{"as_of":"2026-08-08T07:19:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:6be3e0185b0104d745acd72675f1bbd655cd0cc08d3663e7cba64d45d9910f19","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":8,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":8,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-08T06:32:00.761636+00:00","state":"measured"},{"denominator":8,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":8,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T12:35:21.021039Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-15T02:20:44.610149Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":"2312.04127","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Analyzing the Inherent Response Ten- dency of LLMs: Real-World Instructions-Driven Jail- break","venue":null,"work_id":"1dc1fa7b-0097-4a88-a275-56161e751ec9","year":2023},"citing_paper":{"arxiv_id":"2407.04295","last_updated":"2024-08-30T11:57:47Z","snapshot_observed_at":"2026-08-04T23:34:13.332065Z","submitted_at":"2024-07-05T06:57:30Z","title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-05-15T02:20:44.368219Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2407.04295"},"observation_digest":"sha256:6f584c5dae3e85577ae7806dc8d9850315100574177a3fb7c205258df670678b","observation_id":"1959d544-707d-43b3-b06f-152cdf5255e3","resolution":{"observed_at":"2026-05-15T02:20:44.612725Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-07T12:35:21.021039Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.24369","last_updated":"2025-05-30T09:02:07Z","snapshot_observed_at":"2026-08-08T01:18:48.028080Z","submitted_at":"2025-05-30T09:02:07Z","title":"Adversarial Preference Learning for Robust LLM Alignment","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-07T12:35:21.021039Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2505.24369"},"observation_digest":"sha256:3e9820a84f82371ad47385456cadbd3e1d021e9bd489bc483c9a6a3c2b6fe201","observation_id":"3e918652-9044-4560-b738-db78cebd1452","resolution":{"observed_at":"2026-08-07T12:35:21.021039Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-06T23:20:57.014753Z","title":"Analyzing the inherent response tendency of llms: Real-world instructions- driven jailbreak.arXiv preprint arXiv:2312.041272023","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.18543","last_updated":"2026-05-25T10:15:56Z","snapshot_observed_at":"2026-08-06T23:13:30.961405Z","submitted_at":"2025-06-23T11:53:31Z","title":"SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models","version":2},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-06T23:20:57.014753Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2506.18543"},"observation_digest":"sha256:a0618ba093079529477633ec6c3fd1bd9964370a0438a5f90bca1563f678ee3a","observation_id":"f2de84f1-870e-469e-b6f7-00b81abe62f6","resolution":{"observed_at":"2026-08-06T23:20:57.014753Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-06T16:25:55.064809Z","title":"Analyzing the inherent response tendency of llms: Real-world instructions-driven jailbreak,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2507.13761","last_updated":"2025-07-18T09:13:05Z","snapshot_observed_at":"2026-08-08T06:42:02.056472Z","submitted_at":"2025-07-18T09:13:05Z","title":"Innocence in the Crossfire: Roles of Skip Connections in Jailbreaking Visual Language Models","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-06T16:25:55.064809Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2507.13761"},"observation_digest":"sha256:72b971a62a9f05986252df6a738a39f678bc5703b489f5f676132611efb8ed3b","observation_id":"e935f0d9-eb2b-400a-96d5-da4ed0bfeee9","resolution":{"observed_at":"2026-08-06T16:25:55.064809Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-05T20:31:33.736025Z","title":"Analyzing the inher- ent response tendency of llms: Real-world instructions-driven jailbreak","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-08T02:31:17.622343Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:33.736025Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:dd1fbc979455b3f79a27ccccd638526764507f40021cbf7d5e3b2539c0a7f379","observation_id":"2861fd44-e50f-4d4a-8c03-1ae8259f8c1b","resolution":{"observed_at":"2026-08-05T20:31:33.736025Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-04T23:10:21.282394Z","title":"Analyzing the inherent response tendency of llms: Real-world instructions-driven jailbreak,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.06795","last_updated":"2025-09-08T15:24:33Z","snapshot_observed_at":"2026-08-06T11:18:33.345942Z","submitted_at":"2025-09-08T15:24:33Z","title":"Anchoring Refusal Direction: Mitigating Safety Risks in Tuning via Projection Constraint","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-04T23:10:21.282394Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2509.06795"},"observation_digest":"sha256:4d4f9c4322b769ab2b7bdf1050f53bdb04ef1cbd13e059a3df67f760e7d6dc7d","observation_id":"fe38cfcf-af02-4ad5-ae37-7a429babd349","resolution":{"observed_at":"2026-08-04T23:10:21.282394Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-04T23:09:41.456061Z","title":"Analyzing the inherent response tendency of llms: Real-world instructions-driven jailbreak,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.06807","last_updated":"2025-09-08T15:39:17Z","snapshot_observed_at":"2026-08-06T11:18:26.434722Z","submitted_at":"2025-09-08T15:39:17Z","title":"MoGU V2: Toward a Higher Pareto Frontier Between Model Usability and Security","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-04T23:09:41.456061Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2509.06807"},"observation_digest":"sha256:44fde91b994054e3802a736b1d7c6e87a840176df3789667555d65d964642003","observation_id":"af156b49-2e8e-48a1-b665-2b82b8b86dd3","resolution":{"observed_at":"2026-08-04T23:09:41.456061Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.04127","snapshot_observed_at":"2026-08-04T17:46:16.893553Z","title":"Analyzing the inherent response tendency of LLMs: Real-world instructions-driven jailbreak,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.10682","last_updated":"2025-09-12T20:26:16Z","snapshot_observed_at":"2026-08-04T21:00:53.508626Z","submitted_at":"2025-09-12T20:26:16Z","title":"LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems","version":1},"reference_index":80,"source":"pdf_text","source_observed_at":"2026-08-04T17:46:16.893553Z"},"links":{"cited_paper":"/paper/2312.04127","citing_paper":"/paper/2509.10682"},"observation_digest":"sha256:421438a0b6663bcaa5aa1ff82b546df5aba4b6d894c3a9acbbe8a296d1a60dda","observation_id":"f8f1cedc-1993-45e7-b0cd-7c3cfd65c564","resolution":{"observed_at":"2026-08-04T17:46:16.893553Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2312.04127/citation-record","integrity":"/paper/2312.04127/integrity","json":"/paper/2312.04127/citation-record.json","paper":"/paper/2312.04127"},"outbound":[],"paper":{"arxiv_id":"2312.04127","last_updated":"2024-02-23T07:32:27Z","latest_version":2,"primary_category":"cs.CL","snapshot_observed_at":"2026-07-06T16:58:11.501328Z","submitted_at":"2023-12-07T08:29:58Z","title":"Analyzing the Inherent Response Tendency of LLMs: Real-World Instructions-Driven Jailbreak"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"thesis":"As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 8 inbound Pith citation observations for arXiv:2312.04127."}