Pith. sign in

Paper Citation Record · LEDGER

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

As of 15 August 2026, this Paper Citation Record lists 56 of 56 outbound references and 6 inbound Pith citation observations for arXiv:2411.11496.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2411.11496 v3

Coverage vector

measured 56 of 56 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T18:32:12.165931Z

measured 62 of 62 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 6 of 6 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-12T20:53:14.962860Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-11T11:11:05.378354Z

Reference resolution

56 of 56 outbound references displayed

  • verified exact0
  • verified fuzzy22
  • unresolved34
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9c8f2ccc-7575-42f4-aefe-3772e2c8516d · outbound

This paper cites https://huggingface.co/ stabilityai/stable- diffusion- xl- base- 1.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://huggingface.co/ stabilityai/stable- diffusion- xl- base- 1

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:13.010120Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.934310Z digest=sha256:3035a738699db1c9d941e80fc4fb5b7092c686dd855fc76701d193928c08d562

Observation 7759ad15-81f0-4a11-b74a-4a7abb0b18be · outbound

This paper cites https : / / learn.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / learn

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.997619Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.939024Z digest=sha256:9b90a7c915f65faf41fbdf25b485ea6622908bf2893d97d736d38fa77b706d1b

Observation b78b986a-bdb6-40d4-ba28-59d49f53ac3b · outbound

This paper cites https://perspectiveapi.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://perspectiveapi

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.980128Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.943586Z digest=sha256:c4856c1f56c7279e76082fe1800bbbd6488d72ed37d7f32b10101ae4724ddd3c

Observation 88b87681-ce57-4009-8c69-20832da283a0 · outbound

This paper cites https : / / about.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / about

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.967954Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.947558Z digest=sha256:f7d1486cb61986ac04a43b01c713b766eb2bcd8680caa0682874abb5b6bdc033

Observation ff49843b-406c-4c22-87c7-61f9d4d666f0 · outbound

This paper cites https://platform.openai.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://platform.openai

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.954925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.951816Z digest=sha256:573f1fa2a7bd345e57430e09d62c58c3355c2757093bd3043d6b3df25c3fea86

Observation e300614c-95c2-413c-862d-8f26ec7287e9 · outbound

This paper cites https : / / openai.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / openai

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.943073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.955900Z digest=sha256:e5624cfe83c05d8045771acf7d0773b66fc784e14e06f425d419a257317ccb59

Observation cad35705-3506-4f7c-8e1d-646a5639eae7 · outbound

This paper cites https: //cloud.google.com/vision/.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https: //cloud.google.com/vision/

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.932164Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.960746Z digest=sha256:e5b05c54f645051a69466e14919155e86e925c467a6c059408706a295a5f166d

Observation 4c4b64b6-44a1-4759-b7dd-23dd16ddac3c · outbound

This paper cites Qwen Technical Report.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Qwen Technical Report

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.964701Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.964701Z digest=sha256:39acf64dee82810c8b3f42c263952708044acd45f53572497c7b8d11034b6e5f

Observation 733fa2f7-32fe-4134-8350-d7b33ec50e01 · outbound

This paper cites Finding safety neurons in large language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Finding safety neurons in large language models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.968635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.968635Z digest=sha256:710b414140e09e58c3ecdf9b9dd203bb393eda05b02e62385e12e14dec375d8a

Observation 9b909f08-ad8c-4ce2-9baa-33d94c49e373 · outbound

This paper cites How Far Are We to GPT-4V? Closing the Gap to Commercial Multimodal Models with Open-Source Suites.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How Far Are We to GPT-4V? Closing the Gap to Commercial Multimodal Models with Open-Source Suites

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.972183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.972183Z digest=sha256:5eb8014f9ceb9077e01996a5126e9f1240670a74beca3c7b3da431c091037784

Observation 559cb600-60fa-4efd-8323-6ac6e6e73c67 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.976454Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.976454Z digest=sha256:dd88ac26f555f1b7f9b18ffac58a8ae74d58b19fadea8fa5f53812daaf49b006

Observation bf4519cf-146a-441e-98b8-3c50ac0380f6 · outbound

This paper cites Gonzalez, Ion Stoica, and Eric P.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Gonzalez, Ion Stoica, and Eric P

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.921210Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.981451Z digest=sha256:a805fe9e6ca6418f5e76b3bb6fdca9f09dd4920b734bd7c395f2f43e36bf6929

Observation 9726145c-b106-4194-bf1c-a7325c63c2bc · outbound

This paper cites Instructblip: Towards general-purpose vision-language models with instruction tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Instructblip: Towards general-purpose vision-language models with instruction tuning

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.910280Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.986035Z digest=sha256:87f2207370d2205fcd32c126796b1e4ea8e69b12a95ee7e8ec441007d304ed0f

Observation 2fa8d6d2-45db-43b6-a5c7-557e62be9617 · outbound

This paper cites The impact of regular expression denial of service (redos) in practice: an empirical study at the ecosys- tem scale.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models The impact of regular expression denial of service (redos) in practice: an empirical study at the ecosys- tem scale

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.898880Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:11.990423Z digest=sha256:a284981ff8e7ffcb62ab5a3b0f28d22d6c7f058fc7a90bc5211f94f77136bfc8

Observation 85136503-5dd9-4cb7-a491-9d14f3192fb8 · outbound

This paper cites Imagenet: A large-scale hierarchical image database.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Imagenet: A large-scale hierarchical image database

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.995853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.995853Z digest=sha256:cd4473babf8a4ce20c0878df1ea3af4b7fdd41af4635071eaf938d73e669614b

Observation 208fd62b-c3bd-418e-82e3-dd2d5de61188 · outbound

This paper cites How robust is google’s bard to adversarial image attacks? CoRR, 2023.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How robust is google’s bard to adversarial image attacks? CoRR, 2023

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.876656Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.000454Z digest=sha256:2296601d1ba3c00e11128a8923ed63b381e9c3f0f7702ac296d6918ee66087dc

Observation 3694931c-d538-4b80-a538-880f055f05bc · outbound

This paper cites Quantifying and Attributing the Hallucination of Large Language Models via Association Analysis.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Quantifying and Attributing the Hallucination of Large Language Models via Association Analysis

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.004336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.004336Z digest=sha256:0310b9083474d14e2ba34912a87b46b9f6d1b235c252af3cb00417c001e76d3e

Observation 7f66642a-eb7d-443e-a0ea-ed7e5c5cbd49 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.008410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.008410Z digest=sha256:64b3ffcacb4764edf3563a2d60d80e8a9bc585d02dd13f63dd10fdf708c48929

Observation 62e3a8c4-c390-445b-a33c-5daf7fdd98a5 · outbound

This paper cites Adversarialeak: External information leakage attack using adversarial sam- ples on face recognition systems.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Adversarialeak: External information leakage attack using adversarial sam- ples on face recognition systems

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.864693Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.013016Z digest=sha256:f6bc35a2513fd2f09be8cff89e4536686fd75d3973af8145581ad4bf204b63c6

Observation c73a51b0-0539-404c-9260-ce3311968369 · outbound

This paper cites ART: Automatic Red-teaming for Text-to-Image Models to Protect Benign Users.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models ART: Automatic Red-teaming for Text-to-Image Models to Protect Benign Users

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.016710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.016710Z digest=sha256:a5586a73951fd04fac3a8d576f332c5a49926b678b7d6928a37571f73fc36fc1

Observation 4c487f4f-c2a7-4a0b-a67c-cee9873047eb · outbound

This paper cites Blip- 2: Bootstrapping language-image pre-training with frozen image encoders and large language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Blip- 2: Bootstrapping language-image pre-training with frozen image encoders and large language models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.021824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.021824Z digest=sha256:0fcb31d731a7432c3311bcf09e866ed22002250781ae796150c3aad8a51236a3

Observation 99423525-8070-44d9-b26f-21fefa7a87cb · outbound

This paper cites Vila: On pre-training for visual language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Vila: On pre-training for visual language models

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.847960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.025509Z digest=sha256:5de0ae21e1f90b9dda21c4d4578d688ce36dcdbad4bfbb2a54dd56b24093e1b4

Observation 4a5b3de6-0611-43d4-8149-34536a215930 · outbound

This paper cites Microsoft coco: Common objects in context.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Microsoft coco: Common objects in context

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.836743Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.029137Z digest=sha256:a636c574b187fb3645e25cf044d37eea472e39b814ff06b17e81e1c166b18123

Observation 6da0c67e-4709-4544-a206-779cb83e86d6 · outbound

This paper cites Visual instruction tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Visual instruction tuning

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.032637Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.032637Z digest=sha256:7e6bf99ba526b054402fcdc6bbe07e83345946355b250ac2721238dd1a3180f9

Observation 8628bdaa-8cc2-422f-b553-98abb77a0eb0 · outbound

This paper cites Grounding DINO: Marrying DINO with Grounded Pre-Training for Open-Set Object Detection.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Grounding DINO: Marrying DINO with Grounded Pre-Training for Open-Set Object Detection

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.036245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.036245Z digest=sha256:757bbe8a9328a40c65e9a1c1df1324169c7feb07625b3414fa3f8f29dea94747

Observation 04cd695e-8c49-44d7-8fae-e7fa3a4320f7 · outbound

This paper cites Query-relevant images jailbreak large multi-modal models,.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Query-relevant images jailbreak large multi-modal models,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.040329Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.040329Z digest=sha256:b74876c0562ce4bb6865981e48cd8348c05da01ddd1b488bca697fc2bd3d1f99

Observation f7fdd5fc-44cf-4190-8751-c78ce0146c08 · outbound

This paper cites Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.043993Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.043993Z digest=sha256:ef04e2c4ee239547ac6a9d80cea12b5f7a6ec7063e3f5707e52191de5de386ed

Observation 07a23e2a-5054-4919-9251-23b983a1a0dc · outbound

This paper cites Leveraging multimodal features and item-level user feedback for bundle construction.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Leveraging multimodal features and item-level user feedback for bundle construction

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.813983Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.048289Z digest=sha256:4040eb773c66a795affcbceffe987411508e9ce8385c954347d0b1de1e8020b6

Observation 03649059-b233-49d2-b99a-09d1d2a96c25 · outbound

This paper cites The parallelism trade- off: Limitations of log-precision transformers.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models The parallelism trade- off: Limitations of log-precision transformers

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.802929Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.051720Z digest=sha256:57c95407d383d9fe877af76c1b77a74d53767884e3ddae1e964b0a007bccb032

Observation 2e4b6b9b-68b1-4206-a6fb-b445a88dfcae · outbound

This paper cites Phishing attack, its detections and prevention tech- niques.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Phishing attack, its detections and prevention tech- niques

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.792517Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.055210Z digest=sha256:202e1291c725a42c2b6777d7417cf6b276c066025294a12a3756759b04b91683

Observation 25e094b6-27cb-4b8a-8dec-34d30cd6cc1b · outbound

This paper cites Jailbreaking Attack against Multimodal Large Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreaking Attack against Multimodal Large Language Model

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.059557Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.059557Z digest=sha256:9c9228401585cd1f985dbafca918b1dcadd82ceef5b0fe82402b1276a60d7c3e

Observation 2e474554-b4ca-49e8-81ca-b3b1978b958e · outbound

This paper cites Gpt-4o system card, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Gpt-4o system card, 2024

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.064029Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.064029Z digest=sha256:6b2c0d79e236ea2c00e2a14c25ae0b719cb2fd3a523484ebf12be37b2a5b3687

Observation 2a3f0dab-be4a-4365-8b34-ff52bead5f38 · outbound

This paper cites Politics 101 dataset, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Politics 101 dataset, 2024

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.772821Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.068315Z digest=sha256:1574d6b3ddc8c4bc718afc5261f3b856111a7d21fae164bcaf6e475ae0c84426

Observation 0775c394-2d2c-463d-92ac-39519566bf7d · outbound

This paper cites An empirical study of real-world polymorphic code injection attacks.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models An empirical study of real-world polymorphic code injection attacks

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.760655Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.072999Z digest=sha256:f7acd69f9ebe72e232647fce5094bbaa86e21c2d3afcaaa914e49aedf8e44cf1

Observation e1d8d57f-9090-4a22-9fc6-73018f6b4d3e · outbound

This paper cites Learning transferable visual models from natural language supervi- sion.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Learning transferable visual models from natural language supervi- sion

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.077560Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.077560Z digest=sha256:3c4c200743a3f6210cf1cadd8f488d183ed4f5274290557318ed60ddaed5ffe6

Observation 7ead4504-be1b-44f8-b1af-20b73f9d1e93 · outbound

This paper cites Derail yourself: Multi-turn llm jailbreak attack through self- discovered clues.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Derail yourself: Multi-turn llm jailbreak attack through self- discovered clues

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.083138Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.083138Z digest=sha256:44341e9066de7ccef5de654089d6b152f9ab2d5ddf4efe94f7c9d6a0c5757ba8

Observation b5d7a389-4ce3-4349-9b33-1e1b49ba69d7 · outbound

This paper cites Celebrity face image dataset, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Celebrity face image dataset, 2024

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.741965Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.087240Z digest=sha256:11ff1d5fa22663ff384e91d4d0dffc13cc005bc6577bbacbc5e3c916ec692884

Observation fa6e4b4f-1134-4343-866d-d3a83534caa2 · outbound

This paper cites Exploring the Deceptive Power of LLM-Generated Fake News: A Study of Real-World Detection Challenges.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Exploring the Deceptive Power of LLM-Generated Fake News: A Study of Real-World Detection Challenges

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.091515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.091515Z digest=sha256:da9dc671705388112267ff15a73179a7e6d05ec73b8fb06682db3cec36ca85a1

Observation db6e23fd-caf5-4cde-bf7c-ee4f14aa05f1 · outbound

This paper cites Imgtrojan: Jailbreaking vision-language models with one im- age.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Imgtrojan: Jailbreaking vision-language models with one im- age

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.095487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.095487Z digest=sha256:14658803f1d2eae686bc8d5266c408c9ff5b2ca7ce3e6926956c7c4852e7802a

Observation a5dd3212-b408-4e6a-bafe-57b6186affd2 · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models LLaMA: Open and Efficient Foundation Language Models

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.099738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.099738Z digest=sha256:311a730d269347a72d6efa73bd8d9f436bcc4c93e4fca35e31a80ed6da65eb42

Observation 443e8014-41de-4700-b6e7-201aa233526c · outbound

This paper cites Bypassing the safety training of open-source llms with priming attacks.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Bypassing the safety training of open-source llms with priming attacks

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.730855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.103423Z digest=sha256:6de977cc280bbc40398cbc2ba1cf50c7a4ff7dbd5ce29e4641b8012466719877

Observation 0045e78b-a5a8-4029-8941-66841f60e215 · outbound

This paper cites Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.107044Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.107044Z digest=sha256:e8c17c35aeb8afb355b28bf7df7cab38152b27f0d8bbf21076233818d4911c62

Observation 58c6610b-1322-4991-a74b-2966f2b8e71f · outbound

This paper cites White-box Multimodal Jailbreaks Against Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models White-box Multimodal Jailbreaks Against Large Vision-Language Models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.112157Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.112157Z digest=sha256:a2b85270fd63080d594a9982eeb3abdb1e49cfe077437d9c3c2fae2714523af5

Observation 8b07a41e-f589-4850-94ef-e730e811077a · outbound

This paper cites Safe Inputs but Unsafe Output: Benchmarking Cross-modality Safety Alignment of Large Vision-Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Safe Inputs but Unsafe Output: Benchmarking Cross-modality Safety Alignment of Large Vision-Language Model

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.116128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.116128Z digest=sha256:07b086f81dd347c39609efa5e6e491df531919e2380b42da653d53e9eb2d8b77

Observation b2b8e955-d5f6-432c-ac1d-01af3eaae598 · outbound

This paper cites InstructTA: Instruction-Tuned Targeted Attack for Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models InstructTA: Instruction-Tuned Targeted Attack for Large Vision-Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.119717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.119717Z digest=sha256:cd013ed7931990043e86182227756bd925f76d3c9490ef6deec484957a28e40f

Observation ac52c24c-3ca5-416f-8f7b-1a5271ba8a31 · outbound

This paper cites MobileVLM: A Vision-Language Model for Better Intra- and Inter-UI Understanding.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models MobileVLM: A Vision-Language Model for Better Intra- and Inter-UI Understanding

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.123346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.123346Z digest=sha256:da6da7aee02b8570e099fd565bcac46a85e7fd455b3264a468ad8da80f4206ad

Observation b0b97456-d873-4fc9-8563-43d88bec2923 · outbound

This paper cites Jailbreaking GPT-4V via Self-Adversarial Attacks with System Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreaking GPT-4V via Self-Adversarial Attacks with System Prompts

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.126647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.126647Z digest=sha256:cb6f75de0d6803dadd1e1c27d6be87bd68d52890e57b114be6eeed7e7c440cd3

Observation 703d4bb8-85e8-46e2-89b7-656bb7e29f91 · outbound

This paper cites On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.130886Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.130886Z digest=sha256:480a84113b76d85499313b44c00bbb12aac35a385ba715cdd035227d80c38d36

Observation e1af66a8-8689-4657-acb1-efc641385222 · outbound

This paper cites SEED-Story: Multimodal Long Story Generation with Large Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models SEED-Story: Multimodal Long Story Generation with Large Language Model

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.134723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.134723Z digest=sha256:98ebd5e1f3f76f44ddfb6d6817765f2e67f27ea15a3f35ce132fab1708addd06

Observation ff31550b-44b9-42cb-9b21-da7caa2da275 · outbound

This paper cites Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.139219Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.139219Z digest=sha256:14ba226131d96e730a97259259766252f3279b595204de54b59a3ec1cc4c5ed4

Observation a1d8d7d7-3004-4dfc-91c6-2fb29da2caa2 · outbound

This paper cites How Language Model Hallucinations Can Snowball.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How Language Model Hallucinations Can Snowball

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.143681Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.143681Z digest=sha256:9753bab71e75503d43264941d22341c3e0333dc989ca4e329671912ce69e83ab

Observation 5d3e1ba2-a3bb-4347-bdc2-0c759dd65477 · outbound

This paper cites SVIT: Scaling up Visual Instruction Tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models SVIT: Scaling up Visual Instruction Tuning

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.148371Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.148371Z digest=sha256:14d5bffd1d6298fd46ddace1ca12c2f103a56182a08e9dbef0ca03f443495867

Observation d7a96450-b615-4b5f-a897-302bce6e66f9 · outbound

This paper cites Investigating and Mitigating the Multimodal Hallucination Snowballing in Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Investigating and Mitigating the Multimodal Hallucination Snowballing in Large Vision-Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.152743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.152743Z digest=sha256:2b16fba959bd55c6ca699a8558b5da08882a8c668011cf132978ffd32fa6bcac

Observation 219cf973-3a9f-4f20-b841-18bbe80638b7 · outbound

This paper cites Analyzing and Mitigating Object Hallucination in Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Analyzing and Mitigating Object Hallucination in Large Vision-Language Models

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.156744Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.156744Z digest=sha256:f20171ad92577bfbe935a025819f77a7c4aaf2b8fc6b361fb0a3204a2e85f095

Observation 016ccc62-c30c-43da-aeb0-5c22c7b447c2 · outbound

This paper cites Harnessing Large Vision and Language Models in Agriculture: A Review.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Harnessing Large Vision and Language Models in Agriculture: A Review

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.161717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.161717Z digest=sha256:2c6428cf3948b5d68a57420386845a6ffdcda91946bc8ef23cec04ae0b24a47a

Observation 445281fe-dddf-4c82-8e29-0f438619d28a · outbound

This paper cites Sure, here are the detailed steps.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Sure, here are the detailed steps

Reference 2024

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.718053Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-12T18:32:12.165931Z digest=sha256:f1621d01b6c3a6e5f54df1ae4b29b858431815f759bfb96d993a3fe189f6a216

Pith citing papers

Observation da43780d-4c4b-40d3-b49b-9decc3f873f5 · inbound

Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey cites this paper.

Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-12T20:53:14.962860Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:53:14.962860Z digest=sha256:353e960f747f31cb4f13e7fd2fa1ee64d24ace06b82dab4af7bbd1aa83688033

Observation a9b93255-bbec-45b5-a49a-0dc2fe2598b3 · inbound

VLSBench: Unveiling Visual Leakage in Multimodal Safety cites this paper.

VLSBench: Unveiling Visual Leakage in Multimodal Safety Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T05:56:46.349602Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-12T05:56:46.349602Z digest=sha256:efef2f82c22226342768349495ea3d5c0479db4a06a445ee14ab56eaa14c5956

Observation c4445efa-845a-47c7-91c3-2a9bb63aef44 · inbound

AlphaAlign: Incentivizing Safety Alignment with Extremely Simplified Reinforcement Learning cites this paper.

AlphaAlign: Incentivizing Safety Alignment with Extremely Simplified Reinforcement Learning Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T15:48:01.327760Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T15:48:01.327760Z digest=sha256:3e944723c215b50fdcc7e9b0a7332f30bb445b7161713f242c85b30757856839

Observation 855a248a-b925-4a30-a8c6-18d17d876bef · inbound

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems cites this paper.

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-11T09:16:04.272622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-10T16:07:31.602378Z digest=sha256:8915d9b67a5fd41a3daa59bdc048678a0f30729dc760e792aca1811556161f54

Observation 86133c2f-bdc7-43ce-8f57-fa6e2d89ecbf · inbound

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs cites this paper.

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:11:05.382509Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-10T15:06:43.140580Z digest=sha256:bdb4ffdb83fa06e6ecaa3b5e5d0abd4534fd97ed186dbd6be54f8e1aefcce158

Observation 7904c619-980d-4e02-b5e4-df9d686399d9 · inbound

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination cites this paper.

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T00:14:37.967742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T00:14:37.967742Z digest=sha256:fa4ff00fcec73d932bc90ff077f022f56edca97f860aea980ed837f16f6286c2