Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-09T18:05:52.411107Z
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 59 of 59 outbound references and 7 inbound Pith citation observations for arXiv:2502.00718.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-09T18:05:52.411107Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-07T15:42:19.934200Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-06-29T05:53:09.562517Z
59 of 59 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 7bf96aeb-feb5-4280-8404-bf68c1088b43 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Flamingo: a Visual Language Model for Few-Shot Learning
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 61bfcb78-ce78-4d9c-b207-5cc8efc7610a · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Multimodal machine learning: A survey and taxonomy
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation dfce9281-ab22-4a5f-99a5-c5af9cb0dc71 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Evasion Attacks against Machine Learning at Test Time, pp.\ 387–402
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 60f5044d-e729-40c0-8ba7-14f32dfddc2a · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models On the Opportunities and Risks of Foundation Models
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f1552174-b227-4c2e-801d-a2784d273df4 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Language Models are Few-Shot Learners
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5c48a6cc-0341-4ca9-922d-1702d9882feb · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Audio Adversarial Examples: Targeted Attacks on Speech-to-Text
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 910dba40-53d9-40fc-8903-a2de0d9c95e2 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Are aligned neural networks adversarially aligned?
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1d140a9d-87a8-4194-9922-066906d2cede · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 21115587-0540-47a4-9271-0a6430d890cd · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models BEATs: Audio Pre-Training with Acoustic Tokenizers
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a6ffa163-7034-41dc-b559-21894303ea0a · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models E., Stoica, I., and Xing, E
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 67f2d290-ed0e-4896-8685-b45fdb997948 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Deep reinforcement learning from human preferences
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f5448147-e2f0-4260-9b1d-48b69411d164 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Qwen-Audio: Advancing Universal Audio Understanding via Unified Large-Scale Audio-Language Models
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation efa689ac-80a8-40e5-ae60-d1c2ecca8920 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Think you have Solved Question Answering? Try ARC, the AI2 Reasoning Challenge
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4dd26791-469c-4111-b9a2-572703678f65 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Pengi: An Audio Language Model for Audio Tasks
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 72a3d137-feea-4b30-a407-aaad073858b8 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models HotFlip: White-Box Adversarial Examples for Text Classification
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cd6077ff-6625-4d13-8c08-909271d57e7b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Physical Adversarial Examples for Object Detectors
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 95a03691-838c-4c02-834c-86d4e303c06b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models JailbreakLens: Visual Analysis of Jailbreak Attacks Against Large Language Models
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4f394338-d719-4066-b742-428d8b994608 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Advddos: Zero-query adversarial attacks against commercial speech recognition systems
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 890b2520-8524-4e34-ba4d-e2bb57660447 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models RealToxicityPrompts: Evaluating Neural Toxic Degeneration in Language Models
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ebf9c0f6-606f-4c82-9dd9-72356bae4ed4 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models and Unitary team
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ba4f1ca4-fe9b-4438-9a3b-60cfda8044a0 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Best-of-N Jailbreaking
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 03886de2-ae14-407e-b3b6-41a4b5dedf0e · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models and Liang, P
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 423c05fd-9c9d-41f1-b64f-be8c355461a8 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models M., Sun, J., and Chattopadhyay, S
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 041840ae-03d4-4b19-8736-402a9fcdfa6e · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Mixtral of Experts
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 541756fa-360c-4b06-95e4-fd95f0abc85b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models AdvWave: Stealthy Adversarial Jailbreak Attack against Large Audio-Language Models
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 18360d4e-6246-40f1-919a-a41bef1a69d7 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Towards Efficient Visual-Language Alignment of the Q-Former for Visual Reasoning Tasks
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 37755914-1b8c-4039-b0ec-023ebaf9f734 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Voice biometrics fusion for enhanced security and speaker recognition: A comprehensive review
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e400b6bb-d269-4a65-91c0-f431c6157c37 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Fooling end-to-end speaker verification with adversarial examples
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 39bb094a-5346-4191-a8a1-d1488391ef6e · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models AmpleGCG-Plus: A Strong Generative Model of Adversarial Suffixes to Jailbreak LLMs with Higher Success Rates in Fewer Attempts
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6bf3f076-3aa4-400d-a15d-5c9e7dafadb9 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Images are Achilles' Heel of Alignment: Exploiting Visual Vulnerabilities for Jailbreaking Multimodal Large Language Models
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4c967946-2540-43cf-81a1-b095aab1dff6 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4b1029c8-0ea8-4c86-9e42-13b5172ea68a · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbreaking Prompt Attack: A Controllable Adversarial Attack against Diffusion Models
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f1ae30b2-45e4-4644-bc47-cf7de33041a1 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models User interaction patterns and breakdowns in conversing with llm-powered voice assistants
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 5712b820-e111-4872-9133-134ee783c7dd · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Rule Based Rewards for Language Model Safety
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c95fb8dc-f89a-4eae-96e7-5afcb3596340 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models GPT-4 Technical Report
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b55288ce-0d88-46ee-a781-ce34e5ed02ee · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Training language models to follow instructions with human feedback
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a053c25f-791b-4e62-bee6-b67f6605fa9b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Red Teaming Language Models with Language Models
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2dddea1c-6896-4130-9a1c-7cb95ca46e5e · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Visual Adversarial Examples Jailbreak Aligned Large Language Models
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 14eb5793-877f-4d05-99f9-9a7cadc400e0 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Robust Speech Recognition via Large-Scale Weak Supervision
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cbc995c3-5481-4a66-aca1-3eb0e873a171 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Universal adversarial attacks on spoken language assessment systems
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ed9b5ece-75b5-4893-9bec-1d2ee61463ed · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Muting whisper: A universal acoustic adversarial attack on speech foundation models
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3d95282a-3d47-4311-a85a-6d319bc863a3 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Artificial Intelligence and the Problem of Control, pp.\ 19--24
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 36d4c59f-dd61-4521-8fdc-2b4ebb0ac5d1 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Failures to Find Transferable Image Jailbreaks Between Vision-Language Models
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1534340e-a0aa-4139-9ec8-3c72299b783b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic Hiding
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 44c2689c-1bcf-45ec-b906-802d18747382 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 536b9f55-816d-4bb6-9080-49c3f46acc1d · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 094fc1c1-70b9-4523-aad5-925d36fe9675 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Voice Jailbreak Attacks Against GPT-4o
Reference 47
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 264d152f-056b-4332-aa16-87d27ed8cc7b · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Intriguing properties of neural networks
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 89928ea5-dc64-4c6f-afd7-993b1a80a66a · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models SALMONN: Towards Generic Hearing Abilities for Large Language Models
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e6d5872-af8b-4fee-801a-888e189b8cc1 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Universal Adversarial Triggers for Attacking and Analyzing NLP
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4e5b1b26-f85f-43b7-b49d-924f9d9b7389 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbroken: How Does LLM Safety Training Fail?
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 92e33961-2677-4e59-a605-8951d690c751 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Finetuned Language Models Are Zero-Shot Learners
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ec77abd3-e734-45ab-ac5a-7233f3539636 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Ethical and social risks of harm from Language Models
Reference 53
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b2451446-b76f-4e00-a7bd-b54022459dc8 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4f8975f0-ebc4-4b2b-a022-bdf6ac592f42 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Audio Is the Achilles' Heel: Red Teaming Audio Large Multimodal Models
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cbd27bd2-1236-41bb-afd4-924eb250e2aa · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbreak Attacks and Defenses Against Large Language Models: A Survey
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 80ed813d-ef3c-4083-beec-a5ac8fd8c19d · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eb2d21fa-7101-47ac-abfc-10b6c850db8f · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5f9352e1-5df3-4545-b8e1-3c6765c05584 · outbound
"I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models write newline
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 640a865f-55a0-4642-866d-4bccf697773a · inbound
Universal Acoustic Adversarial Attacks for Flexible Control of Speech-LLMs "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 10f74bdd-f3ab-462e-abf1-6a4fb7fe297d · inbound
Towards Holistic Evaluation of Large Audio-Language Models: A Comprehensive Survey "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 120fea50-dc99-414f-bb87-b914e55d8ab7 · inbound
Investigating Vulnerabilities and Defenses Against Audio-Visual Attacks: A Comprehensive Survey Emphasizing Multimodal Models "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 67fbab49-7064-461f-b6c2-c2d307b8a427 · inbound
On Optimizing Multimodal Jailbreaks for Spoken Language Models "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1194067e-34cb-480e-85ca-69dfcfece2f2 · inbound
Benign Fine-Tuning Breaks Safety Alignment in Audio LLMs "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8b3a05c7-410e-473e-8f02-9266fb140ce2 · inbound
A Survey of Large Audio Language Models: Generalization, Trustworthiness, and Outlook "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 166
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 088c884f-afdc-4661-b5fa-1aa3c686eb4c · inbound
Audio Jailbreaks in Large Audio-Language Models: Taxonomy, Attack-Defense Analysis, and Cost-Aware Evaluation "I am bad": Interpreting Stealthy, Universal and Robust Audio Jailbreaks in Audio-Language Models
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.