observation e4b34017-fd2e-46ab-84b7-de38e5014b22 · inbound

Evidence Recomposition and Predictive Context Residualization for Visual Attribution in Multimodal Large Language Models cites this paper.

Evidence Recomposition and Predictive Context Residualization for Visual Attribution in Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-04T14:58:40.894740Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T14:58:40.894740Z digest=sha256:3b0a0a3c1b830f73bdde5bd4740bd14391d1c6094a54f1ff2ed95e43934898ac

Observation 172ab056-f2f2-4ede-aee0-38548d9ae382 · inbound

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses cites this paper.

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 221

Resolution
unresolved
no resolver link, observed 2026-08-04T09:25:58.141356Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T09:25:58.141356Z digest=sha256:ca2330d5dac66cd7035ce639200a77c5fcb72134b2e43eb2c89c98224a9c919c

Observation 7216e311-fdd7-4b39-96ea-783fb2e30473 · inbound

Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation cites this paper.

Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T20:27:03.863353Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T20:27:03.863353Z digest=sha256:16ec676e8a84b6d690aef38d036af6b24ebc760a6584b10d835027a425160f41

Observation caa29f76-9ae6-47f8-b5ef-2113bd0f7225 · inbound

A Patch-based Cross-view Regularized Framework for Backdoor Defense in Multimodal Large Language Models cites this paper.

A Patch-based Cross-view Regularized Framework for Backdoor Defense in Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 7

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T22:05:49.112628Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-10T20:14:02.553313Z digest=sha256:e474c9854e5e016bc0a4f6ee585e6b1088bca4c5b705f949de9e32c6fc1a1dd4

Observation 46391421-e264-4d6e-9dc2-d895c864b488 · inbound

Multimodal Backdoor Attack on VLMs for Autonomous Driving via Graffiti and Cross-Lingual Triggers cites this paper.

Multimodal Backdoor Attack on VLMs for Autonomous Driving via Graffiti and Cross-Lingual Triggers Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 8

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T21:55:49.742793Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-10T20:30:29.032353Z digest=sha256:415894a30c62cd29c7acb59e3deee7706f55952b9730debcb464aece3c1063aa

Observation bf63562f-4f2e-4eda-8cea-7c1cd4710d3b · inbound

LLM-as-Judge Framework for Evaluating Tone-Induced Hallucination in Vision-Language Models cites this paper.

LLM-as-Judge Framework for Evaluating Tone-Induced Hallucination in Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 37

Resolution
verified exact
arxiv_id, observed 2026-05-10T09:38:43.129002Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-10T05:11:01.039309Z digest=sha256:ee44f5f1b438c995fa0ef97958c2e69ad299090cce06e7aff07964002bbee59e

Observation cebbc9fd-bf29-4a68-b47e-4bf63477d9cf · inbound

Laundering AI Authority with Adversarial Examples cites this paper.

Laundering AI Authority with Adversarial Examples Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 69

Resolution
verified exact
arxiv_id, observed 2026-05-11T17:41:07.993730Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-05-08T17:19:38.662062Z digest=sha256:d06de9ad4aeffbc08dcee302b9f1e0cb4b9769a106baa86f1ff3248ecf209349

Observation fc0bf83b-9254-4bf7-bdc2-d4148539f05c · inbound

Localization then Neutralization: Gradient-guided Token Suppression against Visual Prompt Injection Attack cites this paper.

Localization then Neutralization: Gradient-guided Token Suppression against Visual Prompt Injection Attack Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-06-30T12:24:39.793465Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-30T12:19:12.910048Z digest=sha256:2363579b52238717493ad2b7a78044aa96acaf09298d44c86518c5710913a3db

Observation a51ec3bc-a427-4317-886b-1db2d4d5f433 · inbound

Adversarial Diffusion Across Modalities: A Fusion Survey of Attacks, Defenses, and Evaluation for Text, Vision, and Vision-Language Models cites this paper.

Adversarial Diffusion Across Modalities: A Fusion Survey of Attacks, Defenses, and Evaluation for Text, Vision, and Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 77

Resolution
verified exact
arxiv_id, observed 2026-06-26T04:38:59.191152Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=pdf_text observed=2026-06-26T04:35:51.583460Z digest=sha256:088c53674e440c33cd62526c638432c0a83cfc781371e4d1d7744b12cb4913a5

Observation e2c429a6-3c47-4176-8030-153b619f6b56 · inbound

GhostPrompt: Cross-Image Adversarial Prompt for Vision-Language Models cites this paper.

GhostPrompt: Cross-Image Adversarial Prompt for Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-01T12:04:27.555375Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T12:04:27.555375Z digest=sha256:f55b2e8f16bda7a6cb39c1d762d64341d8c251de706d2bf6939efff3515da3b7