Pith. sign in

Paper Citation Record · LEDGER

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs

As of 19 August 2026, this Paper Citation Record lists 40 of 40 outbound references and 4 inbound Pith citation observations for arXiv:2502.00735.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.00735 v3

Coverage vector

measured 40 of 40 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-09T17:58:57.529279Z

measured 44 of 44 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T20:41:29.087405Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-06-29T14:43:31.567700Z

Reference resolution

40 of 40 outbound references displayed

  • verified exact0
  • verified fuzzy7
  • unresolved33
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d7d255e1-b7c6-47e3-a5bb-15166cecbbf4 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm- integrated applications with indirect prompt injection,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Not what you’ve signed up for: Compromising real-world llm- integrated applications with indirect prompt injection,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.351897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.351897Z digest=sha256:da1964ebe9014d08181f4aa9b578061db1427f44c8a78d7cb62e1c1255b5c86f

Observation 81e72bce-80c3-4e5e-b9a4-2ab5575078c1 · outbound

This paper cites Jailbroken: How does llm safety training fail?.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbroken: How does llm safety training fail?

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.153622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.357131Z digest=sha256:fe5ea1e8699821a046143ff97db485a49acccdeacba47213161937d2f1bad5fa

Observation 5028a698-6630-4eff-907b-08d67c8a250f · outbound

This paper cites A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.361973Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.361973Z digest=sha256:6a9e14cd01a38f129fc6cd690aef063704734ae7f4901a45e14a220416ff9305

Observation e34b13c3-19a3-4d5e-8853-4d3a75b4b9b5 · outbound

This paper cites Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.366800Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.366800Z digest=sha256:0570e2992b041f1d6257c77cfa80193ceab4e02c24e658acdbaa723ccc2a3d64

Observation bd30f9b1-4dd5-49fc-8345-5bb2b35b6e25 · outbound

This paper cites ”do anything now.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs ”do anything now

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.138745Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.371911Z digest=sha256:1959a2e66d6759100eed7f03c4a84515c9d993bc5ed94bb05612d53cee46fadc

Observation 3a95f555-62dc-410a-a983-8c5710fda03a · outbound

This paper cites Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.376374Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.376374Z digest=sha256:417128d317353e1e10857f5facb1c2446fb7cc7bc307d9f844f69ac638dfa7a0

Observation 80559eed-b0a8-489c-916f-eaaa61c4bd8e · outbound

This paper cites Play Guessing Game with LLM: Indirect Jailbreak Attack with Implicit Clues.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Play Guessing Game with LLM: Indirect Jailbreak Attack with Implicit Clues

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.381697Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.381697Z digest=sha256:f633abda72f2b319522827c716af55c745d9937e3178aab55150b9079bd25083

Observation ad14ebdb-9b0c-4c75-b80e-3e40e95e8143 · outbound

This paper cites JailbreakRadar: Comprehensive Assessment of Jailbreak Attacks Against LLMs.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs JailbreakRadar: Comprehensive Assessment of Jailbreak Attacks Against LLMs

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.386330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.386330Z digest=sha256:1eaf8cb48950bf9799ed69d731c2a24b66a23f1767b407f05e5b29e6011f850c

Observation 3b5c26c1-e98b-4820-b20e-e96b64ed135c · outbound

This paper cites Sandwich attack: Multi-language Mixture Adaptive Attack on LLMs.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Sandwich attack: Multi-language Mixture Adaptive Attack on LLMs

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.390939Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.390939Z digest=sha256:2a893475d96155b9d3bfc4f66407b3d5be65b8cca5361a62269d09401701932a

Observation 16b0e55e-dac4-40c1-a508-0e77e5cc6ccf · outbound

This paper cites Pleak: Prompt leaking attacks against large language model applications,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Pleak: Prompt leaking attacks against large language model applications,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.123827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.395472Z digest=sha256:bd968ef966d7cefbf6bee5fe0dc69d1755d601992ca3d401f84f1156a431b878

Observation 60141f2f-b40d-4b8d-9373-38dc8cc7cae8 · outbound

This paper cites GPT-4o System Card.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs GPT-4o System Card

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.400082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.400082Z digest=sha256:29693910e5a6a0dfb813b05b620e37126ca1859fc6c1665f80288bf59aecb01d

Observation e0a4bf92-6ff3-4bf0-b947-ffce97a94ff2 · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Gemini: A Family of Highly Capable Multimodal Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.404581Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.404581Z digest=sha256:da8f82f70491129136228fa11f75232956f74047f6a91da6fc15aab5686fbec9

Observation cb6336ee-e3cc-4656-a4ba-15764670ad3f · outbound

This paper cites Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.409109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.409109Z digest=sha256:9a4ad499b716eba0e6e9b62ee2a1530f99cf9ea67d82032b67e41fbf6e30f26c

Observation 42aa56a1-c8a2-4a37-a55d-2b4d3eeb9df5 · outbound

This paper cites Voice Jailbreak Attacks Against GPT-4o.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Voice Jailbreak Attacks Against GPT-4o

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.413578Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.413578Z digest=sha256:cfffdeacc8bfe213cd5519382ac9550a1e9f6b3c6f99d4587f30bd740e504a69

Observation a40ae050-683c-4042-a448-752bf6eadd6e · outbound

This paper cites Image-based multimodal models as intruders: Trans- ferable multimodal attacks on video-based mllms,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Image-based multimodal models as intruders: Trans- ferable multimodal attacks on video-based mllms,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.417903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.417903Z digest=sha256:08a451b478594afa3f8c0ae4f1a5dfdc0fcdf50eafa48475fe77cc82e1ae0ad0

Observation 32207719-e170-414d-8744-180edae9a108 · outbound

This paper cites Generative AI vs. LLMs: What’s the Differ- ence? — Kovaion — kovaion.com,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Generative AI vs. LLMs: What’s the Differ- ence? — Kovaion — kovaion.com,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.109061Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.422255Z digest=sha256:ffaf309b987ba9314b77b4d45c7aec606c8b15f849d8aac92745694eac1df61a

Observation 8d5ad40e-a273-4d0f-98e0-d8b7408cadd5 · outbound

This paper cites GPT-4 Technical Report.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs GPT-4 Technical Report

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.426488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.426488Z digest=sha256:f977f30488a89ded8238132e6de96b5e7de9099aebe0435dced5f8c8dd153d19

Observation b81c112f-9f56-464c-9bf7-7916307ecbc1 · outbound

This paper cites Llama 2: Open Foundation and Fine-Tuned Chat Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Llama 2: Open Foundation and Fine-Tuned Chat Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.430720Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.430720Z digest=sha256:4a523fa65bf7b0f60f50e6ea82728d033ddd8d5a7256906379272a418f070f04

Observation f0723876-7a3b-45fd-8026-97652971a4c0 · outbound

This paper cites Generative adversarial user model for reinforcement learning based recommendation system,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Generative adversarial user model for reinforcement learning based recommendation system,

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.094067Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.435644Z digest=sha256:76dbb000085f0c9e140ac038e457cfbd0dd3b917c55965b3d514e6d465a399a8

Observation 88d160dd-3aaf-451e-ba76-d703f97201c7 · outbound

This paper cites LLM Censorship: A Machine Learning Challenge or a Computer Security Problem?.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs LLM Censorship: A Machine Learning Challenge or a Computer Security Problem?

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.440037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.440037Z digest=sha256:b1607f8eefca40e6ee853159f2fefc9e0b62b4bfc875941a6957677572f593d6

Observation 969180b8-45fc-423c-8180-1ad3be0adfdd · outbound

This paper cites Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.444491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.444491Z digest=sha256:f1c6b96b156ef6059264261fb2231374c5b659488c8ae4351e75d17d2c54b3ce

Observation a0be7cd6-8959-4553-94f0-4904e5a278dd · outbound

This paper cites Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.448870Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.448870Z digest=sha256:4e11649901fe00cf4c3b8e42ddcea817ccf3d44d0b2c8e33e97a7cfdb1ea20f3

Observation f965f748-54b7-40cf-97f5-2c22dbb9b1d7 · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.453228Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.453228Z digest=sha256:881c8f18477381dc3c7e10172889e8f318817450858dcbee807a25229079ede1

Observation b28a8d96-22ea-457e-a7e2-cc0939201c00 · outbound

This paper cites Large lan- guage models are zero-shot reasoners,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Large lan- guage models are zero-shot reasoners,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.457904Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.457904Z digest=sha256:28cb841118b9ac22c074d1d937211fadea795828c4a0b9955a0097e883b46abd

Observation 22c49dda-5037-4e92-b97d-ed531ed6639c · outbound

This paper cites Igniting Language Intelligence: The Hitchhiker's Guide From Chain-of-Thought Reasoning to Language Agents.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Igniting Language Intelligence: The Hitchhiker's Guide From Chain-of-Thought Reasoning to Language Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.462329Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.462329Z digest=sha256:5ed3ffb709775620e526b36019dc8b4ecc49509ad7dae3b0566de3da34f8b1a9

Observation 846f67e8-7398-436f-8935-d577077775e1 · outbound

This paper cites On the Tool Manipulation Capability of Open-source Large Language Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs On the Tool Manipulation Capability of Open-source Large Language Models

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.467117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.467117Z digest=sha256:8e2e82c5fe49facfeb6cb5a1b343eacdefb5f7aa3101a4230c6e4e428dc2a724

Observation 1920c3fb-64cd-48e4-be5a-35131b0b3dc2 · outbound

This paper cites On the Impossible Safety of Large AI Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs On the Impossible Safety of Large AI Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.471908Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.471908Z digest=sha256:a1e29f58849e383f5325db29a71620398094ff96d6315042a83d6fa56cb60395

Observation 2483c2d0-831d-4431-9814-9d42bcd3e5df · outbound

This paper cites Explaining and Harnessing Adversarial Examples.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Explaining and Harnessing Adversarial Examples

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.476357Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.476357Z digest=sha256:0c9a4b4fec1a8ca75734497bf3be4efea880edb059ce3c0c9241c87aa21987ef

Observation 3dbc665f-1bdd-4b6d-a046-7d028940df87 · outbound

This paper cites Imagebind: One embedding space to bind them all,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Imagebind: One embedding space to bind them all,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.480925Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.480925Z digest=sha256:a17f5f1f4b9990b5e0dcd63d0cc26e90be4aed631df2229ea7d361458a67cdc6

Observation 9ff88ea8-82ce-4d91-a02c-06b4cd04a62b · outbound

This paper cites Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.485048Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.485048Z digest=sha256:cdb4f9e63530c590943d98c026548543200d3fc839d6c8f58d67976f9c3a9cca

Observation e93518aa-813c-4db9-92cc-b66e848a3b34 · outbound

This paper cites Learning transferable visual models from natural language supervision,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Learning transferable visual models from natural language supervision,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.489558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.489558Z digest=sha256:3c9bfdeac678fc55cdecd4ce7b4f38fb4f0d708000be9ce134a8821a0fb6554d

Observation 529a65a7-b01c-4a52-a470-69a8269c1b7d · outbound

This paper cites LLaVAR: Enhanced Visual Instruction Tuning for Text-Rich Image Understanding.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs LLaVAR: Enhanced Visual Instruction Tuning for Text-Rich Image Understanding

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.493585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.493585Z digest=sha256:e0a5fdffaf819d1d44a8206e19561dbf5dd842006ee4b7f74b21c9b650cfac5b

Observation a95131dd-f77e-4bf6-8de5-0cda8bffb5ae · outbound

This paper cites Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.498068Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.498068Z digest=sha256:4a6bb2b8929a9981f3d468c4e3d62cff63f537d18588f8cfd468852f5a39c9a8

Observation 06db8f48-9059-46fa-bec0-a95bce650ee8 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.502267Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.502267Z digest=sha256:361cf51a2ad31c2307a37ac268594012f3f95afacc033bac7ffa62494df258e1

Observation c0a763fb-3181-4270-9f8a-1c06df9817cc · outbound

This paper cites Gemini policy guidelines,.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Gemini policy guidelines,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.051230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.506767Z digest=sha256:3ef3f484ab35c08c208a0edd66bdbef677c2f8063f1b82899189e47396673c89

Observation 279bba0f-3198-404f-ac63-4918ea8eea9d · outbound

This paper cites A Comprehensive Review of Multimodal Large Language Models: Performance and Challenges Across Different Tasks.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Comprehensive Review of Multimodal Large Language Models: Performance and Challenges Across Different Tasks

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.510956Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.510956Z digest=sha256:c53fbfb20d83b2d63052a25165ab484a07ccca19f982c3ba2edffaaa755827ca

Observation 4adf32af-18be-409b-94e6-c2ae08f883d5 · outbound

This paper cites The Art of Defending: A Systematic Evaluation and Analysis of LLM Defense Strategies on Safety and Over-Defensiveness.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs The Art of Defending: A Systematic Evaluation and Analysis of LLM Defense Strategies on Safety and Over-Defensiveness

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.515461Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.515461Z digest=sha256:47d1c899654e5c0de2cebe19079cdd62fa450f6e8e72d381c00c45cdc2d88f10

Observation b34be785-8b6a-4060-a67a-d0ed689d1ed5 · outbound

This paper cites A Practical Survey on Emerging Threats from AI-driven Voice Attacks: How Vulnerable are Commercial Voice Control Systems?.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Practical Survey on Emerging Threats from AI-driven Voice Attacks: How Vulnerable are Commercial Voice Control Systems?

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.520120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.520120Z digest=sha256:6ca04c1607ff08d38995e10cf09ccf1869d04768b7748a081d3a9485f99b657a

Observation a89f0c1a-ecb1-4615-8f87-640891669099 · outbound

This paper cites An LLM can Fool Itself: A Prompt-Based Adversarial Attack.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs An LLM can Fool Itself: A Prompt-Based Adversarial Attack

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-09T17:58:57.524743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T17:58:57.524743Z digest=sha256:8db9b392e948a7c31227850e6a9c95b7d3447673fed4d6770c86cd8255d9f6e8

Observation b0c04688-8ef9-4044-b58b-ff1ba0b85e46 · outbound

This paper cites 2) Generating content for scams, phishing, or other deceptive activities.

`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs 2) Generating content for scams, phishing, or other deceptive activities

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-09T17:58:58.036654Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-09T17:58:57.529279Z digest=sha256:eef24e1e7122898e5c3fb496fdb8fe1800fab23a63a118e9f3ea43f050762ff2

Pith citing papers

Observation 1711b8f6-bada-4f8d-a3f8-99f901ada3e7 · inbound

The Tower of Babel Revisited: Multilingual Jailbreak Prompts on Closed-Source Large Language Models cites this paper.

The Tower of Babel Revisited: Multilingual Jailbreak Prompts on Closed-Source Large Language Models `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-15T20:41:29.087405Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T20:41:29.087405Z digest=sha256:1714a124780341fc1116d3c680e0d9f601e49c47faa24a84ed5ec813be96bd27

Observation 291eba03-f8ca-4e32-8383-290a1468cd14 · inbound

Watch, Listen, Understand, Mislead: Tri-modal Adversarial Attacks on Short Videos for Content Appropriateness Evaluation cites this paper.

Watch, Listen, Understand, Mislead: Tri-modal Adversarial Attacks on Short Videos for Content Appropriateness Evaluation `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T17:09:20.679512Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:09:20.679512Z digest=sha256:beaac82c2998bbff63797d54dd4207e68e3a8a8ed976787d5f559267b038c2e1

Observation 7bc98f7c-764d-424f-8e98-d2ccf7a45348 · inbound

Acoustic Interference: A New Paradigm Weaponizing Acoustic Latent Semantic for Universal Jailbreak against Large Audio Language Models cites this paper.

Acoustic Interference: A New Paradigm Weaponizing Acoustic Latent Semantic for Universal Jailbreak against Large Audio Language Models `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:53:15.966329Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-05-20T09:48:43.319804Z digest=sha256:5570ed802c166553e70e0c52ae50924277565d084c82e76573e162599100c893

Observation b773166f-a197-4882-8c48-e69f3c4b896c · inbound

When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech cites this paper.

When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-06-29T14:43:31.569181Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-29T06:17:07.660975Z digest=sha256:2ae3cf5bb4c62a77b6d1419ede5807749e3228a2087a530fec88789aed7067c2