{"as_of":"2026-08-19T19:28:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:ad6bde49450c348170b5cf3bc04109dae0cf5b05f0f074a2a7ddee0cea140238","coverage":[{"denominator":92,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":92,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-16T04:33:06.641038Z","state":"measured"},{"denominator":98,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":98,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-19T06:32:44.657259+00:00","state":"measured"},{"denominator":6,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":6,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T14:21:42.232920Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-18T04:25:52.249755Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-08-07T11:23:45.644623Z","title":"Attack and de- fense techniques in large language models: A survey and new perspectives,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.02696","last_updated":"2025-06-03T09:44:28Z","snapshot_observed_at":"2026-08-15T18:57:46.741569Z","submitted_at":"2025-06-03T09:44:28Z","title":"Shaking to Reveal: Perturbation-Based Detection of LLM Hallucinations","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-07T11:23:45.644623Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2506.02696"},"observation_digest":"sha256:661b4b56d8df05c76f5d99a894e0392c4a6024e8a4e18edce3f0591357e759cc","observation_id":"46285b36-c596-4a1f-bac7-0bbd1f43205f","resolution":{"observed_at":"2026-08-07T11:23:45.644623Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":"2505.00976","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","venue":null,"work_id":"74c54bab-0bd3-41cb-8c55-53f16fb17125","year":2025},"citing_paper":{"arxiv_id":"2510.22628","last_updated":"2026-05-01T17:57:58Z","snapshot_observed_at":"2026-08-13T19:44:16.113742Z","submitted_at":"2025-10-26T11:19:47Z","title":"Sentra-Guard: A Real-Time Multilingual Defense Against Adversarial LLM Prompts","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-18T04:22:54.943043Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2510.22628"},"observation_digest":"sha256:3986fa4bdfa08ba7ffb1c73f98e7cf6a40b23ee6375ce2b674fae15573f2694f","observation_id":"f6b9ebca-6a6d-4ce6-9722-41a2bcb1cf77","resolution":{"observed_at":"2026-05-18T04:25:52.253069Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":"2505.00976","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","venue":null,"work_id":"74c54bab-0bd3-41cb-8c55-53f16fb17125","year":2025},"citing_paper":{"arxiv_id":"2604.08846","last_updated":"2026-04-10T01:01:56Z","snapshot_observed_at":"2026-08-13T19:19:16.724751Z","submitted_at":"2026-04-10T01:01:56Z","title":"Dictionary-Aligned Concept Control for Safeguarding Multimodal LLMs","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-05-10T18:04:05.157103Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2604.08846"},"observation_digest":"sha256:8a7bf875b5c203185f68e5ae5191578b05171be7744cf9bef762c189460dad78","observation_id":"c9433373-0fc3-4415-a886-ea90cb838d70","resolution":{"observed_at":"2026-05-11T05:35:57.747757Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":"2505.00976","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","venue":null,"work_id":"74c54bab-0bd3-41cb-8c55-53f16fb17125","year":2025},"citing_paper":{"arxiv_id":"2604.09056","last_updated":"2026-04-10T07:29:39Z","snapshot_observed_at":"2026-08-12T12:19:53.162452Z","submitted_at":"2026-04-10T07:29:39Z","title":"Conversations Risk Detection LLMs in Financial Agents via Multi-Stage Generative Rollout","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-05-10T17:54:41.534985Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2604.09056"},"observation_digest":"sha256:16332886ea28a4e72f63d41b583912121fa3c122f5aae9d3b2c8e716a5fc663f","observation_id":"719c31f6-d905-4328-935f-7bbfebbafa4a","resolution":{"observed_at":"2026-05-11T05:51:10.957370Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":"2505.00976","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","venue":null,"work_id":"74c54bab-0bd3-41cb-8c55-53f16fb17125","year":2025},"citing_paper":{"arxiv_id":"2604.15725","last_updated":"2026-04-17T05:56:46Z","snapshot_observed_at":"2026-08-14T06:45:34.587653Z","submitted_at":"2026-04-17T05:56:46Z","title":"Reasoning-targeted Jailbreak Attacks on Large Reasoning Models via Semantic Triggers and Psychological Framing","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-05-10T08:24:43.494005Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2604.15725"},"observation_digest":"sha256:a1f6aa0f4d5c7ab999cade288e150b5277b48fcc0cdaea315f69cc5e382c421a","observation_id":"b8d58460-56ee-4a31-abdf-8c3a106993fd","resolution":{"observed_at":"2026-05-10T09:08:26.246230Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.00976","snapshot_observed_at":"2026-08-15T14:21:42.232920Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.10530","last_updated":"2026-08-11T06:11:26Z","snapshot_observed_at":"2026-08-19T18:52:42.862550Z","submitted_at":"2026-08-11T06:11:26Z","title":"On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-15T14:21:42.232920Z"},"links":{"cited_paper":"/paper/2505.00976","citing_paper":"/paper/2608.10530"},"observation_digest":"sha256:d1f8ae85df2a97c94750ae35080dc4eb0037b328b2033d8bd945d912b8da21bd","observation_id":"b45ec352-e572-4bcf-abc0-7b9131838e10","resolution":{"observed_at":"2026-08-15T14:21:42.232920Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2505.00976/citation-record","integrity":"/paper/2505.00976/integrity","json":"/paper/2505.00976/citation-record.json","paper":"/paper/2505.00976"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.182806Z","title":", Wu, C.S.,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.182806Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:835f01d0643096f327b119d40bdf9d0bfeb2ea425f5dac2807e0f181332c278e","observation_id":"1e422e49-a87e-4006-b101-d5f76b4caf28","resolution":{"observed_at":"2026-08-16T04:33:06.182806Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.14132","last_updated":"2023-11-07T03:30:15Z","snapshot_observed_at":"2026-08-15T21:55:47.604051Z","submitted_at":"2023-08-27T15:20:06Z","title":"Detecting Language Model Attacks with Perplexity","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.14132","snapshot_observed_at":"2026-08-16T04:33:06.191534Z","title":"Detecting language model a ttacks with perplexity","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.191534Z"},"links":{"cited_paper":"/paper/2308.14132","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:3ba851cda75a481012975e702b25bdb9253a1a8d7bd56d664315074d002bdf7e","observation_id":"cbf812c1-fde7-419a-8add-e7ffec302cdb","resolution":{"observed_at":"2026-08-16T04:33:06.191534Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2309.10544","last_updated":"2023-09-19T11:45:29Z","snapshot_observed_at":"2026-08-19T09:56:07.546515Z","submitted_at":"2023-09-19T11:45:29Z","title":"Model Leeching: An Extraction Attack Targeting LLMs","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.10544","snapshot_observed_at":"2026-08-16T04:33:06.195521Z","title":"Model leeching: An extraction attack targeting llms","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.195521Z"},"links":{"cited_paper":"/paper/2309.10544","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:7d64e43a1821287a0a775f0edaaa18f7baa5ad5ed30007173455af6763f7fa55","observation_id":"6f3acc73-d4d8-4ba6-ac72-ded3a3932b1a","resolution":{"observed_at":"2026-08-16T04:33:06.195521Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2209.02128","last_updated":"2022-09-05T20:29:17Z","snapshot_observed_at":"2026-08-16T16:34:37.859838Z","submitted_at":"2022-09-05T20:29:17Z","title":"Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2209.02128","snapshot_observed_at":"2026-08-16T04:33:06.199548Z","title":"Evaluating the su scepti- bility of pre-trained language models via handcrafted adve rsarial ex- amples","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.199548Z"},"links":{"cited_paper":"/paper/2209.02128","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b04036a47928a93fa4cf200e08897d6c2bead05f6116da5163b2e1715d9ef502","observation_id":"4f0f2944-a96e-4e9e-be11-8302fd9a1064","resolution":{"observed_at":"2026-08-16T04:33:06.199548Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.203546Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.203546Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:cb70436c16395586642d25ddc837935fcfd523ea996ca70bccd98c886cff67aa","observation_id":"10126db0-cc96-4bc8-a586-a5e93fd8da4b","resolution":{"observed_at":"2026-08-16T04:33:06.203546Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.210792Z","title":"A survey on evaluatio n of large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.210792Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:1b1050c3aee8bcfffec9da6af2e8104b8f6420d17ddb6b80298c29be40e1c92c","observation_id":"bc38e493-c4ae-4377-8787-32dda7140026","resolution":{"observed_at":"2026-08-16T04:33:06.210792Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.08419","last_updated":"2024-07-18T18:24:57Z","snapshot_observed_at":"2026-08-16T13:08:51.920120Z","submitted_at":"2023-10-12T15:38:28Z","title":"Jailbreaking Black Box Large Language Models in Twenty Queries","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.08419","snapshot_observed_at":"2026-08-16T04:33:06.214422Z","title":"Jailbreaking black box large language models in tw enty queries","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.214422Z"},"links":{"cited_paper":"/paper/2310.08419","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:f16058215a3b18dc20c5ed284cff46ad9873d9de7972421016263be518d672b6","observation_id":"25d9cb13-5084-4004-b4fb-666ef0475e3a","resolution":{"observed_at":"2026-08-16T04:33:06.214422Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.06363","last_updated":"2024-09-25T19:48:39Z","snapshot_observed_at":"2026-08-19T16:46:32.130363Z","submitted_at":"2024-02-09T12:15:51Z","title":"StruQ: Defending Against Prompt Injection with Structured Queries","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.06363","snapshot_observed_at":"2026-08-16T04:33:06.218907Z","title":"Stru q: Defend- ing against prompt injection with structured queries","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.218907Z"},"links":{"cited_paper":"/paper/2402.06363","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:6d08096e87a6310464a3473a9581cd278dc62802c79b3a225d692e35097d230d","observation_id":"a4d2085d-33bf-4df0-b823-6d95090b1dc7","resolution":{"observed_at":"2026-08-16T04:33:06.218907Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.223049Z","title":"Denoising adversari al autoen- coders","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.223049Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:f9aba2081239fff0ece32bda8b538354f2ca5a1334cfdbeb9795f4157fa351b4","observation_id":"31f21019-93a2-46b5-a84f-a84aecbf53cf","resolution":{"observed_at":"2026-08-16T04:33:06.223049Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.05778","last_updated":"2024-01-11T09:29:56Z","snapshot_observed_at":"2026-08-18T02:28:42.277659Z","submitted_at":"2024-01-11T09:29:56Z","title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.05778","snapshot_observed_at":"2026-08-16T04:33:06.226603Z","title":"Risk taxonomy, mitigation, and assess- ment benchmarks of large language model systems","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.226603Z"},"links":{"cited_paper":"/paper/2401.05778","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:f545db47287ea8456f38881e125ce5d5574cf3e93c07b30b180af1c5ae0315a4","observation_id":"87a2475c-dfaa-4bdf-98c6-a76bf7242767","resolution":{"observed_at":"2026-08-16T04:33:06.226603Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.230512Z","title":"Security and priva cy chal- lenges of large language models: A survey","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.230512Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:2ca6aa714ee78f7d3023c6e9627ae0853e5451cb37f8962b5512e032bd38eb21","observation_id":"739bd4af-e9e9-497a-8616-b44af9a634bd","resolution":{"observed_at":"2026-08-16T04:33:06.230512Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.12505","last_updated":"2023-10-19T06:15:05Z","snapshot_observed_at":"2026-08-19T18:27:00.936869Z","submitted_at":"2023-10-19T06:15:05Z","title":"Attack Prompt Generation for Red Teaming and Defending Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.12505","snapshot_observed_at":"2026-08-16T04:33:06.234002Z","title":"At- tack prompt generation for red teaming and defending large l anguage models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.234002Z"},"links":{"cited_paper":"/paper/2310.12505","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b1d37b2acbc4272f7b4fa948175bb2a5b3adbb1a4af9364f17c3ccc5c628e424","observation_id":"ae53b5b2-f96a-4e99-83b5-b77fb18fed7e","resolution":{"observed_at":"2026-08-16T04:33:06.234002Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.238075Z","title":"Masterkey: Automated jailbreaking of large language model chatbots, in: Proc","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.238075Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:1e9cbd597fc7fcaa2cdbdfa33af738f2a3ed03d07bd8eefbcd1e321a5412c35c","observation_id":"9d0a2118-9831-41c8-bb80-712bf8f215f9","resolution":{"observed_at":"2026-08-16T04:33:06.238075Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.242121Z","title":"A comprehensi ve sur- vey of attack techniques, implementation, and mitigation strategies in large language models, in: International Conference on Ubi quitous Security, Springer","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.242121Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:9e2717887493c0cdb10ccb3ec4c031df02fc6ffcb50b84352858eb7edfebf9c0","observation_id":"62633ba8-85fd-410d-838d-af5cc5a03607","resolution":{"observed_at":"2026-08-16T04:33:06.242121Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.245625Z","title":"Recent advance s in robust optimization: An overview","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.245625Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:6f1946bf6f025d2948c96a55e3d58089c212c304f6cabeddc5729e33fc21fad5","observation_id":"1d780866-3088-47c2-9f54-4f63a1fad5bb","resolution":{"observed_at":"2026-08-16T04:33:06.245625Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.249505Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.249505Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:53dc739a46af1ebb4514f24ccecab9b2ee2cf5bda296ec67630963609bba13cb","observation_id":"46f81ab0-1a0d-46af-8844-a5ef548ae397","resolution":{"observed_at":"2026-08-16T04:33:06.249505Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.252868Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.252868Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:af1a2f8dc5e8a836d49657f3361386be8da4472856c92b8c29144c59cc0f4809","observation_id":"ff52a8ad-ed36-4f9a-a701-b9b39a0181aa","resolution":{"observed_at":"2026-08-16T04:33:06.252868Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.707792Z","title":"The ethics of c hatgpt in medicine and healthcare: a systematic review on large language mod- els (llms)","venue":null,"work_id":"4b219b84-796b-407c-8bc8-561ac06dca49","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.260651Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ae24babc1d85db1432ddf6981db8d33f5ac5badb42e24d13e7b41d8f92c5c96d","observation_id":"bc5462db-3372-4955-b149-0dbdef650516","resolution":{"observed_at":"2026-08-16T04:33:07.712667Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.694777Z","title":"Cater: Intellectual property protection on text generation apis via conditional watermarks","venue":null,"work_id":"ed9a70f1-ee48-4ef2-8c78-7ca417366873","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.264120Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:24de9da0d5a37d52a960bed02244913345923261ff0b3de40930236b35225380","observation_id":"340c8833-e0e3-42c0-b24a-de58f63238d4","resolution":{"observed_at":"2026-08-16T04:33:07.699528Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.721863Z","title":"IEEE Transactions on Pattern Analysis and Ma chine Intelligence","venue":null,"work_id":"d506fab0-e21a-4b1e-853e-3dda9ea78fad","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.257262Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:645db1cfb579c242dc24bea4d71b0940ab6c1729a494de5f989ffaa4f352dfc7","observation_id":"1504c4a4-a586-43a1-827c-d93e70a58d78","resolution":{"observed_at":"2026-08-16T04:33:07.726345Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2205.12628","last_updated":"2022-10-20T05:30:43Z","snapshot_observed_at":"2026-08-17T14:09:03.289442Z","submitted_at":"2022-05-25T10:08:45Z","title":"Are Large Pre-Trained Language Models Leaking Your Personal Information?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2205.12628","snapshot_observed_at":"2026-08-16T04:33:06.271376Z","title":"Are large pre- trained lan- guage models leaking your personal information? arXiv prep rint arXiv:2205.12628","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.271376Z"},"links":{"cited_paper":"/paper/2205.12628","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:2d3affc5fad083da156e37d5766cc9afece6a31a1caae4a355a0f98c263a81b3","observation_id":"405b8f57-108f-4574-b03b-68d4bb27621d","resolution":{"observed_at":"2026-08-16T04:33:06.271376Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.00348","last_updated":"2025-04-23T01:35:19Z","snapshot_observed_at":"2026-08-17T16:58:11.267710Z","submitted_at":"2024-11-01T04:05:59Z","title":"Attention Tracker: Detecting Prompt Injection Attacks in LLMs","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.00348","snapshot_observed_at":"2026-08-16T04:33:06.274995Z","title":"Attention tracker: Detecting prompt injectio n attacks in llms","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.274995Z"},"links":{"cited_paper":"/paper/2411.00348","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:bb29f6c1aa411f51ed5f6e8c49246c978497542aa64e1d122afce6d0bab91312","observation_id":"2a30be89-fa7a-4a30-9b64-a94bf5829f2b","resolution":{"observed_at":"2026-08-16T04:33:06.274995Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.681807Z","title":"The use and misuse of pre-trained generative large language models in reli- ability engineering, in: 2024 Annual Reliability and Maint ainability Symposium (RAMS), IEEE","venue":null,"work_id":"0e2b9a01-eb99-4b3f-bf77-a5effc8174c0","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.267641Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:9f824eb0caa61535b50e74066ecf9c6ae1086a563435c04a10b2e6af47372f86","observation_id":"5b7138ac-0e2b-48cc-9d2b-eb2b1dbf9ec7","resolution":{"observed_at":"2026-08-16T04:33:07.686316Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2406.02044","last_updated":"2025-05-06T22:24:50Z","snapshot_observed_at":"2026-08-18T14:38:43.228255Z","submitted_at":"2024-06-04T07:27:36Z","title":"Towards Universal and Black-Box Query-Response Only Attack on LLMs with QROA","version":3},"cited_work":{"arxiv_id":"2406.02044","doi":null,"metadata_source":"pith","pith_arxiv_id":"2406.02044","snapshot_observed_at":"2026-08-16T04:33:07.093634Z","title":"Towards Universal and Black-Box Query-Response Only Attack on LLMs with QROA","venue":"cs.CL","work_id":"32b298f5-651f-40e2-a01c-6aca3472b830","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.285996Z"},"links":{"cited_paper":"/paper/2406.02044","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:c2af2830510171fa9e088205a708f554cf79745ab5ffa0da2248bc76d80fab21","observation_id":"18d6b38b-1fd9-4f4c-83c8-b394fcfc8d32","resolution":{"observed_at":"2026-08-16T04:33:07.098165Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.657807Z","title":"Feature selection and d imension- ality reduction: An extensive comparison in hand gesture cl assiﬁca- tion by semg in eight channels armband approach","venue":null,"work_id":"6eec30e8-dd87-4232-9451-4da0b3dea8f8","year":2020},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.289960Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:cab5d18531533798b046fc803f4c8fc1f183211faa9912612dfee6ec2ae962b4","observation_id":"00910e95-d765-4646-bb3e-f1011d0eb765","resolution":{"observed_at":"2026-08-16T04:33:07.662087Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.669700Z","title":null,"venue":null,"work_id":"67a26903-9844-464d-b63e-041e9b7d355c","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.279001Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:adbd1128a4e6c123ef5fb3dd9502ddbf7bcbed7532fe505aa4faed2482423778","observation_id":"c3f66716-35c7-4196-9d69-705d4caa622c","resolution":{"observed_at":"2026-08-16T04:33:07.673634Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.620655Z","title":"Common metadata framework: Int e- grated framework for trustworthy ai pipelines","venue":null,"work_id":"cd7ff98f-6b2b-4466-ae0a-e4fb4b798aa8","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.300380Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:8eeeaeaa1ddfb0f4604b451e8b4fe9e13d4d2678686fa8103098744465da0b31","observation_id":"6d528dbb-f9ba-4806-aad4-588db9aeaaf9","resolution":{"observed_at":"2026-08-16T04:33:07.624807Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1910.12366","last_updated":"2020-10-12T12:14:05Z","snapshot_observed_at":"2026-08-04T05:23:55.491806Z","submitted_at":"2019-10-27T22:09:13Z","title":"Thieves on Sesame Street! Model Extraction of BERT-based APIs","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1910.12366","snapshot_observed_at":"2026-08-16T04:33:06.304205Z","title":"Thieves on sesame street! model extraction of bert-based ap is","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.304205Z"},"links":{"cited_paper":"/paper/1910.12366","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:1d2adb226086802e8d54477f8e7c1341194127ffc4da44768dbfb07ecaae5a61","observation_id":"4d1c9a31-987b-4e01-81ef-22933583d5cd","resolution":{"observed_at":"2026-08-16T04:33:06.304205Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.607738Z","title":"A syntactic analysis of the sentence structure in motivational quotes u sing tree diagram for english learning","venue":null,"work_id":"677b04dc-4ef7-4138-b22d-987ccc60df20","year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.308797Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:fd849d009e3b1f01e24cfff5f8326491c7133792b364758d3d41fd2c3ad585a8","observation_id":"0ba5e84b-4e1c-4502-b538-18e1ce27e258","resolution":{"observed_at":"2026-08-16T04:33:07.612540Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.645488Z","title":null,"venue":null,"work_id":"2462cdcb-5499-43d6-964b-9d9777c7f939","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.293485Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:4692ad164ca17f9b699fc56a67ae3a90e68b748fc6703c3d95e4a371fe51f712","observation_id":"73d70622-7b9b-45ce-bb2c-78e59683c296","resolution":{"observed_at":"2026-08-16T04:33:07.649714Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.632510Z","title":null,"venue":null,"work_id":"ebc9fda2-22e0-44da-b4f6-364c4b7a35d0","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.296824Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b411156482b7c9e670401f501e13868c71f2dd7eb14686acef16b072cb9ba849","observation_id":"0557c7d6-23ba-4104-81f8-b20208b68f40","resolution":{"observed_at":"2026-08-16T04:33:07.636422Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.594929Z","title":null,"venue":null,"work_id":"553d1031-3649-466a-9484-8a65c7bf70dc","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.320062Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:2cf406f58e202d18c59638bf3619c8860f866dceb8715a5c2b1909ee59f09045","observation_id":"befa2a7a-53cd-41c1-becd-17c5b6bcbdda","resolution":{"observed_at":"2026-08-16T04:33:07.599489Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2311.03191","last_updated":"2024-11-28T13:43:50Z","snapshot_observed_at":"2026-08-18T06:50:23.685098Z","submitted_at":"2023-11-06T15:29:30Z","title":"DeepInception: Hypnotize Large Language Model to Be Jailbreaker","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.03191","snapshot_observed_at":"2026-08-16T04:33:06.328044Z","title":"Deep- inception: Hypnotize large language model to be jailbreake r","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.328044Z"},"links":{"cited_paper":"/paper/2311.03191","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ab1af565392babcf5c366c4a68aa2445a205417ae008225947b7ac0671a73fb7","observation_id":"8597a3ea-2a46-4069-958b-11ec07b4931f","resolution":{"observed_at":"2026-08-16T04:33:06.328044Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.16205","last_updated":"2025-06-18T02:41:56Z","snapshot_observed_at":"2026-08-16T13:31:54.315862Z","submitted_at":"2024-07-23T06:14:41Z","title":"LLMs can be Dangerous Reasoners: Analyzing-based Jailbreak Attack on Large Language Models","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.16205","snapshot_observed_at":"2026-08-16T04:33:06.331926Z","title":"Figure it out: Analyzing-based jailbreak attack on large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.331926Z"},"links":{"cited_paper":"/paper/2407.16205","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:5472c6a74dc9610715294b1414cd44823d449cb98b4c7cdb55ef3bf0c3dc4db0","observation_id":"8e69b909-4b90-43a4-b48f-d95eb8043776","resolution":{"observed_at":"2026-08-16T04:33:06.331926Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2404.0263","doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.061689Z","title":"Vocabulary attack to hij ack large lan- guage model applications","venue":null,"work_id":"b376234a-9f61-4d1f-9d34-ff585b7ba004","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.312387Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:444e24ee771b342dc1922769a83a8a7c7aa904f5c609c27cb6507fbbab6060b9","observation_id":"81a89f46-1cc0-4c3f-b9f5-3358b5886cde","resolution":{"observed_at":"2026-08-16T04:33:07.067821Z","resolver_source":"raw_fallback","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2310.10383","last_updated":"2024-09-30T11:58:27Z","snapshot_observed_at":"2026-08-16T14:51:46.668848Z","submitted_at":"2023-10-16T13:23:54Z","title":"Privacy in Large Language Models: Attacks, Defenses and Future Directions","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.10383","snapshot_observed_at":"2026-08-16T04:33:06.316131Z","title":"Privacy in large language models: Attacks, defen ses and future directions","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.316131Z"},"links":{"cited_paper":"/paper/2310.10383","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:6781c1a5b3da0627671aef52a97243add785611d0dbb0b07c214f7507aa91c65","observation_id":"633717d6-8800-4008-8306-e706709a39f1","resolution":{"observed_at":"2026-08-16T04:33:06.316131Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.04957","last_updated":"2024-03-07T23:46:20Z","snapshot_observed_at":"2026-08-18T14:37:14.606602Z","submitted_at":"2024-03-07T23:46:20Z","title":"Automatic and Universal Prompt Injection Attacks against Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.04957","snapshot_observed_at":"2026-08-16T04:33:06.348294Z","title":"Au tomatic and universal prompt injection attacks against large language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.348294Z"},"links":{"cited_paper":"/paper/2403.04957","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b992d7797e31606107b3d0bb2767f5ed593b4ca1858d518158770273a1ecd8cf","observation_id":"7d186fb6-8200-403b-9875-2475bfd5dcd9","resolution":{"observed_at":"2026-08-16T04:33:06.348294Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.16765","last_updated":"2024-01-30T06:04:04Z","snapshot_observed_at":"2026-08-16T14:23:22.820825Z","submitted_at":"2024-01-30T06:04:04Z","title":"A Cross-Language Investigation into Jailbreak Attacks in Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.16765","snapshot_observed_at":"2026-08-16T04:33:06.323833Z","title":"arXiv preprint arXiv:2401.16765","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.323833Z"},"links":{"cited_paper":"/paper/2401.16765","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:8a53041acf139f19d57edadc7403c0833edbc36ca7b63fccb4724114fc8f5116","observation_id":"10fb19f5-75cb-49de-a0c2-098fc5a2c72b","resolution":{"observed_at":"2026-08-16T04:33:06.323833Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.558616Z","title":"Jailbreaking chatgpt vi a prompt engineering: An empirical study","venue":null,"work_id":"d5f75421-362e-46df-b37e-36eddd5c7682","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.356558Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:e11822b77d4c7a9f6f16a452e2db42a17d25d6627d9a3975a3152e8cbb5d7245","observation_id":"0a2c1e36-a5e9-4f52-9525-64d45a70e3d0","resolution":{"observed_at":"2026-08-16T04:33:07.562631Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.547039Z","title":"Summary of chatgpt-related re search and perspective towards the future of large language models","venue":null,"work_id":"0119eabe-0e35-4c66-90dc-b4f79d00cc64","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.360627Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:1757d3d25c319e8ad42083391bab1c815cee007f14afd02865ded57aab8c1572","observation_id":"eaf8cbaa-bcfa-4522-8f51-5d3fc5776916","resolution":{"observed_at":"2026-08-16T04:33:07.550976Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.582831Z","title":null,"venue":null,"work_id":"fc10489f-821b-489d-9aef-262172029411","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.335926Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:601971ca674809762bd069f86ebaa0916e48c57099c07bc27b6ed27f7b71af6f","observation_id":"967d9a17-07b0-4ddf-9833-ee074c2ab3aa","resolution":{"observed_at":"2026-08-16T04:33:07.586903Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.524654Z","title":"Dee p learning- based anomaly detection in cyber-physical systems: Progre ss and op- portunities","venue":null,"work_id":"7a38b351-3c83-4c38-bc37-78f4280f0bf3","year":2021},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.367972Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:2c0707921f5b29112aa48a46fe577353ca621a777afdc5cf68c0115888ca1e1b","observation_id":"e95f2f02-4f72-4e60-acd5-c4b64c54d00d","resolution":{"observed_at":"2026-08-16T04:33:07.528534Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2310.04451","last_updated":"2024-03-20T21:34:56Z","snapshot_observed_at":"2026-08-16T14:36:14.029419Z","submitted_at":"2023-10-03T19:44:37Z","title":"AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.04451","snapshot_observed_at":"2026-08-16T04:33:06.344077Z","title":"Autodan: Gene rating stealthy jailbreak prompts on aligned large language model s","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.344077Z"},"links":{"cited_paper":"/paper/2310.04451","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:511b9111eaaf91b21b04c46367a703869153905c206936a630279074e1d843d4","observation_id":"39dafa90-7602-4ab3-9cd0-9f408d55717e","resolution":{"observed_at":"2026-08-16T04:33:06.344077Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.490948Z","title":"Robust ac- tive learning (roal): Countering dynamic adversaries in ac tive learn- ing with elastic weight consolidation","venue":null,"work_id":"9ecf0e71-5044-4d5f-8edf-0e4278937137","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.379360Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ff4fa824ac9240842885fe3063b451178e3cce44765396b608da3da6a46b99e1","observation_id":"a8442e6d-b6d3-452d-bd07-3f60178b30d3","resolution":{"observed_at":"2026-08-16T04:33:07.495495Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05499","last_updated":"2025-12-29T02:25:27Z","snapshot_observed_at":"2026-07-06T15:40:27.639368Z","submitted_at":"2023-06-08T18:43:11Z","title":"Prompt Injection attack against LLM-integrated Applications","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.05499","snapshot_observed_at":"2026-08-16T04:33:06.352277Z","title":"Prompt injection attack against llm-integrated applications","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.352277Z"},"links":{"cited_paper":"/paper/2306.05499","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:3300ea68f3e2bf915d5031e26e5ae1acf237757e5988eb1bd3799b732494040e","observation_id":"6c2aceea-23bd-43df-905d-8a958a50343b","resolution":{"observed_at":"2026-08-16T04:33:06.352277Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.479877Z","title":null,"venue":null,"work_id":"112e2fdd-d07f-4dd0-b9f6-96cda7b06321","year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.386972Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:dccc9b2385dffdb7740db7988cb9d4c9e2d4ef79b40ec35ba8432495de9bf9be","observation_id":"cbeb2873-820d-4c89-9c5d-7e128806de4d","resolution":{"observed_at":"2026-08-16T04:33:07.483846Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.10036","last_updated":"2023-06-02T06:56:29Z","snapshot_observed_at":"2026-08-16T15:32:25.394782Z","submitted_at":"2023-05-17T08:28:54Z","title":"Are You Copying My Model? Protecting the Copyright of Large Language Models for EaaS via Backdoor Watermark","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.10036","snapshot_observed_at":"2026-08-16T04:33:06.390831Z","title":", Xu, T., Sun, G., Xie, X., 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.390831Z"},"links":{"cited_paper":"/paper/2305.10036","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:8191cad53df39a349c6adea6d9f9651ecbdf0577d9f25e46ef090665c83cbf64","observation_id":"e2e860f1-0cc3-4a6a-9f45-4c6a9ff1f862","resolution":{"observed_at":"2026-08-16T04:33:06.390831Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.535360Z","title":"Fo rmalizing and benchmarking prompt injection attacks and defenses, in : 33rd USENIX Security Symposium (USENIX Security 24), pp","venue":null,"work_id":"a9ae5c5b-e4fc-4fba-b6bc-0fba6efc5a69","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.364155Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:7a541b8fa871f383ac276924a62d97c0828f44717360ba7561c9bf8e6b60ae31","observation_id":"f1e266bb-3a41-4352-aac2-335577e6d0b1","resolution":{"observed_at":"2026-08-16T04:33:07.539315Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2310.03684","last_updated":"2024-06-11T19:02:52Z","snapshot_observed_at":"2026-08-17T15:25:03.596568Z","submitted_at":"2023-10-05T17:01:53Z","title":"SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.03684","snapshot_observed_at":"2026-08-16T04:33:06.398286Z","title":"Sm oothllm: Defending large language models against jailbreaking atta cks","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.398286Z"},"links":{"cited_paper":"/paper/2310.03684","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:4b74da2e755c3b229e3ad58064c5ec2c6862f713f69011942e7e21d86958bc4f","observation_id":"3b12c9ec-57b9-4d16-9773-67418b987550","resolution":{"observed_at":"2026-08-16T04:33:06.398286Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.513660Z","title":null,"venue":null,"work_id":"a21226fb-7a37-407e-b3f4-21cd5a168569","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.372045Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:e04a052b44263900539df2d12a69426ff3b9cc03927fd4e13fa4814560eb15e0","observation_id":"d6147760-08e1-4506-b602-f8f995a4aec6","resolution":{"observed_at":"2026-08-16T04:33:07.517393Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.502483Z","title":"IEEE Communications Magazine","venue":null,"work_id":"3e5fd86f-9780-4152-bbba-8aafc80b5923","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.375556Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:c16a5178c18080805d11d40815b0a9f6e6b92e7c059113c46a5fa44d2c1daaa2","observation_id":"827fb7ca-133b-43d8-93bd-04f8374d2d69","resolution":{"observed_at":"2026-08-16T04:33:07.506779Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.11755","last_updated":"2024-02-19T00:53:48Z","snapshot_observed_at":"2026-08-16T14:17:31.356690Z","submitted_at":"2024-02-19T00:53:48Z","title":"SPML: A DSL for Defending Language Models Against Prompt Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.11755","snapshot_observed_at":"2026-08-16T04:33:06.413648Z","title":"Spml: A dsl for defending language models against prompt attacks","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.413648Z"},"links":{"cited_paper":"/paper/2402.11755","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:dd870af829e4867e5c4154af304b799a5f58d329389af587c5025745368e83bf","observation_id":"4e743713-326e-4aca-9eb0-3e147fa2272b","resolution":{"observed_at":"2026-08-16T04:33:06.413648Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.02365","last_updated":"2025-01-12T12:04:14Z","snapshot_observed_at":"2026-08-16T13:55:44.152485Z","submitted_at":"2024-05-03T06:41:48Z","title":"ModelShield: Adaptive and Robust Watermark against Model Extraction Attack","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.02365","snapshot_observed_at":"2026-08-16T04:33:06.383103Z","title":"Adaptive and ro- bust watermark against model extraction attack","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.383103Z"},"links":{"cited_paper":"/paper/2405.02365","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:193c9792ca5306430cddebb7c8f80ccd44ffb75dda2b05c8a13313a4ece62f3c","observation_id":"b6c02df9-1107-4b23-a82d-64c72bee3aa1","resolution":{"observed_at":"2026-08-16T04:33:06.383103Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.434133Z","title":null,"venue":null,"work_id":"070580cb-95a9-4a9c-9b09-5fcec3b34972","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.421666Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:4be30b6297dc4832ec3e29cc3ee2cd4a34ed4b06f93c7c9b129b8b1aa505acbe","observation_id":"d92ab055-67fd-4b3c-9b16-c83d99e34c7d","resolution":{"observed_at":"2026-08-16T04:33:07.438776Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.408537Z","title":"Signed-prompt: A new approach to prevent prompt Y","venue":null,"work_id":"df9c2ab2-53be-4271-81ee-79e4404d4fe5","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.428848Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:3e3744d5d7fa10ddad7b09312ff1e03057c7f9289b5ec8071b541d66e82cd3fd","observation_id":"08efc195-fe9c-4484-aa7d-9d7ee2124bd9","resolution":{"observed_at":"2026-08-16T04:33:07.412531Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.468733Z","title":"Ignore previous prompt: A ttack tech- niques for language models","venue":null,"work_id":"6d8aa5fb-5d21-4714-989f-f8c740605b91","year":2022},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.394558Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:5ce76a28569e87cd13fb44ba6725b3e77d362b0bada51d06cecae4a5e3aa5a7f","observation_id":"f40a670f-8d49-40c1-a4e8-5bb8323b1892","resolution":{"observed_at":"2026-08-16T04:33:07.472659Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1908.07125","last_updated":"2021-01-03T19:58:55Z","snapshot_observed_at":"2026-08-18T00:51:28.882719Z","submitted_at":"2019-08-20T01:51:40Z","title":"Universal Adversarial Triggers for Attacking and Analyzing NLP","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1908.07125","snapshot_observed_at":"2026-08-16T04:33:06.546327Z","title":"Universal adversarial triggers for attacking and analyzin g nlp","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.546327Z"},"links":{"cited_paper":"/paper/1908.07125","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:c861b404c8d4b6eb10a7fb2bf95d4fd12e0c76fc650eb4af0c9db54e71ba57ef","observation_id":"f64e81e3-8ce4-4720-ad58-6faeb1e15a21","resolution":{"observed_at":"2026-08-16T04:33:06.546327Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.00898","last_updated":"2024-01-31T19:52:00Z","snapshot_observed_at":"2026-08-16T14:22:44.256192Z","submitted_at":"2024-01-31T19:52:00Z","title":"An Early Categorization of Prompt Injection Attacks on Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.00898","snapshot_observed_at":"2026-08-16T04:33:06.402423Z","title":"B., 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.402423Z"},"links":{"cited_paper":"/paper/2402.00898","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ab0b0ba1fb13af913637059fd467777236de49c2637e2a6d7e03060426188d25","observation_id":"94232411-c09c-43c5-a0c4-dd62e82ac6cc","resolution":{"observed_at":"2026-08-16T04:33:06.402423Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.458046Z","title":null,"venue":null,"work_id":"888bf44d-b79e-4ac8-9447-f69bba42fdca","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.406407Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:cc31a3800b7fefe3356b994953341719d9ee292bd793fe188f35bf4bded97d66","observation_id":"c0d59d46-4494-42b7-9ef3-baec195da866","resolution":{"observed_at":"2026-08-16T04:33:07.461608Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.446498Z","title":null,"venue":null,"work_id":"6343b15c-1dcd-42a1-9cdf-23d8a4f475fc","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.410062Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:320e45e514fb421553258f2b281da28f4a05dbad65e6c5ec4e7d6834f05f3d4c","observation_id":"3c1a93b0-6d91-43b2-8b7d-fa717d7cd59e","resolution":{"observed_at":"2026-08-16T04:33:07.450893Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.373359Z","title":"Selfdefend: Llms can defend themselves against jailbreaking in a practical manner","venue":null,"work_id":"e47c078f-884f-4473-98f0-bf2cb0dfdc45","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.562543Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:1df4a0f33c35e679ef63ac725024e789b6f70fe52a45e0633a1c00d408be4722","observation_id":"1e2bbd07-f08a-4e9b-83ce-dc02a4e62314","resolution":{"observed_at":"2026-08-16T04:33:07.377445Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2310.10844","last_updated":"2023-10-16T21:37:24Z","snapshot_observed_at":"2026-08-18T18:53:04.197145Z","submitted_at":"2023-10-16T21:37:24Z","title":"Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.10844","snapshot_observed_at":"2026-08-16T04:33:06.417707Z","title":"Survey of vulnerabilities in large lang uage mod- els revealed by adversarial attacks","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.417707Z"},"links":{"cited_paper":"/paper/2310.10844","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:397aaf2e41719082ccb88d04d779ff80912b8f26be39f82810367eadb3b5b821","observation_id":"f721ed67-26a5-41c3-b3ac-29d3ff93dab9","resolution":{"observed_at":"2026-08-16T04:33:06.417707Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.337776Z","title":"Jailbro ken: How does llm safety training fail? Advances in Neural Information Pr ocessing Systems 36, 80079–80110","venue":null,"work_id":"73f8d9de-3421-4082-a3b1-a53a25e1689f","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.573876Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:85f8bdd8332955bca5e2907b44c15bc6918ac2048f67e6553968c5ee65377d7a","observation_id":"f96e205b-6428-4536-9398-469f8946115e","resolution":{"observed_at":"2026-08-16T04:33:07.341799Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.420235Z","title":null,"venue":null,"work_id":"9ac5abd4-975a-4250-b225-88401f646d4c","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.425070Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:dfa8a8925a28980fdd161593560d85422909c2f0eb3ad0882dde5e5654bea76a","observation_id":"b66060d9-27ed-4b11-a3d7-167291a1a766","resolution":{"observed_at":"2026-08-16T04:33:07.425907Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2311.09127","last_updated":"2024-01-20T18:55:51Z","snapshot_observed_at":"2026-08-16T14:43:00.431429Z","submitted_at":"2023-11-15T17:17:39Z","title":"Jailbreaking GPT-4V via Self-Adversarial Attacks with System Prompts","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.09127","snapshot_observed_at":"2026-08-16T04:33:06.581334Z","title":"Jailbrea king gpt- 4v via self-adversarial attacks with system prompts","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.581334Z"},"links":{"cited_paper":"/paper/2311.09127","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:4bdcc65f3f647e3a06c08552eee9ab6fe35bd9cb3e68a73ec07f05349d4debc8","observation_id":"198e8267-efac-4575-ba90-0152e94eac2f","resolution":{"observed_at":"2026-08-16T04:33:06.581334Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.396668Z","title":"Meta-learning appr oaches for learning-to-learn in deep learning: A survey","venue":null,"work_id":"a7935afd-1273-432f-9aeb-abc1121892b3","year":2022},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.541456Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:fe8412641a452fbd3f794b7dd5961a38c6aaf090941fc9db49c253378a2917f8","observation_id":"b9fb5e5a-1564-4fc1-8bd5-9013feeb2ac7","resolution":{"observed_at":"2026-08-16T04:33:07.400843Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.13494","last_updated":"2024-05-29T21:45:35Z","snapshot_observed_at":"2026-08-16T14:16:45.543749Z","submitted_at":"2024-02-21T03:09:21Z","title":"GradSafe: Detecting Jailbreak Prompts for LLMs via Safety-Critical Gradient Analysis","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.13494","snapshot_observed_at":"2026-08-16T04:33:06.588648Z","title":"Gradsafe: Dete cting unsafe prompts for llms via safety-critical gradient analysis","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.588648Z"},"links":{"cited_paper":"/paper/2402.13494","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:d0e570e53508e38aaa5c8482d7551d658510e3de01b1caac3246fd75a0bd2f33","observation_id":"61817e8a-8040-48b7-9232-69bc1a83c62c","resolution":{"observed_at":"2026-08-16T04:33:06.588648Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2004.15015","last_updated":"2021-01-03T19:05:24Z","snapshot_observed_at":"2026-07-06T09:16:40.349439Z","submitted_at":"2020-04-30T17:56:49Z","title":"Imitation Attacks and Defenses for Black-box Machine Translation Systems","version":3},"cited_work":{"arxiv_id":"2004.15015","doi":null,"metadata_source":"pith","pith_arxiv_id":"2004.15015","snapshot_observed_at":"2026-08-16T04:33:06.807532Z","title":"Imitation Attacks and Defenses for Black-box Machine Translation Systems","venue":"cs.CL","work_id":"31d76d90-1fcb-4b4c-9166-2aca8163d5d5","year":2020},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.550246Z"},"links":{"cited_paper":"/paper/2004.15015","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:8609af1c41a7358f35bec35ea16238fc36537c9c90ecb9eb1f43e63d0c8d6388","observation_id":"0c46fe94-1233-46ab-9742-2b8943c081db","resolution":{"observed_at":"2026-08-16T04:33:06.815448Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2305.14950","last_updated":"2023-10-14T05:03:53Z","snapshot_observed_at":"2026-08-16T15:30:15.719150Z","submitted_at":"2023-05-24T09:40:56Z","title":"Adversarial Demonstration Attacks on Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.14950","snapshot_observed_at":"2026-08-16T04:33:06.554430Z","title":"Adversarial demonstration attacks on large language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.554430Z"},"links":{"cited_paper":"/paper/2305.14950","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:dcc67551c2903e3025d5b3ddcf00edd9fef6c7964b69f779f924dc77fd9c29ea","observation_id":"552e3aae-d3ef-4ef2-ac81-0986ab334d73","resolution":{"observed_at":"2026-08-16T04:33:06.554430Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.384943Z","title":"A multiobje ctive learn- ing and ensembling approach to high-performance speech enh ance- ment with compact neural network architectures","venue":null,"work_id":"7ec475a6-7cb5-4104-bbf8-0ce85840bf16","year":2018},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.558581Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:31129770dae78ac46759a13d1ee9105481149a536d2cfdfe1d4c0d5551a1eae9","observation_id":"fd08f14a-4a63-4bf1-927d-647bb7f4b3be","resolution":{"observed_at":"2026-08-16T04:33:07.389147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.19200","last_updated":"2025-06-12T13:56:26Z","snapshot_observed_at":"2026-08-16T14:14:07.997376Z","submitted_at":"2024-02-29T14:30:28Z","title":"PRSA: Prompt Stealing Attacks against Real-World Prompt Services","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.19200","snapshot_observed_at":"2026-08-16T04:33:06.606888Z","title":", Wang, Z., 2024b","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.606888Z"},"links":{"cited_paper":"/paper/2402.19200","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:194ffc92c8c2778a49cdccd4cfd550de360b19fcb23a3b1836fbe7bd7732c981","observation_id":"5ff8918c-7b5a-4bd7-a687-0a0642c7e721","resolution":{"observed_at":"2026-08-16T04:33:06.606888Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.361337Z","title":null,"venue":null,"work_id":"ce13ddc4-1086-4306-8d6e-2bec88c084ba","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.566447Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:e29c4c409f06856a9ad54e307811c7a4ba30a3176737d67b0911afff9bff680d","observation_id":"5b32a7f3-8149-4f5e-a174-d41f43e3d073","resolution":{"observed_at":"2026-08-16T04:33:07.365493Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2309.10253","last_updated":"2024-06-27T16:01:27Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-09-19T02:19:48Z","title":"GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.10253","snapshot_observed_at":"2026-08-16T04:33:06.614789Z","title":"Gptfuzzer: Red teaming large lan- guage models with auto-generated jailbreak prompts","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.614789Z"},"links":{"cited_paper":"/paper/2309.10253","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ccffc208e52ca2d31b4ea76154e854e472dd863ac4baf763baffbea7b82a3d4b","observation_id":"52bc5694-e826-424c-8a44-153e8f8b106a","resolution":{"observed_at":"2026-08-16T04:33:06.614789Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.11538","last_updated":"2024-05-25T05:32:39Z","snapshot_observed_at":"2026-08-16T14:41:58.337813Z","submitted_at":"2023-11-20T04:56:46Z","title":"Assessing Prompt Injection Risks in 200+ Custom GPTs","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.11538","snapshot_observed_at":"2026-08-16T04:33:06.618480Z","title":"Assessi ng prompt injection risks in 200+ custom gpts","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.618480Z"},"links":{"cited_paper":"/paper/2311.11538","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ca844d44e165d7f67c15b230c651c148cbd36ab14a5f8aaab16a28f4939a88cf","observation_id":"02d318c2-9be3-4d71-b8c6-4901eb006cb9","resolution":{"observed_at":"2026-08-16T04:33:06.618480Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.06387","last_updated":"2024-05-25T07:01:15Z","snapshot_observed_at":"2026-08-16T14:53:33.115609Z","submitted_at":"2023-10-10T07:50:29Z","title":"Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.06387","snapshot_observed_at":"2026-08-16T04:33:06.577405Z","title":"Jailbreak and guard a ligned lan- guage models with only few in-context demonstrations","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.577405Z"},"links":{"cited_paper":"/paper/2310.06387","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:afb5a552eeee3e538bbd346f822d10364b57dc0f7bbaa75eee300753d726cc65","observation_id":"5cd12cf8-ef86-4a7c-b00c-6289a1ee42e6","resolution":{"observed_at":"2026-08-16T04:33:06.577405Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.263178Z","title":"Gener ate adversar- ial examples by adaptive moment iterative fast gradient sig n method","venue":null,"work_id":"ee963f48-5d23-42d8-8d5a-21426df02300","year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.626286Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:7731f7eaa2304ba47e76a3c9e1b923be4a2cd4549cf0fb75304ef36852b29cfa","observation_id":"1cb6eeed-9865-4377-a9a8-48d40f44dc71","resolution":{"observed_at":"2026-08-16T04:33:07.267398Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.08424","last_updated":"2024-09-30T14:25:39Z","snapshot_observed_at":"2026-08-18T03:04:46.346329Z","submitted_at":"2024-03-13T11:16:43Z","title":"Distract Large Language Models for Automatic Jailbreak Attack","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.08424","snapshot_observed_at":"2026-08-16T04:33:06.585083Z","title":"Tastle: Dis tract large language models for automatic jailbreak attack","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":77,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.585083Z"},"links":{"cited_paper":"/paper/2403.08424","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:a609e62e6df24af936430af70bacad52bc1e52c263cb2ba7aaa2ea0ab1819e5c","observation_id":"99fe5dd2-8c1a-48c5-bc71-3a11a9ff58f3","resolution":{"observed_at":"2026-08-16T04:33:06.585083Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.237547Z","title":"Anomaly detection wit h robust deep autoencoders, in: Proceedings of the 23rd ACM SIGKDD in - ternational conference on knowledge discovery and data min ing, pp","venue":null,"work_id":"f1123ce8-fb17-4647-87ae-d19f8291fb25","year":2017},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":78,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.633720Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:6b1181ef0796eb67e51b7f2cf0d89f53ea19a340fb77ed4bc255211f2e23c067","observation_id":"9cf56bac-71ae-4d3f-a8b1-21c1c05e3c92","resolution":{"observed_at":"2026-08-16T04:33:07.242272Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.325354Z","title":null,"venue":null,"work_id":"7bcb65a5-2b62-482d-a7a4-2ed66180ec58","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":79,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.592556Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:bb5b37af025557a796a2b291c852fac7fb9779b214f63528d22514f90d9cde9c","observation_id":"edd64977-826f-4de4-b602-58e2a8129c93","resolution":{"observed_at":"2026-08-16T04:33:07.329235Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.313931Z","title":"Nature Machine Intelligence 5, 1486–1496","venue":null,"work_id":"09a58593-d571-4351-84c4-08227f0e3b48","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":80,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.595976Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b4c449133d5457778fa1acc59bfb82dc3d4f72d2449e501a82f60d7271efb453","observation_id":"77cd5880-92c3-4557-9f96-a67fa6710e69","resolution":{"observed_at":"2026-08-16T04:33:07.317903Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.301403Z","title":"Practical and ethical cha llenges of large language models in education: A systematic scoping review","venue":null,"work_id":"881b4971-9b42-4cf5-a043-e9ba7218e67b","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.599329Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:ef4dc66edcc6651bbe30913dc4e846b94bf760aec2751fcd6bc904475ac00c8e","observation_id":"f7753098-8a0b-4b0f-b287-894aac59259f","resolution":{"observed_at":"2026-08-16T04:33:07.306011Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.288622Z","title":"Harnessing the power of llms in practi ce: A survey on chatgpt and beyond","venue":null,"work_id":"9eb8d20b-7120-4bef-afaa-b8266e37696e","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":82,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.603115Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:d001121040319dbb9f2ddf3a698a63d636d7d46e7347ab977f181974649db591","observation_id":"55e84324-706e-4116-a7db-01138fca41ac","resolution":{"observed_at":"2026-08-16T04:33:07.292848Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.275691Z","title":"Poisonprompt: Backdoor attack on prompt-based large language models, in: ICASSP 2024-2024 I EEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE","venue":null,"work_id":"c8f362c5-b985-4be5-962f-9acea5f948b8","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":84,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.610981Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:cab6f849374eaac78cacff03179739a9628421dc53e83f1eaa39518392d48ae0","observation_id":"c9760144-526a-41ed-9fa2-a78c24e6ccdc","resolution":{"observed_at":"2026-08-16T04:33:07.279947Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.04783","last_updated":"2024-11-14T18:14:00Z","snapshot_observed_at":"2026-08-18T06:55:39.053097Z","submitted_at":"2024-03-02T16:52:22Z","title":"AutoDefense: Multi-Agent LLM Defense against Jailbreak Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.04783","snapshot_observed_at":"2026-08-16T04:33:06.622439Z","title":"Autod efense: Multi-agent llm defense against jailbreak attacks","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":87,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.622439Z"},"links":{"cited_paper":"/paper/2403.04783","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:26e9d6534923b8760bf5f9b8150a9062b790dd5f9a2e1417fdeea75a4a89e517","observation_id":"c252686f-dd82-4de3-9377-8ba484070689","resolution":{"observed_at":"2026-08-16T04:33:06.622439Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.250504Z","title":"Protecting language generation models via invisible watermarking, in: International Conf erence on Machine Learning, PMLR","venue":null,"work_id":"207f4976-2bc3-46f1-8b85-f7150dfb333c","year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":89,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.629939Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:202394b23569e51cd9c6e641358b3f9572ef5af3377c35d015570e63c92080fa","observation_id":"fc31aad5-7740-4fb6-a81f-cf9d4fb56182","resolution":{"observed_at":"2026-08-16T04:33:07.254974Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.223315Z","title":"Risks of discrimination violence and un lawful actions in llm-driven robots","venue":null,"work_id":"a52157f1-bd13-4674-99e3-9d357754391c","year":2024},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":91,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.637519Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:be8711ad72649041b4e30be2ef17f7450a881913fe90fc2444b0b1bdfdd81e91","observation_id":"a2bed685-b5a7-406b-ab66-71fb157f5c9c","resolution":{"observed_at":"2026-08-16T04:33:07.227799Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-08-12T09:06:50.363435Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-16T04:33:06.641038Z","title":"Universal and transferable adversarial attacks o n aligned language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":92,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.641038Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:cc29dcfda594194c6c041b9d0b504aec42077f2794d900261d37a893dafd8a36","observation_id":"b75629ad-6076-4a30-8f69-f34a44dc48d2","resolution":{"observed_at":"2026-08-16T04:33:06.641038Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.570116Z","title":"Proceedin gs of the IEEE 108, 2214–2231","venue":null,"work_id":"f8fa1511-99c0-4c5c-b3b8-a12479beabf3","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2020,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.340297Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:3df653ac3967cd2c6e71bf76852e6f474e96496687fb5ef454233f4bb1bd52b1","observation_id":"8e018281-8599-4447-8c42-15e71a133fd2","resolution":{"observed_at":"2026-08-16T04:33:07.573818Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.207280Z","title":"2633– 2650","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2021,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.207280Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:b4cc1a0ce9bf754c8de9a87505c3c3483fd6e2198bbf3c90e567996578012e05","observation_id":"aa99a021-045a-488a-b1c4-de3c76349811","resolution":{"observed_at":"2026-08-16T04:33:06.207280Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:07.349643Z","title":"10379– 10388","venue":null,"work_id":"fbddc751-2b64-41e4-91e8-4b7061bcc4ab","year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.570028Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:bf87fe32c57f6da2fea7ffb0992af94fcea6d70e46784803db1882c116d1b9ae","observation_id":"07f3387d-9471-450a-bd5f-56e8a4f66e47","resolution":{"observed_at":"2026-08-16T04:33:07.353654Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2309.00614","last_updated":"2023-09-04T17:47:36Z","snapshot_observed_at":"2026-07-06T16:13:23.343694Z","submitted_at":"2023-09-01T17:59:44Z","title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2309.00614","snapshot_observed_at":"2026-08-16T04:33:06.282306Z","title":"arXiv preprint arXiv:2309.00614","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.282306Z"},"links":{"cited_paper":"/paper/2309.00614","citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:2fe649ff5718c44aeffb8d15014bb7afef27870bd57afab1546bc2c3413e48ef","observation_id":"e22a8fd0-2dae-4e0e-8a66-f79dd5ab2521","resolution":{"observed_at":"2026-08-16T04:33:06.282306Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-16T04:33:06.187461Z","title":"arXiv preprint arXiv:240 4.16251","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives","version":1},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-16T04:33:06.187461Z"},"links":{"citing_paper":"/paper/2505.00976"},"observation_digest":"sha256:8cf253bcfc1816c3335e13494d09af9c137efdb2691caca4e19d1d000902339c","observation_id":"f9002336-a86f-4ffa-942f-1c6bcbdc8216","resolution":{"observed_at":"2026-08-16T04:33:06.187461Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2505.00976","last_updated":"2025-05-02T03:37:52Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-19T11:53:04.756231Z","submitted_at":"2025-05-02T03:37:52Z","title":"Attack and defense techniques in large language models: A survey and new perspectives"},"reference_resolution":{"displayed":92,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":60,"verified_exact":3,"verified_fuzzy":29},"total_outbound_references":92},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"thesis":"As of 19 August 2026, this Paper Citation Record lists 92 of 92 outbound references and 6 inbound Pith citation observations for arXiv:2505.00976."}