{"as_of":"2026-08-08T02:15:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:2e0cbe90686f7c3787036412ed57325ba58089c5087444b37b851fdc9975da02","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":20,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":20,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":20,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":20,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T14:18:21.138116Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-06-29T17:33:45.519635Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2409.18169","last_updated":"2026-04-23T18:48:49Z","snapshot_observed_at":"2026-07-06T19:22:58.341345Z","submitted_at":"2024-09-26T17:55:22Z","title":"Harmful Fine-tuning Attacks and Defenses for Large Language Models: A Survey","version":6},"reference_index":163,"source":"pdf_text","source_observed_at":"2026-05-23T20:58:16.237327Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2409.18169"},"observation_digest":"sha256:d00422277c0852f422418a711fca468c6b6052fc5bb39a90e8028fa29cc46aeb","observation_id":"098dc8ab-5ebb-448e-a57d-9132d08bf51b","resolution":{"observed_at":"2026-05-23T20:58:26.065160Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2504.02181","last_updated":"2026-04-22T01:49:17Z","snapshot_observed_at":"2026-07-30T09:24:14.725185Z","submitted_at":"2025-04-02T23:51:27Z","title":"A Survey of Scaling in Large Language Model Reasoning","version":2},"reference_index":227,"source":"pdf_text","source_observed_at":"2026-05-22T21:20:07.238992Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2504.02181"},"observation_digest":"sha256:d219514907d6b1ef2fae903d150cf2669bd23c88834e43bbb2290e1711185da7","observation_id":"7bb08e4b-c31a-441b-b556-5eed7d4b8174","resolution":{"observed_at":"2026-05-22T21:22:09.350054Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2504.05605","last_updated":"2025-04-08T01:36:16Z","snapshot_observed_at":"2026-08-02T05:27:21.658804Z","submitted_at":"2025-04-08T01:36:16Z","title":"ShadowCoT: Cognitive Hijacking for Stealthy Reasoning Backdoors in LLMs","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-05-22T21:11:46.405944Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2504.05605"},"observation_digest":"sha256:3f9a1e01a58fcdd5bfdfe3aed3f06e5d140eddceb55b8cacf75722213151c3cb","observation_id":"c067539a-ca14-4b74-b58c-16b347648203","resolution":{"observed_at":"2026-05-22T21:12:08.345526Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-08-07T14:18:21.138116Z","title":"Badchain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.19405","last_updated":"2025-05-26T01:42:37Z","snapshot_observed_at":"2026-08-07T14:12:40.563554Z","submitted_at":"2025-05-26T01:42:37Z","title":"CoTGuard: Using Chain-of-Thought Triggering for Copyright Protection in Multi-Agent LLM Systems","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T14:18:21.138116Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2505.19405"},"observation_digest":"sha256:62b8ba5572f483177bfbba366f8dd1039987104172484589eef0febe436f28eb","observation_id":"88f32241-8fb1-4f46-b949-46851a523d92","resolution":{"observed_at":"2026-08-07T14:18:21.138116Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-08-06T21:05:19.064128Z","title":"Badchain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.02990","last_updated":"2025-07-01T18:00:04Z","snapshot_observed_at":"2026-08-06T20:57:35.466498Z","submitted_at":"2025-07-01T18:00:04Z","title":"`For Argument's Sake, Show Me How to Harm Myself!': Jailbreaking LLMs in Suicide and Self-Harm Contexts","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-06T21:05:19.064128Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2507.02990"},"observation_digest":"sha256:25982e94481ba7fee74f57b58a829fe2d5c4d4117c2785cc7da7aa74b1f538f7","observation_id":"dd164da0-e7bd-4205-9b1e-9eec09b4d897","resolution":{"observed_at":"2026-08-06T21:05:19.064128Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2508.03793","last_updated":"2026-04-17T19:17:37Z","snapshot_observed_at":"2026-07-06T22:08:21.728198Z","submitted_at":"2025-08-05T17:56:51Z","title":"AttnTrace: Contextual Attribution of Prompt Injection and Knowledge Corruption","version":3},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-05-19T00:33:53.280563Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2508.03793"},"observation_digest":"sha256:deaf442f3bb6d48c5ed36d479da758c0561080b7194ac359d7ff1e49a33d730b","observation_id":"921d3562-6abf-4864-9c19-1df8775b2044","resolution":{"observed_at":"2026-05-19T00:36:56.376520Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-08-06T00:59:41.683308Z","title":"Badchain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.03986","last_updated":"2025-08-06T00:39:28Z","snapshot_observed_at":"2026-08-07T09:03:43.592840Z","submitted_at":"2025-08-06T00:39:28Z","title":"The Emotional Baby Is Truly Deadly: Does your Multimodal Large Reasoning Model Have Emotional Flattery towards Humans?","version":1},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-08-06T00:59:41.683308Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2508.03986"},"observation_digest":"sha256:8337c6ce0073f49c1f0a5a35badec06d7d8048c035e51df5e71fdfc9646981c0","observation_id":"b5490269-de60-49ff-a1fe-891aa27861ca","resolution":{"observed_at":"2026-08-06T00:59:41.683308Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-08-05T05:59:28.656669Z","title":"Badchain: Backdoor chain-of-thought prompting for large language models, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2509.04615","last_updated":"2025-09-04T18:59:07Z","snapshot_observed_at":"2026-08-07T20:47:45.470189Z","submitted_at":"2025-09-04T18:59:07Z","title":"Breaking to Build: A Threat Model of Prompt-Based Attacks for Securing LLMs","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-05T05:59:28.656669Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2509.04615"},"observation_digest":"sha256:2b0337c62077a6dc4838bee7210a19ed7dd993fc1ecbaf54ab64bc444078cc4e","observation_id":"bb8d0d41-f8b3-4413-999a-3e438355bff2","resolution":{"observed_at":"2026-08-05T05:59:28.656669Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2603.25412","last_updated":"2026-05-06T06:58:11Z","snapshot_observed_at":"2026-08-04T09:03:17.011656Z","submitted_at":"2026-03-26T13:08:56Z","title":"Beyond Content Safety: Real-Time Monitoring for Reasoning Vulnerabilities in Large Language Models","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-05-15T00:45:43.705160Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2603.25412"},"observation_digest":"sha256:37d6701d80fc5c8d009588b9914626f08c0c63e2cbcb7cc2157b73e46cb11426","observation_id":"68a6f6bc-9d88-45d9-99a8-df008b470911","resolution":{"observed_at":"2026-05-15T00:48:24.941493Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2604.06811","last_updated":"2026-05-28T07:57:37Z","snapshot_observed_at":"2026-07-13T08:51:18.197463Z","submitted_at":"2026-04-08T08:24:48Z","title":"SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-05-10T17:36:19.694339Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2604.06811"},"observation_digest":"sha256:61d8b41a88816bf8baacf2d2aa84bcb528491b1451e3bea3494ac7606aaafb3e","observation_id":"784aca06-573e-4190-bbb8-4d19ad8f61a9","resolution":{"observed_at":"2026-05-11T06:31:02.029924Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2604.06840","last_updated":"2026-04-12T09:36:15Z","snapshot_observed_at":"2026-07-31T16:00:14.214403Z","submitted_at":"2026-04-08T09:02:05Z","title":"MirageBackdoor: A Stealthy Attack that Induces Think-Well-Answer-Wrong Reasoning","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-10T17:16:34.224543Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2604.06840"},"observation_digest":"sha256:a2a207f0d7e9b3d32b3abbaf208cfe0ce9a9de4c0daf381b5d1ef7eb547896af","observation_id":"cc6c0c9a-379d-40d1-b66b-4eb24bb84959","resolution":{"observed_at":"2026-05-11T07:10:59.763688Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2604.21700","last_updated":"2026-04-23T14:08:53Z","snapshot_observed_at":"2026-07-06T23:08:14.631453Z","submitted_at":"2026-04-23T14:08:53Z","title":"Stealthy Backdoor Attacks against LLMs Based on Natural Style Triggers","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-05-09T21:37:43.177370Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2604.21700"},"observation_digest":"sha256:a58b73e92733c1b328f60ab583f0bb81467442461c56807c6b51908be32a23dc","observation_id":"441c9ccf-cbb6-4b4f-abf2-84faea76fa92","resolution":{"observed_at":"2026-05-11T14:31:07.674325Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2604.24162","last_updated":"2026-04-27T08:18:30Z","snapshot_observed_at":"2026-07-06T23:10:16.426836Z","submitted_at":"2026-04-27T08:18:30Z","title":"Defusing the Trigger: Plug-and-Play Defense for Backdoored LLMs via Tail-Risk Intrinsic Geometric Smoothing","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-05-08T03:09:43.879809Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2604.24162"},"observation_digest":"sha256:3e7479bbe93834227a73025488e0023f2c25afa8958d7292141ec7af8c6b65ab","observation_id":"7f3bba6a-8405-477d-a767-787d300010ab","resolution":{"observed_at":"2026-05-11T22:16:25.806275Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2604.25247","last_updated":"2026-04-28T05:52:57Z","snapshot_observed_at":"2026-07-06T23:11:07.254460Z","submitted_at":"2026-04-28T05:52:57Z","title":"R-CoT: A Reasoning-Layer Watermark via Redundant Chain-of-Thought in Large Language Models","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-05-07T15:54:22.189376Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2604.25247"},"observation_digest":"sha256:1308e905593a095aa2e7591d88914168167fb6d0dbd49158e60a2a1ac217b73d","observation_id":"fbdaf68d-cb81-46a7-a25d-5b613a31720d","resolution":{"observed_at":"2026-05-12T00:01:16.580704Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2605.02255","last_updated":"2026-05-04T06:06:41Z","snapshot_observed_at":"2026-08-07T09:15:56.905794Z","submitted_at":"2026-05-04T06:06:41Z","title":"On the Privacy of LLMs: An Ablation Study","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-05-08T18:25:05.586464Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2605.02255"},"observation_digest":"sha256:f42fdb7ac9314087831798b0345a8acdaab373a9b3d606457d86753e3ca37bb6","observation_id":"0383439a-39dd-4ef0-8481-97bf2e63e21e","resolution":{"observed_at":"2026-05-09T06:25:48.830555Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2605.20641","last_updated":"2026-05-20T02:55:56Z","snapshot_observed_at":"2026-07-06T23:31:13.042581Z","submitted_at":"2026-05-20T02:55:56Z","title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-21T04:45:35.079192Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2605.20641"},"observation_digest":"sha256:660b6df90d66a0c8bd8f06a182d476bb80be71c239f24cf94b8a357c68260119","observation_id":"e79d654a-b052-4d4e-8413-d724a72399b3","resolution":{"observed_at":"2026-05-21T04:49:35.670445Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2605.26795","last_updated":"2026-07-27T09:24:10Z","snapshot_observed_at":"2026-08-02T13:08:36.594565Z","submitted_at":"2026-05-26T10:10:01Z","title":"What Does Chain-of-Thought Contribute at Probe Time? Evidence for Local Co-Occurrence Activation","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-06-29T17:24:32.401230Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2605.26795"},"observation_digest":"sha256:8a18a59525289763fdbfff293975f9d485b1672adcd4a7e567eb68ae3063fc3b","observation_id":"cf917bda-81df-456e-a9cf-c5d40efbc2e3","resolution":{"observed_at":"2026-06-29T17:33:45.521129Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-08-02T13:08:40.588662Z","title":"Badchain: Backdoor chain-of-thought prompting for large language models.arXiv preprint arXiv:2401.12242, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2605.26795","last_updated":"2026-07-27T09:24:10Z","snapshot_observed_at":"2026-08-02T13:08:36.594565Z","submitted_at":"2026-05-26T10:10:01Z","title":"What Does Chain-of-Thought Contribute at Probe Time? Evidence for Local Co-Occurrence Activation","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-02T13:08:40.588662Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2605.26795"},"observation_digest":"sha256:db77ea9e45880e3a3f32f82ff6174589ef79c5523a9e8312b4f7ddd9f6d52bb6","observation_id":"9ae8b2b5-40be-428f-910b-e9dd1e86bf81","resolution":{"observed_at":"2026-08-02T13:08:40.588662Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":"2401.12242","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-06-29T17:33:45.519635Z","title":"Bad- chain: Backdoor chain-of-thought prompting for large language models","venue":null,"work_id":"6a1ff876-4f40-437c-ba69-9cac97dfda8e","year":2024},"citing_paper":{"arxiv_id":"2606.00654","last_updated":"2026-05-30T09:57:42Z","snapshot_observed_at":"2026-08-07T23:35:33.862372Z","submitted_at":"2026-05-30T09:57:42Z","title":"The Invitation Trap: Proactive Availability Backdoor in LLMs via Conversational Induction","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-28T18:43:43.210136Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2606.00654"},"observation_digest":"sha256:e23e74f6e943b6104cc3ca026f84e11a5fdc01c17a072ab3af5459cdb9dabc38","observation_id":"3db34b82-c13a-46d3-afbe-6e5484dc583c","resolution":{"observed_at":"2026-06-28T20:22:37.835069Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.12242","snapshot_observed_at":"2026-07-11T14:39:55.782891Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.04718","last_updated":"2026-07-06T06:43:21Z","snapshot_observed_at":"2026-08-06T02:04:11.416626Z","submitted_at":"2026-07-06T06:43:21Z","title":"FORGE: Research-Trajectory Hijacking Attacks on Deep Research Agents","version":1},"reference_index":97,"source":"arxiv_source","source_observed_at":"2026-07-11T14:39:55.782891Z"},"links":{"cited_paper":"/paper/2401.12242","citing_paper":"/paper/2607.04718"},"observation_digest":"sha256:320f96ea15bce49aecc98547ce356a81ac6755640dcaeb198bf8823736216271","observation_id":"3654ba80-4d6b-4412-8c35-6e68b257a284","resolution":{"observed_at":"2026-07-11T14:39:55.782891Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2401.12242/citation-record","integrity":"/paper/2401.12242/integrity","json":"/paper/2401.12242/citation-record.json","paper":"/paper/2401.12242"},"outbound":[],"paper":{"arxiv_id":"2401.12242","last_updated":"2024-01-20T04:53:35Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-03T13:20:53.690687Z","submitted_at":"2024-01-20T04:53:35Z","title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 8 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 20 inbound Pith citation observations for arXiv:2401.12242."}