Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-09T17:58:57.529279Z
Paper Citation Record · LEDGER
As of 19 August 2026, this Paper Citation Record lists 40 of 40 outbound references and 4 inbound Pith citation observations for arXiv:2502.00735.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-09T17:58:57.529279Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-15T20:41:29.087405Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-06-29T14:43:31.567700Z
40 of 40 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation d7d255e1-b7c6-47e3-a5bb-15166cecbbf4 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Not what you’ve signed up for: Compromising real-world llm- integrated applications with indirect prompt injection,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 81e72bce-80c3-4e5e-b9a4-2ab5575078c1 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbroken: How does llm safety training fail?
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 5028a698-6630-4eff-907b-08d67c8a250f · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e34b13c3-19a3-4d5e-8853-4d3a75b4b9b5 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bd30f9b1-4dd5-49fc-8345-5bb2b35b6e25 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs ”do anything now
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 3a95f555-62dc-410a-a983-8c5710fda03a · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 80559eed-b0a8-489c-916f-eaaa61c4bd8e · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Play Guessing Game with LLM: Indirect Jailbreak Attack with Implicit Clues
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ad14ebdb-9b0c-4c75-b80e-3e40e95e8143 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs JailbreakRadar: Comprehensive Assessment of Jailbreak Attacks Against LLMs
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3b5c26c1-e98b-4820-b20e-e96b64ed135c · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Sandwich attack: Multi-language Mixture Adaptive Attack on LLMs
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 16b0e55e-dac4-40c1-a508-0e77e5cc6ccf · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Pleak: Prompt leaking attacks against large language model applications,
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 60141f2f-b40d-4b8d-9373-38dc8cc7cae8 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs GPT-4o System Card
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e0a4bf92-6ff3-4bf0-b947-ffce97a94ff2 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Gemini: A Family of Highly Capable Multimodal Models
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cb6336ee-e3cc-4656-a4ba-15764670ad3f · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 42aa56a1-c8a2-4a37-a55d-2b4d3eeb9df5 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Voice Jailbreak Attacks Against GPT-4o
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a40ae050-683c-4042-a448-752bf6eadd6e · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Image-based multimodal models as intruders: Trans- ferable multimodal attacks on video-based mllms,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 32207719-e170-414d-8744-180edae9a108 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Generative AI vs. LLMs: What’s the Differ- ence? — Kovaion — kovaion.com,
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 8d5ad40e-a273-4d0f-98e0-d8b7408cadd5 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs GPT-4 Technical Report
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b81c112f-9f56-464c-9bf7-7916307ecbc1 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Llama 2: Open Foundation and Fine-Tuned Chat Models
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f0723876-7a3b-45fd-8026-97652971a4c0 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Generative adversarial user model for reinforcement learning based recommendation system,
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 88d160dd-3aaf-451e-ba76-d703f97201c7 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs LLM Censorship: A Machine Learning Challenge or a Computer Security Problem?
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 969180b8-45fc-423c-8180-1ad3be0adfdd · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a0be7cd6-8959-4553-94f0-4904e5a278dd · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f965f748-54b7-40cf-97f5-2c22dbb9b1d7 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b28a8d96-22ea-457e-a7e2-cc0939201c00 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Large lan- guage models are zero-shot reasoners,
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 22c49dda-5037-4e92-b97d-ed531ed6639c · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Igniting Language Intelligence: The Hitchhiker's Guide From Chain-of-Thought Reasoning to Language Agents
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 846f67e8-7398-436f-8935-d577077775e1 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs On the Tool Manipulation Capability of Open-source Large Language Models
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1920c3fb-64cd-48e4-be5a-35131b0b3dc2 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs On the Impossible Safety of Large AI Models
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2483c2d0-831d-4431-9814-9d42bcd3e5df · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Explaining and Harnessing Adversarial Examples
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3dbc665f-1bdd-4b6d-a046-7d028940df87 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Imagebind: One embedding space to bind them all,
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9ff88ea8-82ce-4d91-a02c-06b4cd04a62b · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e93518aa-813c-4db9-92cc-b66e848a3b34 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Learning transferable visual models from natural language supervision,
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 529a65a7-b01c-4a52-a470-69a8269c1b7d · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs LLaVAR: Enhanced Visual Instruction Tuning for Text-Rich Image Understanding
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a95131dd-f77e-4bf6-8de5-0cda8bffb5ae · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 06db8f48-9059-46fa-bec0-a95bce650ee8 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c0a763fb-3181-4270-9f8a-1c06df9817cc · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs Gemini policy guidelines,
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 279bba0f-3198-404f-ac63-4918ea8eea9d · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Comprehensive Review of Multimodal Large Language Models: Performance and Challenges Across Different Tasks
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4adf32af-18be-409b-94e6-c2ae08f883d5 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs The Art of Defending: A Systematic Evaluation and Analysis of LLM Defense Strategies on Safety and Over-Defensiveness
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b34be785-8b6a-4060-a67a-d0ed689d1ed5 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs A Practical Survey on Emerging Threats from AI-driven Voice Attacks: How Vulnerable are Commercial Voice Control Systems?
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a89f0c1a-ecb1-4615-8f87-640891669099 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs An LLM can Fool Itself: A Prompt-Based Adversarial Attack
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0c04688-8ef9-4044-b58b-ff1ba0b85e46 · outbound
`Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs 2) Generating content for scams, phishing, or other deceptive activities
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 1711b8f6-bada-4f8d-a3f8-99f901ada3e7 · inbound
The Tower of Babel Revisited: Multilingual Jailbreak Prompts on Closed-Source Large Language Models `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 291eba03-f8ca-4e32-8383-290a1468cd14 · inbound
Watch, Listen, Understand, Mislead: Tri-modal Adversarial Attacks on Short Videos for Content Appropriateness Evaluation `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7bc98f7c-764d-424f-8e98-d2ccf7a45348 · inbound
Acoustic Interference: A New Paradigm Weaponizing Acoustic Latent Semantic for Universal Jailbreak against Large Audio Language Models `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation b773166f-a197-4882-8c48-e69f3c4b896c · inbound
When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech `Do as I say not as I do': A Semi-Automated Approach for Jailbreak Prompt Attack against Multimodal LLMs
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.