{"as_of":"2026-08-07T17:59:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:b853788ad85373790d08da02e999b0f0a1f95ee9f37697331221cdcc9cf305ce","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":12,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":12,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":12,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":12,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T10:28:52.855847Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-24T00:38:39.819593Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":"2404.16369","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2404.16369 (2024)","venue":null,"work_id":"860c54c3-6fa3-4579-a8b4-41b533bc62e8","year":2024},"citing_paper":{"arxiv_id":"2405.13068","last_updated":"2026-04-18T08:25:50Z","snapshot_observed_at":"2026-08-04T20:18:53.393132Z","submitted_at":"2024-05-20T17:17:55Z","title":"Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment","version":4},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-05-24T00:38:36.992597Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2405.13068"},"observation_digest":"sha256:8c893fe7f2551fcc77157bfa1e0c9dcd5c7349ab0e8defe59410d6cc84c88e07","observation_id":"366c2e06-2992-430f-869e-3a8443a2753c","resolution":{"observed_at":"2026-05-24T00:38:39.826939Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":"2404.16369","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2404.16369 (2024)","venue":null,"work_id":"860c54c3-6fa3-4579-a8b4-41b533bc62e8","year":2024},"citing_paper":{"arxiv_id":"2407.04295","last_updated":"2024-08-30T11:57:47Z","snapshot_observed_at":"2026-08-04T23:34:13.332065Z","submitted_at":"2024-07-05T06:57:30Z","title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","version":2},"reference_index":123,"source":"pdf_text","source_observed_at":"2026-05-15T02:20:44.368219Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2407.04295"},"observation_digest":"sha256:1292448200374c781d3394d08872ab219a0f43c44c796601563065f137ead5d6","observation_id":"e224c9e7-a992-4dda-95ae-7a0912f68518","resolution":{"observed_at":"2026-05-15T02:20:44.527408Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-07T10:28:52.855847Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.06391","last_updated":"2025-06-05T16:53:29Z","snapshot_observed_at":"2026-08-07T10:19:54.496854Z","submitted_at":"2025-06-05T16:53:29Z","title":"From Rogue to Safe AI: The Role of Explicit Refusals in Aligning LLMs with International Humanitarian Law","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T10:28:52.855847Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2506.06391"},"observation_digest":"sha256:90943e5f2b8e7c54a1664f207b9319cc31d2ec198e3d35f7f7a90daa2d474a56","observation_id":"34896cab-3e45-46f0-b59a-f53c3fcb04d0","resolution":{"observed_at":"2026-08-07T10:28:52.855847Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-07T05:40:20.621417Z","title":"Don’t say no: Jailbreaking llm by suppressing refusal","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.07402","last_updated":"2025-06-09T03:52:43Z","snapshot_observed_at":"2026-08-07T10:07:41.500171Z","submitted_at":"2025-06-09T03:52:43Z","title":"Beyond Jailbreaks: Revealing Stealthier and Broader LLM Security Risks Stemming from Alignment Failures","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T05:40:20.621417Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2506.07402"},"observation_digest":"sha256:7e82599c42c8579ae270cf8d5dba5d9ba4689a99cde0d70bafe80a25ede541fe","observation_id":"72ba783a-5b5a-4037-a109-1035b69cdfe8","resolution":{"observed_at":"2026-08-07T05:40:20.621417Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-06T23:20:57.656839Z","title":"Don’t say no: Jailbreaking llm by suppressing refusal.arXiv preprint arXiv:2404.163692024","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.18543","last_updated":"2026-05-25T10:15:56Z","snapshot_observed_at":"2026-08-06T23:13:30.961405Z","submitted_at":"2025-06-23T11:53:31Z","title":"SoK: A Comprehensive Security Analysis of Jailbreak Resilience in GPT and DeepSeek Models","version":2},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-06T23:20:57.656839Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2506.18543"},"observation_digest":"sha256:4ea71d89bf2e642918bc95907e35822354534ca54695c955256570a3aadb8ea4","observation_id":"42a48662-4628-4735-83ee-9602c01ffcd3","resolution":{"observed_at":"2026-08-06T23:20:57.656839Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-06T21:34:41.418171Z","title":"Don’t say no: Jailbreaking llm by suppressing refusal,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.23930","last_updated":"2025-06-30T14:59:25Z","snapshot_observed_at":"2026-08-06T21:25:36.872783Z","submitted_at":"2025-06-30T14:59:25Z","title":"Leveraging the Potential of Prompt Engineering for Hate Speech Detection in Low-Resource Languages","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-06T21:34:41.418171Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2506.23930"},"observation_digest":"sha256:f0aebacbe8b1617004f7d9a4dbb1cfcd6b975e6352475f409c487793db3d4c38","observation_id":"36a7ccd1-900a-40af-92c3-8adda79cb4ea","resolution":{"observed_at":"2026-08-06T21:34:41.418171Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-05T20:31:33.756873Z","title":"Don’t say no: Jailbreaking llm by suppressing refusal","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-07T14:42:27.926127Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:33.756873Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:08929bd517a65b8ac1825d1bf54fc14e11f6a0bb43fc47f9f2b500c3f0a50b7e","observation_id":"17b10907-dc4b-451b-b535-e0841e28f91e","resolution":{"observed_at":"2026-08-05T20:31:33.756873Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-05T14:51:03.812481Z","title":"Don’t Say No: Jailbreaking LLM by Sup- pressing Refusal","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.20848","last_updated":"2025-08-28T14:40:27Z","snapshot_observed_at":"2026-08-05T14:51:02.831302Z","submitted_at":"2025-08-28T14:40:27Z","title":"JADES: A Universal Framework for Jailbreak Assessment via Decompositional Scoring","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-05T14:51:03.812481Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2508.20848"},"observation_digest":"sha256:ae9c3cb449b4a3ab2b752e04f8b2e3807f7285ec5ceab5d87bcf8ca79747b80a","observation_id":"0acbcdc5-64f0-4ef2-937b-b660adecc5c2","resolution":{"observed_at":"2026-08-05T14:51:03.812481Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-08-04T09:25:58.741705Z","title":"Don’t say no: Jailbreaking LLM by suppressing refusal.CoRR, abs/2404.16369, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2510.15476","last_updated":"2026-07-04T04:20:15Z","snapshot_observed_at":"2026-08-06T02:45:04.316908Z","submitted_at":"2025-10-17T09:38:54Z","title":"SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses","version":3},"reference_index":246,"source":"pdf_text","source_observed_at":"2026-08-04T09:25:58.741705Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2510.15476"},"observation_digest":"sha256:2fabd3096df6ab99362b233c7125fc7933543524b5ffd7a174a25c14816b2856","observation_id":"53dee416-6ad5-4d83-a501-a5a3c659e3de","resolution":{"observed_at":"2026-08-04T09:25:58.741705Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":"2404.16369","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2404.16369 (2024)","venue":null,"work_id":"860c54c3-6fa3-4579-a8b4-41b533bc62e8","year":2024},"citing_paper":{"arxiv_id":"2601.02670","last_updated":"2026-04-08T04:11:40Z","snapshot_observed_at":"2026-07-06T22:40:46.465095Z","submitted_at":"2026-01-06T02:58:22Z","title":"Break Me If You Can: Self-Jailbreaking of Aligned LLMs via Lexical Insertion Prompting","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-16T18:04:44.543311Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2601.02670"},"observation_digest":"sha256:3b9ceb37d81034d96683a1da1010d8294b2749d05765274dd19da54da22c1599","observation_id":"85d5ee7b-4e79-40c2-a9b7-8a97940035a2","resolution":{"observed_at":"2026-05-16T18:08:13.063281Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":"2404.16369","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2404.16369 (2024)","venue":null,"work_id":"860c54c3-6fa3-4579-a8b4-41b533bc62e8","year":2024},"citing_paper":{"arxiv_id":"2604.11309","last_updated":"2026-04-13T11:12:30Z","snapshot_observed_at":"2026-07-30T17:13:57.164751Z","submitted_at":"2026-04-13T11:12:30Z","title":"The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-05-10T16:07:31.602378Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2604.11309"},"observation_digest":"sha256:40b1de54446a3b0642f878778d3bec2b2ee2c217de9eeab25cd9950e88874c09","observation_id":"a46b9f70-7727-424c-9626-25a7dfb622f3","resolution":{"observed_at":"2026-05-11T09:16:03.956567Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal","version":3},"cited_work":{"arxiv_id":"2404.16369","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2404.16369","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2404.16369 (2024)","venue":null,"work_id":"860c54c3-6fa3-4579-a8b4-41b533bc62e8","year":2024},"citing_paper":{"arxiv_id":"2605.21674","last_updated":"2026-05-20T19:31:07Z","snapshot_observed_at":"2026-07-06T23:32:05.693503Z","submitted_at":"2026-05-20T19:31:07Z","title":"Adversarial Reframing: A Framework for Targeted Generation in Language Models","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-05-22T09:35:51.862736Z"},"links":{"cited_paper":"/paper/2404.16369","citing_paper":"/paper/2605.21674"},"observation_digest":"sha256:fcc744d11147abfdf4a5e54147ba1045a9982dfa3d2456eac8207e280d1cc198","observation_id":"ed39c6ea-b358-4627-9245-5009824ddd61","resolution":{"observed_at":"2026-05-22T09:36:20.999209Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2404.16369/citation-record","integrity":"/paper/2404.16369/integrity","json":"/paper/2404.16369/citation-record.json","paper":"/paper/2404.16369"},"outbound":[],"paper":{"arxiv_id":"2404.16369","last_updated":"2025-07-02T07:27:32Z","latest_version":3,"primary_category":"cs.CL","snapshot_observed_at":"2026-07-06T18:05:20.955471Z","submitted_at":"2024-04-25T07:15:23Z","title":"Don't Say No: Jailbreaking LLM by Suppressing Refusal"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 12 inbound Pith citation observations for arXiv:2404.16369."}