{"as_of":"2026-08-09T11:58:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:d3de4bd27bbdc00f1a32e4484bff179330cb686aa5a63eb78aa986a3aef76439","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":12,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":12,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":12,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":12,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-09T00:50:00.297603Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-25T05:03:46.896233Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":"2305.14710","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","venue":null,"work_id":"625cb425-a6f2-43e2-acb0-51c4a5293c68","year":2023},"citing_paper":{"arxiv_id":"2306.12001","last_updated":"2023-10-09T22:57:01Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-06-21T03:35:06Z","title":"An Overview of Catastrophic AI Risks","version":6},"reference_index":138,"source":"pdf_text","source_observed_at":"2026-05-25T05:03:46.615765Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2306.12001"},"observation_digest":"sha256:039c5755142eb688fa6c31e708a345a49fa88c0fb2ee93f0920a3e27c64d1e94","observation_id":"7f1301a2-6812-45ed-b504-e340d7607c51","resolution":{"observed_at":"2026-05-25T05:03:46.899976Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":"2305.14710","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","venue":null,"work_id":"625cb425-a6f2-43e2-acb0-51c4a5293c68","year":2023},"citing_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"reference_index":33,"source":"arxiv_source","source_observed_at":"2026-05-12T13:36:57.011451Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2410.02644"},"observation_digest":"sha256:6414ac8d3b6c682551db1436b7bd8549bcc06706ae03cb67dfe7674bf9ed5a4e","observation_id":"6d0f3c18-b513-4fd4-a1fc-3e7ad22a1cb5","resolution":{"observed_at":"2026-05-12T13:36:57.087415Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-09T00:50:00.297603Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.05224","last_updated":"2025-02-06T04:43:05Z","snapshot_observed_at":"2026-08-09T05:58:57.244749Z","submitted_at":"2025-02-06T04:43:05Z","title":"A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations","version":1},"reference_index":85,"source":"pdf_text","source_observed_at":"2026-08-09T00:50:00.297603Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2502.05224"},"observation_digest":"sha256:1d62d6c2b2a2bf82570abb2640f51dce79b86e52f5dced1f5db1101c60f50619","observation_id":"b2409fb2-aebe-4140-90dd-9b3b51ea3946","resolution":{"observed_at":"2026-08-09T00:50:00.297603Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-08T17:16:49.780363Z","title":"Alexander Wei, Nika Haghtalab, and Jacob Steinhardt","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2502.10438","last_updated":"2025-02-09T17:03:23Z","snapshot_observed_at":"2026-08-08T17:10:48.174230Z","submitted_at":"2025-02-09T17:03:23Z","title":"Injecting Universal Jailbreak Backdoors into LLMs in Minutes","version":1},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-08T17:16:49.780363Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2502.10438"},"observation_digest":"sha256:53836cb1ff563d6aeabf02cbe077ea011e8a14859db2cce5fb6670ed7470067e","observation_id":"a2e710c9-79cd-4b5e-91cb-48c06504e091","resolution":{"observed_at":"2026-08-08T17:16:49.780363Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-07T19:45:19.784747Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2502.14881","last_updated":"2025-02-14T08:42:43Z","snapshot_observed_at":"2026-08-07T22:02:21.919237Z","submitted_at":"2025-02-14T08:42:43Z","title":"A Survey of Safety on Large Vision-Language Models: Attacks, Defenses and Evaluations","version":1},"reference_index":124,"source":"pdf_text","source_observed_at":"2026-08-07T19:45:19.784747Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2502.14881"},"observation_digest":"sha256:0f010fdfb34e7fd48fa92320c99493617d6c018cc393ea236b2fdf13839fe7b2","observation_id":"3879b470-b54c-4f35-b1b2-f1bd0733f3bb","resolution":{"observed_at":"2026-08-07T19:45:19.784747Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-07T14:32:04.854266Z","title":"Yueqi Xie, Jingwei Yi, Jiawei Shao, Justin Curl, Lingjuan Lyu, Qifeng Chen, Xing Xie, and Fangzhao Wu","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.18680","last_updated":"2025-05-24T12:54:22Z","snapshot_observed_at":"2026-08-07T14:25:38.844849Z","submitted_at":"2025-05-24T12:54:22Z","title":"$PD^3F$: A Pluggable and Dynamic DoS-Defense Framework Against Resource Consumption Attacks Targeting Large Language Models","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T14:32:04.854266Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2505.18680"},"observation_digest":"sha256:7e220adf05f0262137c42bb7435cb318b91ef656184640593742b132bfd9b604","observation_id":"aa3c4d00-fae0-4551-9bd2-7a8ba27a65f0","resolution":{"observed_at":"2026-08-07T14:32:04.854266Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-07T12:56:17.201653Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models.arXiv preprint arXiv:2305.14710, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.23223","last_updated":"2025-05-29T08:08:38Z","snapshot_observed_at":"2026-08-09T07:33:03.065346Z","submitted_at":"2025-05-29T08:08:38Z","title":"Daunce: Data Attribution through Uncertainty Estimation","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-07T12:56:17.201653Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2505.23223"},"observation_digest":"sha256:c5741b02ecf3f8cc9fa2da888e65b6f6aa1d9efa90fd8758bd48db488864c03f","observation_id":"b89bbc68-dbf9-464b-8b0b-4cc345126973","resolution":{"observed_at":"2026-08-07T12:56:17.201653Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-07T12:12:52.493476Z","title":"Multi-token prediction improves language modeling,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.00312","last_updated":"2025-05-30T23:45:53Z","snapshot_observed_at":"2026-08-07T12:05:29.974731Z","submitted_at":"2025-05-30T23:45:53Z","title":"An evaluation of LLMs for generating movie reviews: GPT-4o, Gemini-2.0 and DeepSeek-V3","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T12:12:52.493476Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2506.00312"},"observation_digest":"sha256:a0d862549c912a3711b1b494c6a35d8a1907303f4943802a122f44e631b317d6","observation_id":"a6fe6a95-c848-47f4-98ec-9dc79e418761","resolution":{"observed_at":"2026-08-07T12:12:52.493476Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-07T05:45:56.134629Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.07214","last_updated":"2025-06-08T16:40:40Z","snapshot_observed_at":"2026-08-09T06:16:28.205414Z","submitted_at":"2025-06-08T16:40:40Z","title":"Backdoor Attack on Vision Language Models with Stealthy Semantic Manipulation","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T05:45:56.134629Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2506.07214"},"observation_digest":"sha256:4fe093490b0102d88002a1f00b342b867828b5a46b5269f3f6fffda051217056","observation_id":"d5f5a94d-64c7-4426-be51-ccce25be8610","resolution":{"observed_at":"2026-08-07T05:45:56.134629Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-04T22:33:29.981637Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.07287","last_updated":"2025-09-08T23:44:00Z","snapshot_observed_at":"2026-08-06T22:54:10.353309Z","submitted_at":"2025-09-08T23:44:00Z","title":"Paladin: Defending LLM-enabled Phishing Emails with a New Trigger-Tag Paradigm","version":1},"reference_index":96,"source":"pdf_text","source_observed_at":"2026-08-04T22:33:29.981637Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2509.07287"},"observation_digest":"sha256:00ed6ee5eb1511048cc09ee023ba8ec08798c94d3e25bfc6a8e606c44a9e3788","observation_id":"29ecab4a-5913-4ebc-88bb-f45e8f6a09e9","resolution":{"observed_at":"2026-08-04T22:33:29.981637Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-08-04T13:15:24.179041Z","title":"Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2510.01157","last_updated":"2026-06-09T20:25:55Z","snapshot_observed_at":"2026-08-08T09:22:36.387389Z","submitted_at":"2025-10-01T17:45:04Z","title":"Where Do Backdoors Live? A Component-Level Analysis of Backdoor Propagation in Speech Language Models","version":4},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-08-04T13:15:24.179041Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2510.01157"},"observation_digest":"sha256:2ed0cf22102dfb500ef65f78fb945ac81c5409ce9d24762f9162fce2ab1a0b25","observation_id":"15e7b15e-7fe8-4670-8053-7de3f9b82bb0","resolution":{"observed_at":"2026-08-04T13:15:24.179041Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","version":2},"cited_work":{"arxiv_id":"2305.14710","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2305.14710","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models","venue":null,"work_id":"625cb425-a6f2-43e2-acb0-51c4a5293c68","year":2023},"citing_paper":{"arxiv_id":"2510.18333","last_updated":"2026-04-21T04:19:09Z","snapshot_observed_at":"2026-07-06T22:33:39.148066Z","submitted_at":"2025-10-21T06:34:51Z","title":"Position: LLM Watermarking Should Align Stakeholders' Incentives for Practical Adoption","version":2},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-05-18T05:24:25.622071Z"},"links":{"cited_paper":"/paper/2305.14710","citing_paper":"/paper/2510.18333"},"observation_digest":"sha256:ad2f9ef3187da55b537dbdf71c947dfb0e699fd790147f4191d34b4fc17d23d0","observation_id":"87037e30-0385-4b0c-b044-9ebda7b31148","resolution":{"observed_at":"2026-05-18T05:25:54.517830Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2305.14710/citation-record","integrity":"/paper/2305.14710/integrity","json":"/paper/2305.14710/citation-record.json","paper":"/paper/2305.14710"},"outbound":[],"paper":{"arxiv_id":"2305.14710","last_updated":"2024-04-03T09:15:15Z","latest_version":2,"primary_category":"cs.CL","snapshot_observed_at":"2026-08-06T20:08:37.704569Z","submitted_at":"2023-05-24T04:27:21Z","title":"Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 12 inbound Pith citation observations for arXiv:2305.14710."}