Pith. sign in

Paper Citation Record · LEDGER

Multi-step Jailbreaking Privacy Attacks on ChatGPT

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 29 inbound Pith citation observations for arXiv:2304.05197.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2304.05197 v3

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 29 of 29 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-09T05:31:14.325060Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

23
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 204da7a1-74fc-4dbf-8820-6ce367f02093 · inbound

Jailbroken: How Does LLM Safety Training Fail? cites this paper.

Jailbroken: How Does LLM Safety Training Fail? Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-05-14T18:17:42.875300Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-14T18:17:42.752997Z digest=sha256:c584cdaf56ff56577c56bd8cb7fe080432243ea39e41db8896d0c8b1b7b5c7aa

Observation 491ec865-d4aa-4cee-a1d3-67c6f26efb66 · inbound

"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models cites this paper.

"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-17T08:39:28.187529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-17T08:39:28.047394Z digest=sha256:3b7db4dc6b7a70d77e9664aca37c4bf51fb6b2c8a706e3e4ef2010129a490bb0

Observation 22aa7f8a-75c6-4e1c-8bb8-b3e5138b9891 · inbound

Baseline Defenses for Adversarial Attacks Against Aligned Language Models cites this paper.

Baseline Defenses for Adversarial Attacks Against Aligned Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-13T23:24:40.042862Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-13T23:24:39.835347Z digest=sha256:5083ce39343561956e16158a6facf4a1718f379628c52cd4141309c4f3b71abf

Observation 87765850-f45c-4693-8675-f0980c4c5c32 · inbound

GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts cites this paper.

GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-15T06:25:21.059948Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-15T06:25:20.966510Z digest=sha256:121249080a8b85cb868cc5edeba413063f3f80f4edebe13499383219d5811a3c

Observation 0208d8b9-342c-45c0-b777-fadf982d748a · inbound

Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation cites this paper.

Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-16T22:00:51.560693Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-16T22:00:51.487120Z digest=sha256:f9c6e1c878e0b7f036281197a9218b88be31f184be15211573f30a6fabc24561

Observation 26fc97cf-6200-4b3e-b9f1-a3940bb92306 · inbound

TrustLLM: Trustworthiness in Large Language Models cites this paper.

TrustLLM: Trustworthiness in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 277

Resolution
verified exact
arxiv_id, observed 2026-05-18T11:17:08.792092Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T11:17:08.108565Z digest=sha256:ca20953c6668e069c6d870c7cb326d1aaa5972b6cb5b8546d25c58917426ba8c

Observation 2af2417c-cfaa-4663-8bfb-f254c35ef1df · inbound

Jailbreak Attacks and Defenses Against Large Language Models: A Survey cites this paper.

Jailbreak Attacks and Defenses Against Large Language Models: A Survey Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:20:44.714757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-15T02:20:44.368219Z digest=sha256:303751668bac4c934f075b42e975590e0e0c87d75c06486fb2e31d3366068cd3

Observation 2df84383-6af1-4717-a0b3-27be0b89e95e · inbound

Peering Behind the Shield: Guardrail Identification in Large Language Models cites this paper.

Peering Behind the Shield: Guardrail Identification in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-23T03:45:21.377951Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-23T03:45:14.234545Z digest=sha256:a8ea25c2816f5f19ff51be5af986915ed62f64127d000842007c7b871cd7d419

Observation 34cecc57-b2a0-49b9-9b31-80218f7f3585 · inbound

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation cites this paper.

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-09T05:31:14.325060Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T05:31:14.325060Z digest=sha256:aa39b9650a24656db9fdf97e1cff766b46b28d6271d5ddbd11670454c819dca5

Observation 69c29d1a-8897-4304-9e63-78f6bb46e2ba · inbound

KDA: A Knowledge-Distilled Attacker for Generating Diverse Prompts to Jailbreak LLMs cites this paper.

KDA: A Knowledge-Distilled Attacker for Generating Diverse Prompts to Jailbreak LLMs Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-09T04:22:00.471038Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-09T04:22:00.471038Z digest=sha256:d08120413eac8e2127d84d8b9d19a84657bd8ea89cba48c5fb31f21525d1c2fa

Observation f7e18a7c-af09-43e7-a55d-7dc2e77a5963 · inbound

Context Reasoner: Incentivizing Reasoning Capability for Contextualized Privacy and Safety Compliance via Reinforcement Learning cites this paper.

Context Reasoner: Incentivizing Reasoning Capability for Contextualized Privacy and Safety Compliance via Reinforcement Learning Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T15:37:27.312304Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:37:27.312304Z digest=sha256:ae76e82ed66f687f963c8bdb09bcb913aa25b246d1897099d80fdfefae7c75c8

Observation f0a5b696-8e6d-41ff-a1ee-460b73b5c2e8 · inbound

Audio Jailbreak Attacks: Exposing Vulnerabilities in SpeechGPT in a White-Box Framework cites this paper.

Audio Jailbreak Attacks: Exposing Vulnerabilities in SpeechGPT in a White-Box Framework Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T14:27:05.763058Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:27:05.763058Z digest=sha256:60fb28b9b96d51dd6a6ca03cc77ba6e1e049cc24470b5949ac93caf71b370599

Observation 227d56cf-4a72-4ca8-954f-adc32a8a8f80 · inbound

System Prompt Extraction Attacks and Defenses in Large Language Models cites this paper.

System Prompt Extraction Attacks and Defenses in Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T13:28:17.454592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:28:17.454592Z digest=sha256:4e792e91764b3e8f610892360f5cb65b835cd63d4ca89b08c1ac03c56d7fa789

Observation b71f90d3-ed83-411a-953f-8f89b9ec73c1 · inbound

From Hallucinations to Jailbreaks: Rethinking the Vulnerability of Large Foundation Models cites this paper.

From Hallucinations to Jailbreaks: Rethinking the Vulnerability of Large Foundation Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T12:34:34.521629Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:34:34.521629Z digest=sha256:b13d034a1e3af54a823edd1cb8a7454c562cad95406d95dbfea5c372f4eb09c0

Observation 8ee003a4-d249-40a4-8d2b-ffcf7a084972 · inbound

SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and Mitigation cites this paper.

SoK: The Privacy Paradox of Large Language Models: Advancements, Privacy Risks, and Mitigation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T00:46:10.159449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:46:10.159449Z digest=sha256:b0d6c3cf8018490b87ef58849dc61f6cff699ee97d186412407c418a1975685f

Observation 2ec64b4f-08f6-42c6-a595-c514a2f21e81 · inbound

SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models cites this paper.

SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T23:20:53.545039Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:20:53.545039Z digest=sha256:e141a183529767f7dc01e18babeda2e4f83e5c42b6a110162ccdcba7704b1fdd

Observation 40754a9e-14de-4b14-8c84-e60493fb549b · inbound

Context-Aware CodeLLM Eviction for AI-assisted Coding cites this paper.

Context-Aware CodeLLM Eviction for AI-assisted Coding Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-06T23:20:21.849271Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T23:20:21.849271Z digest=sha256:5ad77671aae3fb69e76fe9638bd21fd5a11ef9767381a81ff6f016828d16a550

Observation 56c20140-73a0-4ff4-9ef4-3d80d0683b38 · inbound

PII Jailbreaking in LLMs via Activation Steering Reveals Personal Information Leakage cites this paper.

PII Jailbreaking in LLMs via Activation Steering Reveals Personal Information Leakage Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T20:36:46.757676Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T20:36:46.757676Z digest=sha256:b9b5291a165b219786bed8a071182e6f3403d83667a6acea0213ddaaef21c1d7

Observation 3284897d-dcb6-4f19-94b1-f3889c235309 · inbound

`For Argument's Sake, Show Me How to Harm Myself!': Jailbreaking LLMs in Suicide and Self-Harm Contexts cites this paper.

`For Argument's Sake, Show Me How to Harm Myself!': Jailbreaking LLMs in Suicide and Self-Harm Contexts Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-06T21:05:19.409556Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:05:19.409556Z digest=sha256:a4ee63abbb568ee5cdf4da86b238c5d0ee380b7b331f33de129aae0a2b07a98d

Observation dff63c40-38df-4b90-87f7-1e84646346d8 · inbound

ASSURE: Metamorphic Testing for AI-powered Browser Extensions cites this paper.

ASSURE: Metamorphic Testing for AI-powered Browser Extensions Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T19:43:28.259535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:43:28.259535Z digest=sha256:fc259f99c31b4350e72c21fa402f2a85641471b5ddc4630b1eaaaa9a8f33484d

Observation 71226ad7-b208-4b86-9b7a-fdf73dd78354 · inbound

MOCHA: Are Code Language Models Robust Against Multi-Turn Malicious Coding Prompts? cites this paper.

MOCHA: Are Code Language Models Robust Against Multi-Turn Malicious Coding Prompts? Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-06T14:17:34.033208Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T14:17:34.033208Z digest=sha256:3d3413fc1f353e2425c332005abb3db3460730880d465f06fb99cfcb5d10467d

Observation 5e00bf6b-3ea3-49c7-8290-047fa9be4ff3 · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 125

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:44.379657Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:44.379657Z digest=sha256:dd7d965943cf2257da14a97ce00a97a5f718ad6dd0bc56f9222c57a754c1546e

Observation ef35f386-b49d-4051-89c1-c0d2990413b2 · inbound

GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs cites this paper.

GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 20

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T21:36:52.522996Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T21:34:51.665401Z digest=sha256:e4d4490c7d458c477276af85192b5ae0ff1cac0a1c702997b1295ea2104a3301

Observation 0531ff80-7e34-4b9b-9aa5-b094f3650f56 · inbound

The Resurgence of GCG Adversarial Attacks on Large Language Models cites this paper.

The Resurgence of GCG Adversarial Attacks on Large Language Models Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-05T13:42:42.111230Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T13:42:42.111230Z digest=sha256:df441ad7fac5c068b7d8e4f947771e85f1d4aa152f9013e351cc81dfc46de7ad

Observation 1fc3e1a8-895c-4e0f-8215-22f8b45590cc · inbound

Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain cites this paper.

Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-05T10:44:10.497463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T10:44:10.497463Z digest=sha256:abfae33902d87d52642f460552014b14fe0bcac13792f4ad6b8bb2c2ebbcdb57

Observation eae64ffb-36c8-45b9-9b02-97bbad674b2b · inbound

A First Look at the Security Issues in the Model Context Protocol Ecosystem cites this paper.

A First Look at the Security Issues in the Model Context Protocol Ecosystem Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-18T06:12:26.285817Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T06:10:58.928119Z digest=sha256:bda5880d805fa8948deaa39c62c37c90748d6ae74a13b9ec15c253d57186b8dc

Observation a8cd7965-2239-46e6-80de-95c139b66f82 · inbound

Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks cites this paper.

Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 55

Resolution
verified exact
arxiv_id, observed 2026-05-21T12:10:06.533915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-21T12:09:55.500940Z digest=sha256:3b0b347c1a48a9503dfb780a75a18506664f26c9e485c0c4afb790155ddfc90f

Observation 9704c824-fe30-4529-a2bf-ebd943e2ca1c · inbound

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense cites this paper.

Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 108

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T12:45:44.876166Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-07-01T01:44:07.700127Z digest=sha256:8595e8d4ce29d6dcf264079e0299fb86c8c5b438d3ea46eb21ab74eab75d68de

Observation cea1207f-3ba8-4970-8da3-33735677e940 · inbound

Probing Memorization of Tabular In-Context Learning cites this paper.

Probing Memorization of Tabular In-Context Learning Multi-step Jailbreaking Privacy Attacks on ChatGPT

Reference 46

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T09:25:40.859090Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-07-01T06:37:44.328625Z digest=sha256:7c222d6699864162f290073a0e0e5a261eddd95c87a01054eebd627df9e1a1ac