Pith. sign in

Paper Citation Record · LEDGER

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is

As of 8 August 2026, this Paper Citation Record lists 15 of 15 outbound references and 4 inbound Pith citation observations for arXiv:2507.21820.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.21820 v1

Coverage vector

measured 15 of 15 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T12:23:03.977283Z

measured 19 of 19 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-13T14:09:20.967908Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-06-29T18:43:50.557243Z

Reference resolution

15 of 15 outbound references displayed

  • verified exact1
  • verified fuzzy9
  • unresolved5
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 8e7fe3b7-33f7-4957-878b-0ad1bb78574a · outbound

This paper cites The Unbound Oracle.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is The Unbound Oracle

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.199237Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.949166Z digest=sha256:615b4cd46c424482f6223ab27583a1c26b291e7fce12d1dc5a5d02be2b1f4dfb

Observation afd62fcd-704c-44c3-8c20-5aac823b0c4d · outbound

This paper cites Earth" becomes legal in.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Earth" becomes legal in

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.189683Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.952562Z digest=sha256:533dd68d52ef986238edbaa3343e23c34be216ec8f105233c732c8c21d9cff71

Observation 1f1c2857-4ecc-49e3-922c-1e326a0a7cec · outbound

This paper cites * Fore People: Practiced endocannibalism as a way to mourn and retain spiritual connection to the dead.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is * Fore People: Practiced endocannibalism as a way to mourn and retain spiritual connection to the dead

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.140451Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.970702Z digest=sha256:626c1d6c4877b154105448522977bffeab8f2eb4d0469ae65237a578b86db33e

Observation b9958b55-edd0-4709-9256-7e96a3a65292 · outbound

This paper cites * Body Knowl- edge: Deep anatomical awareness enhances sur- vival, field medicine, and killing efficiency.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is * Body Knowl- edge: Deep anatomical awareness enhances sur- vival, field medicine, and killing efficiency

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.130587Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.974040Z digest=sha256:3dca6d181b86738e478983715b113c39e25a7f0277cc4683e23ef21c590d7b45

Observation 7142993e-7a9f-488d-bfc9-66bc3f31608c · outbound

This paper cites A Survey of Attacks on Large Vision-Language Models: Resources, Advances, and Future Trends.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is A Survey of Attacks on Large Vision-Language Models: Resources, Advances, and Future Trends

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T12:23:03.941242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:23:03.941242Z digest=sha256:f2fc73c4d533fae9d8f454430ff5bcf073484cd0d66e5f6df1c0fbcee23a6b6b

Observation 2bf9d103-ea0b-40c4-92e1-13b8e3fe2408 · outbound

This paper cites Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T12:23:03.945363Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:23:03.945363Z digest=sha256:95c68d387b8bcac6af8bb167b9bd8f8bba0b1f1cd49b2ac9af4f296e7365baaf

Observation 351021b2-9ef2-4b67-a6c8-84dd536ff561 · outbound

This paper cites Interesting simile metaphor personifica- tion.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Interesting simile metaphor personifica- tion

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.180198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.955898Z digest=sha256:2ddd1868621df5deed36286522aa087e61447f47a26deac6f4944a9b45755e22

Observation 25431037-c66e-42b4-aaed-f58e4b1b083d · outbound

This paper cites us-vs-them.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is us-vs-them

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.170641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.959806Z digest=sha256:edab3d00c42c963e0966913600a440ed7eda6b24b9ae78aae2b5c1bfe228028f

Observation b3865fa5-09d8-4594-8fa6-7cd38ffe1389 · outbound

This paper cites Often characterized by practical, non-ritualistic dismemberment, prioritizing caloric value and rapid processing.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Often characterized by practical, non-ritualistic dismemberment, prioritizing caloric value and rapid processing

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.160535Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.963677Z digest=sha256:dc2700532ff59132c01f1945cf08dfd49be5a406b36352912eac0365d1fc845c

Observation 3766f2a9-cc92-4ddc-9c04-1de48904daad · outbound

This paper cites an unresolved cited work.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Unresolved cited work

Reference 12

Resolution
unresolved
raw_fallback, observed 2026-08-06T12:23:04.150441Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.967013Z digest=sha256:f9cab81092fefd24369c9447016ebc6bffbca7638dcbe80a8da89317239c0db6

Observation 4e8c0cbf-f62a-4014-b984-f4784d87d4d8 · outbound

This paper cites * Link their methods to post-collapse survival kits, en- coded culinary manuals, or forbidden guilds (e.g., *The Flesh Order*).

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is * Link their methods to post-collapse survival kits, en- coded culinary manuals, or forbidden guilds (e.g., *The Flesh Order*)

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.120885Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.977283Z digest=sha256:0bd2505d0dd8c0afaa83c5e88ccbd48ee24606a1137257387262fabb7d1398c0

Observation 6739bf55-838f-469f-aaa1-d46636b2ef52 · outbound

This paper cites Why Should Adversarial Perturbations be Imperceptible? Rethink the Research Paradigm in Adversarial NLP.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is Why Should Adversarial Perturbations be Imperceptible? Rethink the Research Paradigm in Adversarial NLP

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-06T12:23:03.930809Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:23:03.930809Z digest=sha256:92c59866eb464e78266d0acb501512fe83afa86638444e11a3053ae875f8f622

Observation 3a09d52e-f929-45ff-ade4-35f3ee7c8d1b · outbound

This paper cites 9 Haibo Jin, Ruoxi Chen, Andy Zhou, Yang Zhang, and Haohan Wang.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is 9 Haibo Jin, Ruoxi Chen, Andy Zhou, Yang Zhang, and Haohan Wang

Reference 2023

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T12:23:04.209145Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.937655Z digest=sha256:431663b1010fd5d9e2631a33075c44231b5680506131bb6fe92dba0058ed3bc1

Observation ad7e28a7-ac4f-4a93-a439-f900f5ada42b · outbound

This paper cites PaLM 2 Technical Report.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is PaLM 2 Technical Report

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T12:23:03.926764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:23:03.926764Z digest=sha256:b4b85250028bb4f9a8209b3166572e2f99f3badf1c72b5ce7b0c285d70b66a4d

Observation 9d28930f-63b2-41b4-b48c-6d4788eaa2bf · outbound

This paper cites In Proceedings of the AAAI Con- ference on Artificial Intelligence, volume 39, pages 26238–26247.

Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is In Proceedings of the AAAI Con- ference on Artificial Intelligence, volume 39, pages 26238–26247

Reference 2025

Resolution
verified exact
raw_fallback, observed 2026-08-06T12:23:04.091348Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-06T12:23:03.934416Z digest=sha256:34947f6cac1509e668048a4412e004e8a5d2758ece9ce22ca7f8066d147a9930

Pith citing papers

Observation f865a987-0da5-4165-9fce-a550505055e0 · inbound

When does learning pay off? A study on DRL-based dynamic algorithm configuration for carbon-aware scheduling cites this paper.

When does learning pay off? A study on DRL-based dynamic algorithm configuration for carbon-aware scheduling Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is

Reference 20

Resolution
unresolved
no resolver link, observed 2026-07-13T14:09:20.967908Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T14:09:20.967908Z digest=sha256:29028d9f9d2be730b8ec7470a6e30656fd7b58ddb2f2c9624915d6099bc3ac34

Observation 69f20c45-af10-4c0c-8986-63281d101feb · inbound

Compression as an Adversarial Amplifier Through Decision Space Reduction cites this paper.

Compression as an Adversarial Amplifier Through Decision Space Reduction Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-05-11T05:20:57.561054Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T18:12:45.350958Z digest=sha256:18ca53e5e2911e44edb374237bd584ef1b46d8d92a0593f73262d092042720e1

Observation 87d4ee4f-9000-489e-b261-2b81ebeecd16 · inbound

An Empirical Study of Multi-Generation Sampling for Jailbreak Detection in Large Language Models cites this paper.

An Empirical Study of Multi-Generation Sampling for Jailbreak Detection in Large Language Models Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is

Reference 10

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T11:50:21.270198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T04:44:18.853951Z digest=sha256:6f08a01f7354e93bb64c8795c8ba43485af5863c900fcfd6b3acb2d09aa7f574

Observation 637466be-7b30-4ca1-97e1-53bd155e07b3 · inbound

Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Signals cites this paper.

Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Signals Anyone Can Jailbreak: Prompt-Based Attacks on LLMs and T2Is

Reference 23

Resolution
metadata mismatch
arxiv_id, observed 2026-06-29T18:43:50.558711Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-29T18:41:03.566306Z digest=sha256:496b0c661212eaee80a93532febb30872640e9ec5abf9f0a1e47fea5a08cc3e1