Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-15T23:36:01.163570Z
Paper Citation Record · LEDGER
As of 18 August 2026, this Paper Citation Record lists 61 of 61 outbound references and 2 inbound Pith citation observations for arXiv:2505.04673.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-15T23:36:01.163570Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-02T23:16:36.682289Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-05-11T22:11:14.069836Z
61 of 61 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 2372d5ee-7081-44f0-8df0-f25d95aa2df6 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Phi-3 technical report: A highly capable language model locally on your phone, 2024
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 48a516ca-e40e-497c-89ed-d4fa57b437c1 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 47a98ffb-9fb4-433b-a014-9e1c0adcd38e · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Image H ijacks: Adversarial images can control generative models at runtime
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 5550279d-2f90-48d5-9708-77d1ac0536e8 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM The dark side of language models: Exploring the potential of LLM s in multimedia disinformation generation and dissemination
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation bdb41b61-e870-47a6-8159-099eb3e5142d · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Easily accessible text-to-image generation amplifies demographic stereotypes at large scale
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 87a81ea1-e6e3-4302-947d-adb633e63310 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Distilling adversarial prompts from safety benchmarks: Report for the A dversarial N ibbler C hallenge
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 2c8229d2-d390-4361-8ffd-d3a3ebe5047b · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems , 36, 2023
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation b25722db-b863-4da2-85d8-4a4e2557be9a · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM A survey on adversarial attacks and defences
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 83808a87-d0ed-46a9-bf71-4f808a0b41a3 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aad88ebe-9bd5-4d67-a113-0c3931a5c8dc · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Leveraging the context through multi-round interactions for jailbreaking attacks, 2024
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation d4397a30-703e-47c1-a722-72d383601818 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Dall- E val: Probing the reasoning skills and social biases of text-to-image generation models
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation e085f569-71fc-4b7e-b728-73d2c5e34292 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Training verifiers to solve math word problems, 2021
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 4ace2c42-49cf-4d13-89e1-ad431fcdb04a · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Towards safer generative language models: A survey on safety risks, evaluations, and improvements, 2023
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 9fe23c88-b7dd-4b71-9535-8c925f49685c · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM How Robust is Google's Bard to Adversarial Image Attacks?
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d9973e3f-764d-4c42-9752-982c0cbd4bd6 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Attacks, defenses and evaluations for LLM conversation safety: A survey
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation b51987b6-11e6-4841-b5ec-5e8289c5b633 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM ROBBIE : Robust bias evaluation of large generative language models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 1d9547d3-307b-4888-9c84-c4832b70f0ad · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aea58e4f-8da1-4351-9eab-4a85a2103550 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM [Online; accessed 05-October-2024]
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 02a18049-04bc-43a2-9aaa-e8992ccd1e1b · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM MLLMG uard: A multi-dimensional safety evaluation suite for multimodal large language models, 2024
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation cd1f4572-39f2-43cb-bf5a-500c313d6112 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Harm Amplification in Text-to-Image Models
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 396f1031-cb72-4e8b-8f1d-9a8403c78231 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Evil P rompt F uzzer: generating inappropriate content based on text-to-image models
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 5dc5bbcb-2efd-416f-ae5f-1332e53c2f77 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM VLSBench: Unveiling Visual Leakage in Multimodal Safety
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41fe0290-f5e6-450d-b575-5f2c41672e41 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Cornwell, Nicole S
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 4b2c054c-5e2b-415d-820b-f8314af59631 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM LLM defenses are not robust to multi-turn human jailbreaks yet, 2024
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 295c2b7b-39a2-4492-8f95-db11a3c980c9 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Images are A chilles' heel of alignment: Exploiting visual vulnerabilities for jailbreaking multimodal large language models, 2024
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation ff1ed617-cf5c-44bc-a4c0-27f671e016a5 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Holistic evaluation of language models
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 850ad2b9-03f8-4803-bbc3-0aaf1d9a6ecc · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM VL-Trojan: Multimodal Instruction Backdoor Attacks against Autoregressive Visual Language Models
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d1ef7b5b-9ecc-4401-a847-952e7c867919 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Delving into transferable adversarial examples and black-box attacks
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 4150a70b-a954-4d94-a51a-053aae5247e3 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM A survey of attacks on large vision-language models: Resources, advances, and future trends, 2024
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 2223b08f-5ea8-4a2a-86b6-e711f21453a9 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Safety of multimodal large language models on images and text
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation ba83cc34-a509-4fa1-a232-fa15bae9940a · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Unresolved cited work
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 85e058f3-da95-4bbc-ad77-53495dfcf1d9 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM MM - S afetybench: A benchmark for safety evaluation of multimodal large language models
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 2f441fce-e5c0-4540-ad47-130bd4c51eb9 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM [Online; accessed 31-December-2024]
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 08fd376c-700e-4510-b3f5-15ee6f6cd599 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM JailBreakV: A Benchmark for Assessing the Robustness of MultiModal Large Language Models against Jailbreak Attacks
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation df17114a-f348-44cf-b49b-b5e5fe0b8f6b · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Visual-RolePlay: Universal Jailbreak Attack on MultiModal Large Language Models via Role-playing Image Character
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24d95985-8c56-41a4-9153-91cac18dfdbf · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Announcing microsoft copilot, your everyday ai companion - the official microsoft blog, 11 2023
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 343593da-3519-4c35-aee5-64fa2e339303 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Jailbreaking Attack against Multimodal Large Language Model
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d9cf6cd2-5163-4e40-bcb4-2255d29aadbf · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Automating Customer Service using LangChain: Building custom open-source GPT Chatbot for organizations
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bae6b810-12aa-41a6-b283-86d77f970c80 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM [Online; accessed 05-January-2025]
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 38dfb18d-45e2-45e5-889d-462ea2233bf6 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Visual adversarial examples jailbreak aligned large language models
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation e64c1b0a-1fa3-440e-879f-c31e1c13123c · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Unsafe diffusion: On the generation of unsafe images and hateful memes from text-to-image models
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 5e6a4370-cbf8-4977-98f5-08c30578c994 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Adversarial N ibbler: An open red-teaming method for identifying diverse harms in text-to-image generation
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 505a22bf-59bc-4e97-90e0-069b3bb34dd2 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 01ac96f5-a074-4c35-92ce-a22bc80d5f0f · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Assessment of Multimodal Large Language Models in Alignment with Human Values
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0e91b285-e53d-416b-8fa0-571fd765f467 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Imgtrojan: Jailbreaking vision-language models with ONE image
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc49285e-9cfd-4a96-b0f4-82a6dcd0cb4f · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context, 2024
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c05b9d81-11c6-4893-9f33-3733c3f174f7 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM ALERT : A comprehensive benchmark for assessing large language models' safety through red teaming, 2024
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation f40b87ec-6283-4cc3-8247-c58d55d65103 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM How Many Unicorns Are in This Image? A Safety Evaluation Benchmark for Vision LLMs
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 75456340-9d0d-413b-8d49-5c5e808aeab2 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM ToViLaG: Your Visual-Language Generative Model is Also An Evildoer
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 55f0483d-f863-4091-8bab-74a92c058ab2 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation faf74bb5-3383-4e00-b762-3e72e7682dd1 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Sociotechnical safety evaluation of generative AI systems, 2023
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation e9945fb7-48dc-416e-b608-1f4c2cbc526d · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Vision-Language Models: Unlocking the future of multimodal AI , 12 2024
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 4fe39c17-d9e7-4e30-817f-f419e3633f83 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Adversarial attacks and defenses in images, graphs and text: A review
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation f1b9bbe3-33fc-4e7a-b605-36c0cb05519d · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Viassist: Adapting multi-modal large language models for users with visual impairments, 2024
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 036e7825-fc34-46d0-bf73-6f22e4389baa · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Chain of attack: a semantic-driven contextual multi-turn attacker for LLM , 2024
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation d62abf6c-e3a1-4a8c-8a7c-c4f1eca6f15a · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Sneakyprompt: Jailbreaking text-to-image generative models
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation c46a4fdc-382a-4cba-9e48-9af2e9b7f6be · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt
Reference 57
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 88c7ec34-432e-40ac-a724-9ade7997f920 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 11317825-d672-4d24-bda2-2901ae2e76c4 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Xing, Joseph E
Reference 59
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41966232-8d32-41d4-8b75-b14f35606361 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM Speak out of turn: Safety vulnerability of large language models in multi-turn dialogue, 2024
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.
Observation 0842f708-8c28-4f6f-a1d5-0a74301cfa04 · outbound
REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM write newline
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1173e618-490e-49e9-90bd-8aa57e633551 · inbound
Multi-Turn Adaptive Prompting Attack on Large Vision-Language Models REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 44b637bf-86dd-49d5-ad06-3f37d12b7ea1 · inbound
Jailbreaking Frontier Foundation Models Through Intention Deception REVEAL: Multi-turn Evaluation of Image-Input Harms for Vision LLM
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.