Pith. sign in

Paper Citation Record · LEDGER

LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 37 inbound Pith citation observations for arXiv:2408.15221.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2408.15221 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 37 of 37 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 37 of 37 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T19:32:24.045500Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T17:30:00.600665Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 00f3009b-b943-4e6c-a81e-c9876dd4efe8 · inbound

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents cites this paper.

AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-14T01:35:51.196729Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-14T01:35:50.992477Z digest=sha256:8910307debd9190aa5ce62503539d4bdf1f21d56115cc922bbe23e64993849e0

Observation c9d9c45c-9194-4078-a496-571e02d37ab6 · inbound

Fast Proxies for LLM Robustness Evaluation cites this paper.

Fast Proxies for LLM Robustness Evaluation LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T19:32:24.045500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T19:32:24.045500Z digest=sha256:caedb8b2f1b95e5ca2b2e4db6d34a07afda21fdaf96f607e6f097ac078544c47

Observation d3962040-2111-4a15-87eb-fd55a83b7fa1 · inbound

MTSA: Multi-turn Safety Alignment for LLMs through Multi-round Red-teaming cites this paper.

MTSA: Multi-turn Safety Alignment for LLMs through Multi-round Red-teaming LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T15:09:58.868771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:09:58.868771Z digest=sha256:2c61d5357a1a831b9db18c0733be6a5b7c2b0ba5e1d84d425ef96967051e8613

Observation 025da3cb-08c6-465b-bc04-ee7fc410a902 · inbound

Reality Check: A New Evaluation Ecosystem Is Necessary to Understand AI's Real World Effects cites this paper.

Reality Check: A New Evaluation Ecosystem Is Necessary to Understand AI's Real World Effects LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-07T14:26:35.050363Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:26:35.050363Z digest=sha256:6ae6a934b1d0a110b88e6241b986e55d0182c6f64df78423daf2ff59841bfa1a

Observation af5baf9c-24f2-4c7e-bfbf-4d60fce44742 · inbound

SafeTy Reasoning Elicitation Alignment for Multi-Turn Dialogues cites this paper.

SafeTy Reasoning Elicitation Alignment for Multi-Turn Dialogues LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T12:04:46.808275Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T12:04:46.808275Z digest=sha256:ee0601922819e7a62a14e839fa66ce279caf5bb879d0d17ca591002f70e16eb5

Observation 0795bf9e-e8f0-4fc9-b33f-0846d3705edb · inbound

Existing Large Language Model Unlearning Evaluations Are Inconclusive cites this paper.

Existing Large Language Model Unlearning Evaluations Are Inconclusive LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T12:05:55.420996Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:05:55.420996Z digest=sha256:b165923193de452fc370088a313c3f19538929f41fe0d0e074a877d0356a3945

Observation ea5b7d3f-4fcd-41a9-bb98-f17d2047398d · inbound

Adversarial Attacks on Robotic Vision Language Action Models cites this paper.

Adversarial Attacks on Robotic Vision Language Action Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-07T11:11:40.490378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:11:40.490378Z digest=sha256:9560946e98ed0bbb635e5866b4571bf5acdb481568c7f9913b96380845f861d0

Observation 423fc428-ce25-4c67-86de-47204dbbddfe · inbound

A Red Teaming Roadmap Towards System-Level Safety cites this paper.

A Red Teaming Roadmap Towards System-Level Safety LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T12:11:20.823652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:11:20.823652Z digest=sha256:1148b65621e6424af4f7b9319c3c363a5e2b3f57a72a214ff34875b63962c59c

Observation d5622b38-d1cb-47b7-9f96-0a23a7be94db · inbound

FORTRESS: Frontier Risk Evaluation for National Security and Public Safety cites this paper.

FORTRESS: Frontier Risk Evaluation for National Security and Public Safety LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T00:15:01.464128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:15:01.464128Z digest=sha256:75c2e9e29b217665b3ee3f3af7802c1f029e983db00afa3762f37060ef8b42fa

Observation c6e2f740-a3b4-4596-b545-b38fd8c10bda · inbound

A Representation Engineering Perspective on the Effectiveness of Multi-Turn Jailbreaks cites this paper.

A Representation Engineering Perspective on the Effectiveness of Multi-Turn Jailbreaks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T21:50:24.381051Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T21:50:24.381051Z digest=sha256:d49b1dd21c3ea39be0fa50a74e5f0aadb4b1a7f82414e2175ea83df352689f73

Observation dc7aef9d-0703-43cf-9d52-107eb2ead49c · inbound

Reliable Weak-to-Strong Monitoring of LLM Agents cites this paper.

Reliable Weak-to-Strong Monitoring of LLM Agents LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-05T15:53:52.389653Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:53:52.389653Z digest=sha256:cdd7b935341a682f43fd73a26675c7b7377949947e9117c735d5344a70cd1f20

Observation 0f2e6602-08ca-43d2-9b71-c8070ef34c97 · inbound

Certifiable Safe RLHF: Semantic Grounding and Fixed Penalty Constraint Optimization for Safer LLM Alignment cites this paper.

Certifiable Safe RLHF: Semantic Grounding and Fixed Penalty Constraint Optimization for Safer LLM Alignment LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-04T12:27:28.687570Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:27:28.687570Z digest=sha256:be1f90391116d8e5b4cb816637a108ab28fbad8709e6382757f2f254424d441a

Observation 309ec9ad-75ad-489f-8785-ee5c42109a05 · inbound

Echoes of Human Malice in Agents: Benchmarking LLMs for Multi-Turn Online Harassment Attacks cites this paper.

Echoes of Human Malice in Agents: Benchmarking LLMs for Multi-Turn Online Harassment Attacks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-04T09:40:45.154452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T09:40:45.154452Z digest=sha256:4e335cde983935f744e0787769cbdaf420a2497158508d492d7a619b46f9be29

Observation 4b3e7a82-fdde-47cc-9155-3044d9651a7f · inbound

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses cites this paper.

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 102

Resolution
unresolved
no resolver link, observed 2026-08-04T09:25:46.079982Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T09:25:46.079982Z digest=sha256:6a95cb1b8d860d4a9427152e32d1ae13e0e523d1cd50af9dfd198e1312b72062

Observation 1a126705-4d3b-41e5-91f1-f56f557d7299 · inbound

ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs cites this paper.

ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 25

Resolution
verified exact
arxiv_id, observed 2026-05-18T01:55:38.102301Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T01:54:22.995178Z digest=sha256:9b631bd42f001d27c627ce2d65e4da148aaa9045f9e1ff4719b8cb95f49fe401

Observation 247a5f25-22ba-4dda-8c19-878517708f42 · inbound

TrajGuard: Streaming Hidden-state Trajectory Detection for Decoding-time Jailbreak Defense cites this paper.

TrajGuard: Streaming Hidden-state Trajectory Detection for Decoding-time Jailbreak Defense LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-11T00:35:50.926434Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-10T18:26:19.922383Z digest=sha256:6373ae5238c52af4760381d4e0b0ac8b5fa541ee6d5f3ddefc1ff61aba5f287f

Observation a0f878cb-8114-447b-940e-cd4f89f64fbb · inbound

Jailbreaking the Matrix: Nullspace Steering for Controlled Model Subversion cites this paper.

Jailbreaking the Matrix: Nullspace Steering for Controlled Model Subversion LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-05-11T10:46:04.298032Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-10T15:19:46.920899Z digest=sha256:cf157b1f1e9c1e29a771bb72d3666c6a143bf35a2d565d3fbe8a089d573e5490

Observation 7536afa1-8f93-42f7-aebb-3233d15663a0 · inbound

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems cites this paper.

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-11T09:16:04.319458Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T16:07:31.602378Z digest=sha256:94a431de37659c1dc1a3da0a02887adce66c758f7ff23dd40151feaa0ba2b34e

Observation b8f758b8-04bd-4c98-b15a-60c8b6524bd3 · inbound

MASCing: Configurable Mixture-of-Experts Behavior via Activation Steering Masks cites this paper.

MASCing: Configurable Mixture-of-Experts Behavior via Activation Steering Masks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-05-12T10:36:30.234082Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-07T05:31:47.682478Z digest=sha256:a4502e3f94fb4b83a76bd615753fdb475b26074b25ae2c10502e632562fd7a40

Observation 564491a8-4c05-4997-9103-3bee6e9e20a3 · inbound

MultiBreak: A Scalable and Diverse Multi-turn Jailbreak Benchmark for Evaluating LLM Safety cites this paper.

MultiBreak: A Scalable and Diverse Multi-turn Jailbreak Benchmark for Evaluating LLM Safety LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T09:31:01.117969Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-10T16:00:32.413225Z digest=sha256:e84e84a2424a0a5c93a9ceaf3539eb678a657ece2ad2e90ee00b93e394c81964

Observation dfc78e53-93fb-41db-bf6c-48a286a0781e · inbound

Evolving and Detecting Multi-Turn Deception using Geometric Signatures cites this paper.

Evolving and Detecting Multi-Turn Deception using Geometric Signatures LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-29T15:23:32.700901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-29T15:17:58.804973Z digest=sha256:60bbd50a090b9f72270e7618f16f17a9528e4f386da9d7629b69be4f0bf58feb

Observation 9946a1cd-f8e2-4ad4-82e5-f7b21607fdff · inbound

Learning from Mistakes: Can LLM Self-Recover after Misalignment? cites this paper.

Learning from Mistakes: Can LLM Self-Recover after Misalignment? LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 28

Resolution
unresolved
no resolver link, observed 2026-07-13T18:51:10.298187Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T18:51:10.298187Z digest=sha256:0e0e4ee76389d9f6c88587bcaf4efae344a9ca35436ecbea5de41d639692adb2

Observation 284104f1-8e15-4221-b954-329445444012 · inbound

SentGuard: Sentence-Level Streaming Guardrails for Large Language Models cites this paper.

SentGuard: Sentence-Level Streaming Guardrails for Large Language Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T22:56:20.699869Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-28T14:51:17.667213Z digest=sha256:e06a5a79807a1f401d2901e17b9a808607d01fceebeed65cb3772286115ee982

Observation 3049dbee-2d34-46df-a22d-a70daf20d4b8 · inbound

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents cites this paper.

Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-02T04:16:36.009627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-28T09:15:57.044886Z digest=sha256:755f868254003c1c6d881c7747546ec22c03f427001638d0c544b12322c66b41

Observation a3a43767-df8f-4547-8278-1b7e140699c0 · inbound

Where Instruction Hierarchy Breaks: Diagnosing and Repairing Failures in Reasoning Language Models cites this paper.

Where Instruction Hierarchy Breaks: Diagnosing and Repairing Failures in Reasoning Language Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-07-02T17:47:18.134705Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T21:51:34.829877Z digest=sha256:b0ca6ebad7ad74ad7c48be731f15539dcb53ee3ea8a98ecdadb63470e024a9e1

Observation 61326c0e-fcbf-4c6e-9818-5e9ed641c4ea · inbound

From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails cites this paper.

From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-07-03T16:58:43.534360Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T04:42:05.886984Z digest=sha256:f165ce0b25af3f3db7b6d145f3e6c937eb615bfc7e69b97770cc10cb2934ccd7

Observation 69b52be5-acb9-44ee-891c-ecefc9fbcba6 · inbound

NRT-Bench: Benchmarking Multi-Turn Red-Teaming of LLM Operator Agents in Safety-Critical Control Rooms cites this paper.

NRT-Bench: Benchmarking Multi-Turn Red-Teaming of LLM Operator Agents in Safety-Critical Control Rooms LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-04T04:09:34.476904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-26T17:13:26.201462Z digest=sha256:45324e6dc8c84d187905408117debbef6290d2b70a6d3c5b0687f552929a1714

Observation 621dde8d-66f7-41e2-8abd-fef7d8c646a7 · inbound

PHANTOM: A Large-Scale Dataset of Multimodal Adversarial Attacks for Vision-Language Models cites this paper.

PHANTOM: A Large-Scale Dataset of Multimodal Adversarial Attacks for Vision-Language Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-04T17:09:59.528094Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-25T23:52:02.327522Z digest=sha256:8f85c0452dd4636ed773a1acaf13bb9076c993d99e945927582c8485bf54f6da

Observation 61d50880-a3b8-44fd-8e0d-baf2b1480e20 · inbound

Do Thinking Tokens Help with Safety? cites this paper.

Do Thinking Tokens Help with Safety? LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 73

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T17:30:00.602650Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-25T23:37:49.412578Z digest=sha256:a793d91ac2de005df51c3eb244460c6b2309d8354157bc4f908067835a40b53a

Observation c78087e5-adb2-4f36-8087-e8dc34bc18db · inbound

Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety cites this paper.

Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-07-03T20:38:54.925819Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-07-03T20:38:16.610310Z digest=sha256:71bc4505897ee33ad94fdf799d144c8de9a81e5f9b3fc9c9b8fd6e1d0d756e91

Observation 368139f9-4c32-473b-8a35-3f186dd78d3a · inbound

AMT-X: Phase-Structured Multi-Turn Red-Teaming with Checklist-Gated Evaluation cites this paper.

AMT-X: Phase-Structured Multi-Turn Red-Teaming with Checklist-Gated Evaluation LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-14T06:40:17.865408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T06:40:17.865408Z digest=sha256:2e2915db67e766cac9edb893f44767449f9ce4a2cfc6508c4104db957ba6ea40

Observation 52be3610-9d22-4093-b472-d455bb546b5d · inbound

Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security cites this paper.

Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 1939

Resolution
unresolved
no resolver link, observed 2026-08-01T16:19:08.626130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T16:19:08.626130Z digest=sha256:9a011a017d7b84d22b0ea52d2b130b4c4cea538276c518ca9762291879aef722

Observation 2b05152e-9391-4fb2-8bf2-2754d6943dd3 · inbound

The safety failures we are not instrumenting: a perspective on hidden safety-critical challenges in modern AI systems cites this paper.

The safety failures we are not instrumenting: a perspective on hidden safety-critical challenges in modern AI systems LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T12:54:34.458741Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T12:54:34.458741Z digest=sha256:b61980a760e023bd9e3349c1c851bee9fd29e41405bf5e79f1d328eaa1879dd7

Observation 517c58ae-e33a-4b57-a802-dda793e6ad6d · inbound

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges cites this paper.

Chain-of-Models: Cross-Model Auditing for Bias-Robust LLM Judges LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-03T00:55:24.309791Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T00:55:24.309791Z digest=sha256:4441a3d3c70c9d2f93245644517af2e90330d93b309cd074fa1b871a65683c99

Observation 0067c403-d465-4008-9400-5843a1aea210 · inbound

Alignment Is Local: A Paired Diagnostic for GUI Agents under User-Side Persuasion cites this paper.

Alignment Is Local: A Paired Diagnostic for GUI Agents under User-Side Persuasion LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T11:50:47.128838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T11:50:47.128838Z digest=sha256:8194edea7d818473aa45f365f4c099da859a4fe1295b23d2a3fea1b7b82797fc

Observation 51f6832f-3f61-4b2a-8830-0224e9affcb8 · inbound

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks cites this paper.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:00.935942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:00.935942Z digest=sha256:5f053eded338bbab6266c20cb0ab6c2acb04a125b4c515c398287d461600ade1

Observation fb46f4d2-7cbb-4a41-ab8f-5d17ec9f892c · inbound

Magnet: Detecting Cross-Session AI Misuse Through Capability Accumulation cites this paper.

Magnet: Detecting Cross-Session AI Misuse Through Capability Accumulation LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-04T05:44:22.263222Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T05:44:22.263222Z digest=sha256:65820630765a962f62f40ff6df5c159196b0d0641450855d28338841f3acf2d6