Pith. sign in

Paper Citation Record · LEDGER

Image Hijacks: Adversarial Images can Control Generative Models at Runtime

As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 31 inbound Pith citation observations for arXiv:2309.00236.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2309.00236 v4

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 31 of 31 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 31 of 31 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T13:35:49.779331Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

4
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 02321d28-3888-4a5c-8712-d3a9c6079e51 · inbound

A StrongREJECT for Empty Jailbreaks cites this paper.

A StrongREJECT for Empty Jailbreaks Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 3

Resolution
verified exact
arxiv_id, observed 2026-05-16T21:28:02.778509Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-16T21:28:02.745230Z digest=sha256:05937f01431416cbf961d8039ffcea4fe36d26a945ac06abac5f39bf17c1089f

Observation 774c8317-bc82-4074-87ff-188c9f1bb67d · inbound

AI Safety Landscape for Large Language Models: Taxonomy, State-of-the-art, and Future Directions cites this paper.

AI Safety Landscape for Large Language Models: Taxonomy, State-of-the-art, and Future Directions Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-23T21:55:50.328454Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-23T21:54:26.670284Z digest=sha256:2008f3b08ce969d3d158090474c26b7d133b2193b6af112a428ba0026d9ddc55

Observation 5685b14d-88f9-4990-9c1f-fec7f000d2fe · inbound

Visual Adversarial Attack on Vision-Language Models for Autonomous Driving cites this paper.

Visual Adversarial Attack on Vision-Language Models for Autonomous Driving Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-23T16:35:42.148847Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-23T16:35:24.063578Z digest=sha256:51a5688136b8d2e05e143a8b8a6ca89214723f56fc4318e5649e6f444979bf25

Observation 461e3e73-78d4-43f1-8b51-fcf858ff2ac0 · inbound

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety cites this paper.

Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 274

Resolution
verified exact
arxiv_id, observed 2026-05-23T04:42:34.140208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-23T04:39:04.591722Z digest=sha256:de6a37e40bc712044864aa00cfc66a238e96a9408102ced5faea31c8f6948179

Observation 3e321515-ee4d-4d33-abcc-a89f409c1336 · inbound

RedDiffuser: Auditing Multimodal Safety Failures in Vision-Language Models via Reinforced Diffusion cites this paper.

RedDiffuser: Auditing Multimodal Safety Failures in Vision-Language Models via Reinforced Diffusion Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-23T00:15:14.813903Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-23T00:13:08.603115Z digest=sha256:903eea1174577d9cfa91c3d6585e70732099ce287f36b0d240ae2e6cedc7dce9

Observation 4039150c-a3ae-444f-a8b0-24972fc7bc92 · inbound

Adversarial Attacks against Closed-Source MLLMs via Feature Optimal Alignment cites this paper.

Adversarial Attacks against Closed-Source MLLMs via Feature Optimal Alignment Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T13:35:49.779331Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:35:49.779331Z digest=sha256:901ba01f9cea27b69f0fd4c35af8d603d5a2139cad6bf7887c764afca7cfded5

Observation f2c31fbc-821e-42fe-bdd7-19e4ef8a4a10 · inbound

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery cites this paper.

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T13:32:45.612634Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:32:45.612634Z digest=sha256:d91c3365a4c34c1c110ebcb987b52ef0514389d10cfe520ccdda2b56af21ab7d

Observation 2b5915c6-681e-41a8-81d0-73865e04c1f5 · inbound

Con Instruction: Universal Jailbreaking of Multimodal Large Language Models via Non-Textual Modalities cites this paper.

Con Instruction: Universal Jailbreaking of Multimodal Large Language Models via Non-Textual Modalities Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T12:07:58.302229Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T12:07:58.302229Z digest=sha256:6d58eb9860f269853f18d41deeacd9a50df9a41cf88704138f394fc28200f268

Observation 9fefb28a-1b63-4374-aac9-ccaebc44501a · inbound

MGC: A Compiler Framework Exploiting Compositional Blindness in Aligned LLMs for Malware Generation cites this paper.

MGC: A Compiler Framework Exploiting Compositional Blindness in Aligned LLMs for Malware Generation Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T20:45:53.240015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:45:53.240015Z digest=sha256:0def9dce94a90a8f14e9175142ac4b3093fa5254f32512682efd92895516a733

Observation 2f8da359-dda7-4ee8-beac-ffae3b37f341 · inbound

One Object, Multiple Lies: A Benchmark for Cross-task Adversarial Attack on Unified Vision-Language Models cites this paper.

One Object, Multiple Lies: A Benchmark for Cross-task Adversarial Attack on Unified Vision-Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T18:40:52.561526Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T18:40:52.561526Z digest=sha256:95c1ee9a2677dc5e04f3e07e1418280d04417c97457926f4cf84bdd93692c8f3

Observation 517e308b-7e38-4685-85ce-e9f649f6d4c3 · inbound

PRM-Free Security Alignment of Large Models via Red Teaming and Adversarial Training cites this paper.

PRM-Free Security Alignment of Large Models via Red Teaming and Adversarial Training Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T17:35:47.822419Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T17:35:47.822419Z digest=sha256:d1eebf3e624dd64777d9bbc88c8bd9314481701c22d9cd5b8ed48655e5a2ff30

Observation cf046c21-fd53-4e9d-b1c2-edb0f1fd98ce · inbound

Secure Tug-of-War (SecTOW): Iterative Defense-Attack Training with Reinforcement Learning for Multimodal Model Security cites this paper.

Secure Tug-of-War (SecTOW): Iterative Defense-Attack Training with Reinforcement Learning for Multimodal Model Security Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T12:09:39.620116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T12:09:39.620116Z digest=sha256:5e91f4905a583c793a9af496d3851fcdd8057bb2cb81a0c0cb468ac0d9424cad

Observation 355b679a-62d3-4fc7-9471-be2b086b490b · inbound

Adversarial-Guided Diffusion for Multimodal LLM Attacks cites this paper.

Adversarial-Guided Diffusion for Multimodal LLM Attacks Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T11:02:14.914452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T11:02:14.914452Z digest=sha256:de7879b0003ab8c58dfa95eb68f7707ffb63b883b59c07bb3b643892366bacad

Observation 728cd3cb-46c5-4121-86d0-75811683e759 · inbound

Empowering Multimodal LLMs with External Tools: A Comprehensive Survey cites this paper.

Empowering Multimodal LLMs with External Tools: A Comprehensive Survey Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 221

Resolution
unresolved
no resolver link, observed 2026-08-05T20:29:05.290017Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T20:29:05.290017Z digest=sha256:de4a182e8b00583a3d1e5d95a4443ebcf3297f08250904396c1d4197ae5b9591

Observation 359f7fbe-c741-402f-9da7-57fcf4bed3f8 · inbound

On Surjectivity of Neural Networks: Can you elicit any behavior from your model? cites this paper.

On Surjectivity of Neural Networks: Can you elicit any behavior from your model? Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-05T16:00:48.260226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T16:00:48.260226Z digest=sha256:c00b23ecf2f95f423da363a5bd99b9c1e2fdb971d0733b63b5cbfb44f3ded386

Observation c82158bb-6354-4108-8dac-4d49dca84707 · inbound

VISOR++: Universal Visual Inputs based Steering for Large Vision Language Models cites this paper.

VISOR++: Universal Visual Inputs based Steering for Large Vision Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-04T13:45:26.101151Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T13:45:26.101151Z digest=sha256:8ef441ffdf38832ff949451712d0529b30cf260de859a8a8f94e145214643a79

Observation bdc042fa-3441-4b1f-b3e8-9a641a28b43e · inbound

Bridging Symbolic Control and Neural Reasoning in LLM Agents -- The Structured Cognitive Loop cites this paper.

Bridging Symbolic Control and Neural Reasoning in LLM Agents -- The Structured Cognitive Loop Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-03T21:04:37.726826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T21:04:37.726826Z digest=sha256:91fc33bead6051fdb9511ee460085ad3a3db43f57701604e6f5b66ee68854a3e

Observation d60046bd-6ccb-49f0-90f8-a6c2f08e2217 · inbound

Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation cites this paper.

Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T20:27:03.808043Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T20:27:03.808043Z digest=sha256:7d2e694de6adc82ef7ffee516df8b1064000faf324574cadd2d7686c23e8803d

Observation 642cc3bb-29dd-44b4-8536-6692169c79e8 · inbound

Gaslight, Gatekeep, V1-V3: Early Visual Cortex Alignment Shields Vision-Language Models from Sycophantic Manipulation cites this paper.

Gaslight, Gatekeep, V1-V3: Early Visual Cortex Alignment Shields Vision-Language Models from Sycophantic Manipulation Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-10T13:10:26.112009Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-10T13:09:35.407790Z digest=sha256:4bdeb4f49bb771a1fa2a89ae0bffbb7cc6cd4cac519f754b52d8c43c5105c097

Observation 7894a867-930c-433e-a2f5-6202fe646a6f · inbound

VisInject: Disruption != Injection -- A Dual-Dimension Evaluation of Universal Adversarial Attacks on Vision-Language Models cites this paper.

VisInject: Disruption != Injection -- A Dual-Dimension Evaluation of Universal Adversarial Attacks on Vision-Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-11T16:56:07.993342Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-09T14:24:48.999632Z digest=sha256:620d9a7f8d4822d0674a8339fc062d8257fb02e7ca1b68c6ade12bbee3f554b6

Observation 554af555-e98d-4093-810f-582aa7cb93a2 · inbound

Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems cites this paper.

Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-05-15T07:15:11.986933Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-15T07:11:16.568353Z digest=sha256:a2d0eccc81ff744bff6e0fbc693133ecb9bf55fc22ef16036eb199225bb75682

Observation e08a0691-f426-46c8-b89a-8801f0209f1e · inbound

Laundering AI Authority with Adversarial Examples cites this paper.

Laundering AI Authority with Adversarial Examples Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-11T17:41:08.090263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-08T17:19:38.662062Z digest=sha256:83a7da3c2ef96b6938b979bbc4aa49de9f0235d98a128c03feddca0cc2cec585

Observation b913bc95-d0d5-4d3f-a995-6548ac2acf4b · inbound

Guaranteed Jailbreaking Defense via Disrupt-and-Rectify Smoothing cites this paper.

Guaranteed Jailbreaking Defense via Disrupt-and-Rectify Smoothing Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 45

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T05:51:27.536708Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-05-12T04:50:08.866969Z digest=sha256:bbf5b5ee2c548624e89c42bdb019487f9b38c4726b83d20c4fee841ed1d4d988

Observation 9e03c10e-ad26-4b82-a41d-117a4ef72908 · inbound

Surviving the Unseen: Predictive Defense for Novel Multi-Turn Multimodal Attacks cites this paper.

Surviving the Unseen: Predictive Defense for Novel Multi-Turn Multimodal Attacks Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 2

Resolution
metadata mismatch
arxiv_id, observed 2026-05-20T09:08:09.459878Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-20T09:07:47.278074Z digest=sha256:f081573bd9a16bde47590d4dec6fc9107ec0ce23fb709b6363691eb9eda8ead8

Observation f8e1ebab-a606-4108-8d4d-ed56415f6c81 · inbound

Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition cites this paper.

Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-07-01T23:26:23.291566Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-28T14:17:52.902183Z digest=sha256:c94436825ecfe042a2bd6621f33805e12e0feb1d225f879d0ad6d2999767acad

Observation 66954ccd-3081-4be4-b8f8-bd09cfc67b1d · inbound

Exploring Adversarial Robustness and Safety Alignment in Multilingual Multi-Modal Large Language Models cites this paper.

Exploring Adversarial Robustness and Safety Alignment in Multilingual Multi-Modal Large Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-07-02T03:16:34.797053Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-28T10:10:38.261635Z digest=sha256:6326f375a528073c7555c34d72388ee849714940c39de24a8856701106552c95

Observation d1e7e3a0-313f-4c4d-8452-1045bc2cdcb2 · inbound

VisualLeakBench: Reproducible Action-Boundary Propagation Failures in Vision-Language Agents cites this paper.

VisualLeakBench: Reproducible Action-Boundary Propagation Failures in Vision-Language Agents Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T23:02:46.373139Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-28T22:59:43.041678Z digest=sha256:a0127ca14d49aebf033db294f156e91bec6bb4e770a1a7e6bfd7cd26fc388482

Observation 5a665c2a-4ae5-43bc-b903-1f388e7cd76d · inbound

Fine-tuning Multi-modal LLMs with ART: Art-based Reinforcement Training cites this paper.

Fine-tuning Multi-modal LLMs with ART: Art-based Reinforcement Training Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-03T09:07:48.147077Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T10:30:51.490047Z digest=sha256:001638672ed110e62486565f0a811eb478b2c18c62562a27406c09d214629274

Observation 31f82be9-7a6e-4e6d-a307-80e3e09d17de · inbound

MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents cites this paper.

MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T21:08:58.363185Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-27T00:54:00.944706Z digest=sha256:2fd280a73101f827db6c3b3ad6fda3f38ed528ae2b33c298bbff269b88e0b27c

Observation cf292219-7594-4d33-bc45-85751b4b59c9 · inbound

On Adversarial Vulnerability of Vision-Language Models through the Lens of Intermediate Spectral Subspaces cites this paper.

On Adversarial Vulnerability of Vision-Language Models through the Lens of Intermediate Spectral Subspaces Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 5

Resolution
metadata mismatch
local_arxiv, observed 2026-07-09T12:56:14.860115Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-07-09T12:55:34.631248Z digest=sha256:3f061cbfdfb399ea29288060b81201d170e2de63f5e9e6a68df9434721c96523

Observation 28af3106-d41f-413d-b3f1-54babc562468 · inbound

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination cites this paper.

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 116

Resolution
unresolved
no resolver link, observed 2026-08-07T00:14:47.254551Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T00:14:47.254551Z digest=sha256:1e082804819b7b493c54e63aa505320887df1e135e0bca45c10ffd9d31aedcaa