Pith. sign in

Paper Citation Record · LEDGER

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models

As of 11 August 2026, this Paper Citation Record lists 45 of 45 outbound references and 1 inbound Pith citation observation for arXiv:2506.01307.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.01307 v1

Coverage vector

measured 45 of 45 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T11:51:33.211141Z

measured 46 of 46 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-05-10T19:04:46.426969Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-10T23:30:51.277126Z

Reference resolution

45 of 45 outbound references displayed

  • verified exact1
  • verified fuzzy15
  • unresolved29
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 1fb9bb94-5321-44bf-9cbb-be3ed3dcdf9c · outbound

This paper cites GPT-4 Technical Report.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.472465Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.472465Z digest=sha256:0b04e30b605bcf1cb70f7d58d780e3e5ac4eabe1296e6ae3311d595416ef8ca8

Observation e72e39d2-d951-4d67-b0e7-71f5f40a6948 · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Gemini: A Family of Highly Capable Multimodal Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.525374Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.525374Z digest=sha256:e79264f3e7fd0014aa0c4dc6025a07aed3fab8d290156bbe76ee461fd2281d16

Observation ef0946de-ab69-4161-a9d6-0138554acc8e · outbound

This paper cites A Survey on Multimodal Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A Survey on Multimodal Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.594092Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.594092Z digest=sha256:42484c9339de35e493352255b3ea2f81c691e67e31bc197ac7bc52194aa7909b

Observation 82887369-20a4-46cc-866f-d1f7955af88a · outbound

This paper cites Visual instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.654714Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.654714Z digest=sha256:a77f3554875ff993429058aa9df4e80cd57aeb2a1c784882308897cd1689563a

Observation fc6bae13-b3ab-420e-981c-09a913f748a7 · outbound

This paper cites VideoChat: Chat-Centric Video Understanding.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models VideoChat: Chat-Centric Video Understanding

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.708631Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.708631Z digest=sha256:1de46ef5e090994d6b83fb0ee3def9d18de75ca9f2ebe69a8ae5dd74838d66ad

Observation e94737b0-a031-499f-b7a7-4779385e11b0 · outbound

This paper cites Pengi: An audio language model for audio tasks,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pengi: An audio language model for audio tasks,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.759161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.759161Z digest=sha256:6937a083307827bfbc0d39ee15cacb0fbb076f7ad2e27ecca926b225df32a09f

Observation b140f10b-8e32-48a6-b77f-5fb694fbd27c · outbound

This paper cites Llava-med: Training a large language-and-vision assistant for biomedicine in one day,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Llava-med: Training a large language-and-vision assistant for biomedicine in one day,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.538329Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:30.826744Z digest=sha256:f62f89c7a5a63bf1231495b884af0ccabc9267c1759873bf03360590e8323829

Observation d294cd55-61f5-4fe2-b256-a9bc23193f35 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.892052Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.892052Z digest=sha256:23a6ca67482f1524438fc2078537a901161ebedeecdb6c4095793ca56526f027

Observation 85f15e9a-2344-4c10-ad7f-c18cdf49a089 · outbound

This paper cites GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.970995Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.970995Z digest=sha256:bcf72e747b8c30376766c67bf21be026c2b9555f3b6594aca111ae75d55589fe

Observation 44e84603-c99d-4013-b29f-afa15ba7b79e · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.034488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.034488Z digest=sha256:06c97056683de78c570243022bf9cfd65ea03df5da46683c717f70bcb6698db9

Observation 71dff876-f268-4db8-90a7-05b02771e398 · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.427322Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.080590Z digest=sha256:9b2bf7471df9a5a7d2c8fd64ae12e29cfd1ad7c70fc74adaf1f569aaf95e40ff

Observation 9ae543c5-0770-4eb5-b2cb-bf6ea664a28b · outbound

This paper cites Visual instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.127775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.127775Z digest=sha256:3912c4b1531f294b44aecdaef9539087444bef7692a64db0605d1a5086065688

Observation 57ac1d65-0182-4a1d-9dac-fd127fb32722 · outbound

This paper cites Yi: Open foundation models by 01.ai,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Yi: Open foundation models by 01.ai,

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.326526Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.210881Z digest=sha256:1503a2a6c864358829f4344b4e7c344fb4498e73042a885b3b1d703c2989b4ec

Observation fc9a1c67-4e3c-4534-bfaf-65ac5aa04ea5 · outbound

This paper cites MiniGPT-v2: large language model as a unified interface for vision-language multi-task learning.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-v2: large language model as a unified interface for vision-language multi-task learning

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.266316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.266316Z digest=sha256:f8424d1485850b57c5d7bb08c5e8c809f1f050bc9789b61dc0ed7c608a3c007d

Observation 3b4e1997-ed96-4122-a888-6bcd1297b8db · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.323529Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.323529Z digest=sha256:5f7a20db43d74f3880a7920d7e36d835a98303619130301fa43470896335a606

Observation a5a0e50a-313f-495a-8d1e-a3a49a8cab13 · outbound

This paper cites Instructblip: Towards general-purpose vision- language models with instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Instructblip: Towards general-purpose vision- language models with instruction tuning,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.196949Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.355865Z digest=sha256:cd932dbb7fbf089bed30313fbfffc51fa339c8ee8b79156edb0e47dac8918b30

Observation 808cb02a-cd49-405e-999e-1fb1ab3722af · outbound

This paper cites Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.406556Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.406556Z digest=sha256:b06c91e4f2e23573f64ed9d15791cd6ca9ac8d56b82be5968e4be1ba095ff7f3

Observation 14a3b5fe-c5da-424c-bd2e-786547a8abcd · outbound

This paper cites mplug-owl2: Revolutionizing multi-modal large language model with modality collaboration,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models mplug-owl2: Revolutionizing multi-modal large language model with modality collaboration,

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.043145Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.439571Z digest=sha256:bfea94a2dab16de78b148391e77e80707dc8075478d43111c8542d5c5eded8e0

Observation 0ebd9d24-a5ce-477f-ba5d-7558ca94cb4d · outbound

This paper cites MiniCPM-V: A GPT-4V Level MLLM on Your Phone.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniCPM-V: A GPT-4V Level MLLM on Your Phone

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.473616Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.473616Z digest=sha256:c7aaf62c8608718fcdbcb05e65c2ea8a7135d5b69841d8c8378e0a641ceb24e9

Observation 80c65fb0-056e-4ca7-9709-2649b5f5fc6d · outbound

This paper cites CogVLM: Visual Expert for Pretrained Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models CogVLM: Visual Expert for Pretrained Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.525668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.525668Z digest=sha256:fec64e8ca75c447c3110b5e77bc73ff6cc003b0f66d53a19951289f402a9417a

Observation 644770f6-f978-49a1-8c07-841eeb5244af · outbound

This paper cites COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.581115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.581115Z digest=sha256:c88c0607c53a58dbac45d1325a1950b3e4bac5b961e41d89c96df7e7a3f57a5f

Observation 63fcc7da-0de8-450c-9094-c3e55489aac6 · outbound

This paper cites Jailbreaking Attack against Multimodal Large Language Model.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Attack against Multimodal Large Language Model

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.629125Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.629125Z digest=sha256:751f77e846e0bf156cdbbbca3e4e21cfbb8f0f3e494471612f95cb69967479a1

Observation ee961af7-a279-4c2c-9283-c6f26bbd0a01 · outbound

This paper cites Cross-shaped adversarial patch attack,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Cross-shaped adversarial patch attack,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.956625Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.648158Z digest=sha256:4f840541507fdb6e4d494a52a4968584feafd6c971f65abb9552ad0170eb2610

Observation 1a24ef4f-6ac7-454f-90bf-1019ecc4704b · outbound

This paper cites Targeted adversarial attack against deep cross-modal hashing retrieval,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Targeted adversarial attack against deep cross-modal hashing retrieval,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.882627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.697495Z digest=sha256:0c4765710e446d11147f39d6bebc6f6c90622d155a02f9773c2f33caa99fb97e

Observation 53e32251-37cf-495c-971e-3e243982e2dc · outbound

This paper cites Dynamics-aware adversarial attack of adaptive neural networks,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Dynamics-aware adversarial attack of adaptive neural networks,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.777603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.762048Z digest=sha256:7130e84d1ceb8f57050cdc3cd024efb2ef2e28e4d7141300daa20a6c5ead1a01

Observation dbfd7b8c-da2e-4b6e-9dac-2336b4cfa51f · outbound

This paper cites Iterative adversarial attack on image- guided story ending generation,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Iterative adversarial attack on image- guided story ending generation,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.620955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.818425Z digest=sha256:a9544f8374fbed3f160fee242f9152f2bf5304ea1b1bd2116eb573bcdaa2be34

Observation 9e9df887-7064-4106-8bd4-e12dafd4ba22 · outbound

This paper cites Toward robust neural image compression: Adver- sarial attack and model finetuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Toward robust neural image compression: Adver- sarial attack and model finetuning,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.458925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.888309Z digest=sha256:51d898e28d91f765217779152eef59e7e6c08dbf5667fe255c33f3f6baf21d7d

Observation 16740d72-5656-4a95-8111-043ba3356ee1 · outbound

This paper cites Towards adversarial attack on vision- language pre-training models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards adversarial attack on vision- language pre-training models,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.301714Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:31.950339Z digest=sha256:12a662509a8a92d1868e3535c1c1fa4fdbed0400b25645e785c7b73efc6c8e73

Observation a6fead6f-3ab2-4daa-9c6e-e8d303eb6951 · outbound

This paper cites Exploring Transferability of Multimodal Adversarial Samples for Vision-Language Pre-training Models with Contrastive Learning.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Exploring Transferability of Multimodal Adversarial Samples for Vision-Language Pre-training Models with Contrastive Learning

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.003169Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.003169Z digest=sha256:947f32aed0528b1bd46bce974033a2bd02196f23993bdc29f6793bdb3d01465b

Observation 039539f4-a146-4f94-afa1-83b8d23ab22f · outbound

This paper cites Scalable universal adversarial watermark defending against fa- cial forgery,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Scalable universal adversarial watermark defending against fa- cial forgery,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.148747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:32.061863Z digest=sha256:f808b7816ca96ae171921a6ea571d1e37fe105a6a0b8fba96c3e8a9998d0b5f6

Observation c3142e28-7d08-4ff6-8aaf-64c719910493 · outbound

This paper cites An unforgeable publicly verifiable watermark for large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models An unforgeable publicly verifiable watermark for large language models,

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.031982Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:32.132317Z digest=sha256:b93209c532bcfdff916645cc3c49984fd42503f666513d11af1b76922c246265

Observation 1cff7bda-554f-4ec0-8768-57ec9584f7c0 · outbound

This paper cites A novel model watermarking for protecting generative adversarial network,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A novel model watermarking for protecting generative adversarial network,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:33.891576Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:32.221165Z digest=sha256:cbb3dbc7f24f8ec2059020925ced8b469565f555c41431216c49d4e618e5a30a

Observation 02b16ad3-6cfc-4111-8bcc-7a358ee07963 · outbound

This paper cites MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.292682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.292682Z digest=sha256:fa417ff0c89770c135885b998196349f225f83795b63713d7aa632d6e55e09c6

Observation b81d3f36-170a-408b-8194-6c093c191ddd · outbound

This paper cites Visually adversarial attacks and defenses in the physical world: A survey,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visually adversarial attacks and defenses in the physical world: A survey,

Reference 34

Resolution
verified exact
raw_fallback, observed 2026-08-07T11:51:33.486716Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:32.375525Z digest=sha256:12f006dd43e7a91304a5ec2d0ab2c761a440823d382a8a7454300e4d8e6d2647

Observation 215ff0cf-0c24-48e6-ae3d-3b778e38bf4b · outbound

This paper cites How to Bridge the Gap between Modalities: Survey on Multimodal Large Language Model.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models How to Bridge the Gap between Modalities: Survey on Multimodal Large Language Model

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.442812Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.442812Z digest=sha256:35a8749d7b3ae137ebd6955ad35b806f83855cc71246c3e5c9a40311ce5f4871

Observation e1c4d96c-2bd5-4fbe-b6be-214a7bb7eaa5 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.503010Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.503010Z digest=sha256:9a293261c3f07db5ac704a1a2e34dd4a53d53bb264087b7a3e4fcfd7c36d3ec0

Observation e078d193-ea6c-4d38-a95e-710c97cdccab · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.593150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.593150Z digest=sha256:f80e4563c7a26ee5f1857ada11e0d239bc54eb6c99dce86d14025e905a496db6

Observation c386dfdb-b3cc-4bfc-beec-60afe310ec2c · outbound

This paper cites Enhancing the transferability of adversarial attacks through variance tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Enhancing the transferability of adversarial attacks through variance tuning,

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:33.749670Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-08-07T11:51:32.655871Z digest=sha256:5c0072d85298a39612d7de32485898d8c04282184f3b0181ac1db8ecc3659642

Observation 810c9d6f-f753-4bba-a412-6bafc1d7d107 · outbound

This paper cites Pytorch: An imperative style, high-performance deep learning library,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pytorch: An imperative style, high-performance deep learning library,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.738478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.738478Z digest=sha256:c5e13c838f29a61683e0fd5614b9d20518d23f06e9549119aeb63123ba50a9d8

Observation 6b7c214f-b5e7-4092-9def-6fdc3742f280 · outbound

This paper cites Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.812440Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.812440Z digest=sha256:6741c6653df7605bf0ba974b276cac228675d95b53dfe5833c24980c8a08c29a

Observation 22298515-bd24-4400-84c9-790d5dad6e67 · outbound

This paper cites Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.894561Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.894561Z digest=sha256:716dfdd1311f860a1aecc0f24756812571e085ec3fee5dca2d58b70b53069a43

Observation cc92866a-6aa5-44dc-a637-714a814ed871 · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.972848Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.972848Z digest=sha256:27e2dfbf9d0c1f4a534857d0900dc5e1495cb124f87e0731bd122fad90067250

Observation 3bb0ae46-7edd-488f-a05a-11b2cfd86068 · outbound

This paper cites Self-Guard: Empower the LLM to Safeguard Itself.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Self-Guard: Empower the LLM to Safeguard Itself

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.051132Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.051132Z digest=sha256:6d8db7c5071e23ec4c50ab491bc0dd929321ea13c1c1a9f91be38f9643757720

Observation 24f406f7-dac3-4aae-af34-04176296cb90 · outbound

This paper cites Refuse Whenever You Feel Unsafe: Improving Safety in LLMs via Decoupled Refusal Training.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Refuse Whenever You Feel Unsafe: Improving Safety in LLMs via Decoupled Refusal Training

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.126948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.126948Z digest=sha256:ed283cf08d836d5515563c5a2b6ba1729d39512132921f7ac8261f0dad23dbb5

Observation 2033bf75-41f1-4ab5-8e01-a3f3876b678b · outbound

This paper cites Efficient Adversarial Training in LLMs with Continuous Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Efficient Adversarial Training in LLMs with Continuous Attacks

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.211141Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.211141Z digest=sha256:9b172add7b597ed166b04fd09b6accc54d6a26d702cc5818dee49c9f1136c7cb

Pith citing papers

Observation 92a8316e-aa44-4442-94a5-6ce1c411ff39 · inbound

SALLIE: Generation-Free Hidden-State Detection of Jailbreaks and Prompt Injections Across Text and Vision cites this paper.

SALLIE: Generation-Free Hidden-State Detection of Jailbreaks and Prompt Injections Across Text and Vision Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-10T23:30:51.279710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-10T19:04:46.426969Z digest=sha256:09db7f28f0b13a5c5a9fd1a2525be3299a677c93b3a2285aa66905e35a66c786