{"as_of":"2026-08-07T12:51:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:ae93e5f38012d061323f8b255e70da06f812e7f61d56b639b3b3f1b8a022e543","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":9,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":9,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":9,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":9,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T05:59:24.716762Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":5,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":"2402.09063","doi":"10.48550/arxiv.2402.09063","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source LLMs through the embedding space","venue":"arXiv (Cornell University)","work_id":"57e13778-6493-44c7-9453-1fd0842f8a5c","year":2024},"citing_paper":{"arxiv_id":"2503.02574","last_updated":"2026-05-18T17:54:05Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-03-04T12:55:07Z","title":"LLM-Safety Evaluations Lack Robustness","version":2},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-05-23T01:26:45.402983Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2503.02574"},"observation_digest":"sha256:c55df6fcfb1d6b0ab48cdd45e1f70eccdcbb96bec12f4add5f03d63d792fbae3","observation_id":"cc335f10-b94a-4214-9dc5-b34398eefa78","resolution":{"observed_at":"2026-05-23T01:27:21.349571Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-07T05:59:24.716762Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.06447","last_updated":"2025-06-06T18:09:30Z","snapshot_observed_at":"2026-08-07T05:54:17.609511Z","submitted_at":"2025-06-06T18:09:30Z","title":"Fake Friends and Sponsored Ads: The Risks of Advertising in Conversational Search","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T05:59:24.716762Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2506.06447"},"observation_digest":"sha256:069494e819e8378d99b751d2b778a0cbe6bb13d397321d98210d8019f40e1829","observation_id":"e8e073b0-f459-4c27-a790-27bc91acf10b","resolution":{"observed_at":"2026-08-07T05:59:24.716762Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-06T21:50:25.052460Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source llms through the embedding space, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.02956","last_updated":"2025-06-29T23:28:55Z","snapshot_observed_at":"2026-08-06T21:40:50.164647Z","submitted_at":"2025-06-29T23:28:55Z","title":"A Representation Engineering Perspective on the Effectiveness of Multi-Turn Jailbreaks","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-06T21:50:25.052460Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2507.02956"},"observation_digest":"sha256:842d64c1d7fc00c333e65f8ce24d1ff30c67d957a04ecea2e0b6f5b0eec6f0c2","observation_id":"d96455b2-84ed-4436-8021-783c7711c8d1","resolution":{"observed_at":"2026-08-06T21:50:25.052460Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-06T19:59:53.129178Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source llms through the embedding space","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2507.04219","last_updated":"2026-06-17T16:48:46Z","snapshot_observed_at":"2026-08-06T19:50:32.081193Z","submitted_at":"2025-07-06T03:08:49Z","title":"Model Collapse Is Not a Bug but a Feature in Machine Unlearning for LLMs","version":5},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-06T19:59:53.129178Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2507.04219"},"observation_digest":"sha256:714d46bc707deabf5b09514cb7d8bc44429b6c8ba8baaffb150c8a96f8d752fe","observation_id":"ba850a58-8388-4051-a10f-7b95ce1f8678","resolution":{"observed_at":"2026-08-06T19:59:53.129178Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-06T19:26:13.718850Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.08020","last_updated":"2025-07-08T03:01:00Z","snapshot_observed_at":"2026-08-06T19:19:20.387278Z","submitted_at":"2025-07-08T03:01:00Z","title":"Circumventing Safety Alignment in Large Language Models Through Embedding Space Toxicity Attenuation","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-06T19:26:13.718850Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2507.08020"},"observation_digest":"sha256:784b7c18eda2616094e400280953edf9dd906b0f9c721701b7cbb0bb0b20e0f6","observation_id":"c0fae038-732b-47ca-9473-9237fc0effa6","resolution":{"observed_at":"2026-08-06T19:26:13.718850Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-05T20:31:37.155433Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source llms through the embedding space","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-05T20:31:28.198027Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:37.155433Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:d9ae503878414f746e28751a57360fc424f1fea5111fd7d71a97650a20965c8c","observation_id":"25011324-4e75-4273-8cdd-0c3901a57082","resolution":{"observed_at":"2026-08-05T20:31:37.155433Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":"2402.09063","doi":"10.48550/arxiv.2402.09063","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source LLMs through the embedding space","venue":"arXiv (Cornell University)","work_id":"57e13778-6493-44c7-9453-1fd0842f8a5c","year":2024},"citing_paper":{"arxiv_id":"2604.10403","last_updated":"2026-04-12T01:37:45Z","snapshot_observed_at":"2026-07-06T22:59:01.129724Z","submitted_at":"2026-04-12T01:37:45Z","title":"Latent Instruction Representation Alignment: defending against jailbreaks, backdoors and undesired knowledge in LLMs","version":1},"reference_index":32,"source":"arxiv_source","source_observed_at":"2026-05-10T16:41:52.440793Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2604.10403"},"observation_digest":"sha256:bfb1f273937f3f9805ca0e97b6c6b9494f77c1025dfd25c1cb7651f4d79f60a7","observation_id":"f863855c-2927-461e-94ff-d7ea1978ab0e","resolution":{"observed_at":"2026-05-11T08:21:00.105707Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":"2402.09063","doi":"10.48550/arxiv.2402.09063","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source LLMs through the embedding space","venue":"arXiv (Cornell University)","work_id":"57e13778-6493-44c7-9453-1fd0842f8a5c","year":2024},"citing_paper":{"arxiv_id":"2605.11170","last_updated":"2026-06-02T13:57:02Z","snapshot_observed_at":"2026-08-02T02:13:17.912919Z","submitted_at":"2026-05-11T19:28:33Z","title":"Unlearning with Asymmetric Sources: Improved Unlearning-Utility Trade-off with Public Data","version":1},"reference_index":129,"source":"arxiv_source","source_observed_at":"2026-05-13T05:56:38.042978Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2605.11170"},"observation_digest":"sha256:940daef8ece41e508d0884d3d64ad661bf9c4c2845b1a3dfb7b5b172e4b4c8c1","observation_id":"aeb00d55-7c17-4338-9bac-3b1bd8a0f3d2","resolution":{"observed_at":"2026-05-13T05:57:21.589235Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.09063","snapshot_observed_at":"2026-08-01T15:40:36.714300Z","title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source LLMs through the embedding space.arXiv preprint arXiv:2402.09063, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.18228","last_updated":"2026-07-20T17:58:05Z","snapshot_observed_at":"2026-08-01T15:40:34.037153Z","submitted_at":"2026-07-20T17:58:05Z","title":"Logical Judgments Under Pressure: Diagnosing Syllogistic Stability with Learned Soft Prefixes","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-01T15:40:36.714300Z"},"links":{"cited_paper":"/paper/2402.09063","citing_paper":"/paper/2607.18228"},"observation_digest":"sha256:61a861d6c46187ffb4839de9859ffba480fac76840c1955d46615d3710f78258","observation_id":"d3268f6a-4563-4f02-bc30-06e7152dc068","resolution":{"observed_at":"2026-08-01T15:40:36.714300Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2402.09063/citation-record","integrity":"/paper/2402.09063/integrity","json":"/paper/2402.09063/citation-record.json","paper":"/paper/2402.09063"},"outbound":[],"paper":{"arxiv_id":"2402.09063","last_updated":"2025-04-16T15:15:56Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-07-06T17:29:56.393307Z","submitted_at":"2024-02-14T10:20:03Z","title":"Soft Prompt Threats: Attacking Safety Alignment and Unlearning in Open-Source LLMs through the Embedding Space"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 9 inbound Pith citation observations for arXiv:2402.09063."}