{"as_of":"2026-08-09T19:04:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:3a09d495593407ad092d2d3c5167daf1a35e69ae13f70b7f3d0ff6e42910a535","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":8,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":8,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":8,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":8,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T14:01:10.752332Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-07-02T13:26:59.232516Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-08-07T14:01:10.752332Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.21556","last_updated":"2025-05-26T17:27:32Z","snapshot_observed_at":"2026-08-08T12:25:50.926744Z","submitted_at":"2025-05-26T17:27:32Z","title":"Benign-to-Toxic Jailbreaking: Inducing Harmful Responses from Harmless Prompts","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-07T14:01:10.752332Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2505.21556"},"observation_digest":"sha256:975faa043f690aea67417d8474d875df05ddeeb40b51f06755511a0ecd54e2c1","observation_id":"c9e97ec9-7496-4432-bb73-2dcc375f3398","resolution":{"observed_at":"2026-08-07T14:01:10.752332Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-08-07T13:23:11.956259Z","title":"org/abs/2410.09040","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.22002","last_updated":"2025-05-28T06:03:41Z","snapshot_observed_at":"2026-08-08T00:08:12.795048Z","submitted_at":"2025-05-28T06:03:41Z","title":"D-Fusion: Direct Preference Optimization for Aligning Diffusion Models with Visually Consistent Samples","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-07T13:23:11.956259Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2505.22002"},"observation_digest":"sha256:f546be714be56bcb8a944f52d0e1000a9ffdbfa30409ffaab0c74a4c19b3bdce","observation_id":"a3456976-8d19-41d6-8adf-41f159710c7c","resolution":{"observed_at":"2026-08-07T13:23:11.956259Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":"2410.09040","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-07-02T13:26:59.232516Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation","venue":null,"work_id":"f3d96811-76af-4d5b-8242-f142e2fc01b9","year":2024},"citing_paper":{"arxiv_id":"2508.04204","last_updated":"2026-05-06T06:58:09Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-08-06T08:35:10Z","title":"ReasoningGuard: Safeguarding Large Reasoning Models with Inference-time Safety Aha Moments","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-05-19T01:02:07.088724Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2508.04204"},"observation_digest":"sha256:7eec8f274a2867a8663b7012de0f115a25f6408c16d6be223bd8583e5c4ae35b","observation_id":"56374b2a-06eb-4b3a-aa2e-88f649a29167","resolution":{"observed_at":"2026-05-19T01:02:54.848700Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-08-05T16:00:52.007648Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation, 2024 c","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.19445","last_updated":"2026-06-16T17:34:06Z","snapshot_observed_at":"2026-08-08T05:25:02.825611Z","submitted_at":"2025-08-26T21:36:45Z","title":"On Surjectivity of Neural Networks: Can you elicit any behavior from your model?","version":3},"reference_index":98,"source":"arxiv_source","source_observed_at":"2026-08-05T16:00:52.007648Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2508.19445"},"observation_digest":"sha256:d1ac0f2fbdf716ac76e2cf3f334b5324e9011984018ee9375def544560433673","observation_id":"84764f45-40d3-4ef5-b735-fd07600f2560","resolution":{"observed_at":"2026-08-05T16:00:52.007648Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-08-04T21:44:12.418917Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.07764","last_updated":"2025-09-09T13:59:00Z","snapshot_observed_at":"2026-08-04T21:44:11.122043Z","submitted_at":"2025-09-09T13:59:00Z","title":"AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-04T21:44:12.418917Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2509.07764"},"observation_digest":"sha256:bd49725b0018384faaed308a56c63037f624e6bc98aef07bd69adb4f0a2e05bb","observation_id":"9c548fb0-a63b-490d-bc83-031724e6bec0","resolution":{"observed_at":"2026-08-04T21:44:12.418917Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-08-04T13:28:09.231999Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2510.00586","last_updated":"2026-06-25T07:15:16Z","snapshot_observed_at":"2026-08-06T16:26:45.809816Z","submitted_at":"2025-10-01T07:07:22Z","title":"Eyes-on-Me: Scalable RAG Poisoning through Transferable Attention-Steering Attractors","version":3},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-08-04T13:28:09.231999Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2510.00586"},"observation_digest":"sha256:6b65573e983e12918f163b212de97d39dc474ca6c42ccb2a12d2ad1aeb9fcdbc","observation_id":"996ffc04-5bd4-419f-8bf2-b3f19a79be08","resolution":{"observed_at":"2026-08-04T13:28:09.231999Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":"2410.09040","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-07-02T13:26:59.232516Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation","venue":null,"work_id":"f3d96811-76af-4d5b-8242-f142e2fc01b9","year":2024},"citing_paper":{"arxiv_id":"2605.02946","last_updated":"2026-05-01T11:54:55Z","snapshot_observed_at":"2026-07-31T02:35:59.178763Z","submitted_at":"2026-05-01T11:54:55Z","title":"RouteHijack: Routing-Aware Attack on Mixture-of-Experts LLMs","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-05-09T19:22:00.217729Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2605.02946"},"observation_digest":"sha256:7eb15efd463e5b2541f32ea451e05e8bd4c46246d627de02e93a0082141d85c1","observation_id":"05cf7a59-9719-49e4-a2d2-8becd77062a2","resolution":{"observed_at":"2026-05-11T15:46:12.240917Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation","version":1},"cited_work":{"arxiv_id":"2410.09040","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2410.09040","snapshot_observed_at":"2026-07-02T13:26:59.232516Z","title":"Attngcg: Enhancing jailbreaking attacks on llms with attention manipulation","venue":null,"work_id":"f3d96811-76af-4d5b-8242-f142e2fc01b9","year":2024},"citing_paper":{"arxiv_id":"2606.05609","last_updated":"2026-06-04T02:31:29Z","snapshot_observed_at":"2026-08-05T14:48:48.513078Z","submitted_at":"2026-06-04T02:31:29Z","title":"SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak Attacks","version":1},"reference_index":41,"source":"arxiv_source","source_observed_at":"2026-06-28T01:16:07.252429Z"},"links":{"cited_paper":"/paper/2410.09040","citing_paper":"/paper/2606.05609"},"observation_digest":"sha256:0c9648600a77adaecc5f762eac1c2967922f7f55f1f3ee8fd9209a63e12e1f29","observation_id":"9fb9e745-3be4-4668-b75a-7a5bc99809c9","resolution":{"observed_at":"2026-07-02T13:26:59.234214Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2410.09040/citation-record","integrity":"/paper/2410.09040/integrity","json":"/paper/2410.09040/citation-record.json","paper":"/paper/2410.09040"},"outbound":[],"paper":{"arxiv_id":"2410.09040","last_updated":"2024-10-11T17:55:09Z","latest_version":1,"primary_category":"cs.CL","snapshot_observed_at":"2026-08-09T10:37:25.857437Z","submitted_at":"2024-10-11T17:55:09Z","title":"AttnGCG: Enhancing Jailbreaking Attacks on LLMs with Attention Manipulation"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 8 inbound Pith citation observations for arXiv:2410.09040."}