{"as_of":"2026-08-21T04:11:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:76842306e1a1f01a555bf9431f3a8c27f86ee030a8543cb6dfe8b4180c552512","coverage":[{"denominator":33,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":33,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T00:57:13.807101Z","state":"measured"},{"denominator":38,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":38,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-20T06:33:59.587034+00:00","state":"measured"},{"denominator":5,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":5,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T14:01:41.521564Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-18T08:16:06.518951Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.12430","snapshot_observed_at":"2026-08-04T14:58:40.973955Z","title":"Pushing the limits of safety: A technical report on the atlas challenge 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.22415","last_updated":"2026-07-15T06:42:59Z","snapshot_observed_at":"2026-08-17T15:37:22.862610Z","submitted_at":"2025-09-26T14:39:13Z","title":"Evidence Recomposition and Predictive Context Residualization for Visual Attribution in Multimodal Large Language Models","version":4},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-08-04T14:58:40.973955Z"},"links":{"cited_paper":"/paper/2506.12430","citing_paper":"/paper/2509.22415"},"observation_digest":"sha256:1de3eb6fd9a9ad6618b11a9a649947b6b8a1a7b2363b943667422050368ca4e6","observation_id":"d959c428-ffb2-4b39-a8e2-ed0d461d1b1f","resolution":{"observed_at":"2026-08-04T14:58:40.973955Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"cited_work":{"arxiv_id":"2506.12430","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2506.12430","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2506.12430 (2025)","venue":null,"work_id":"c14725ba-ce02-4621-89e6-c60f13e4f27a","year":2025},"citing_paper":{"arxiv_id":"2510.10073","last_updated":"2026-04-14T02:53:37Z","snapshot_observed_at":"2026-08-19T14:01:44.473863Z","submitted_at":"2025-10-11T07:18:12Z","title":"SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents","version":2},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-05-18T08:14:51.102085Z"},"links":{"cited_paper":"/paper/2506.12430","citing_paper":"/paper/2510.10073"},"observation_digest":"sha256:454a4768ae3756c339f76c3a94976cd0a0d08fad6b662f1653f4fec855dbc11d","observation_id":"5db08660-b4bb-4fc9-ac48-6ec409bfe460","resolution":{"observed_at":"2026-05-18T08:16:06.521830Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"cited_work":{"arxiv_id":"2506.12430","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2506.12430","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2506.12430 (2025)","venue":null,"work_id":"c14725ba-ce02-4621-89e6-c60f13e4f27a","year":2025},"citing_paper":{"arxiv_id":"2604.04488","last_updated":"2026-04-06T07:27:04Z","snapshot_observed_at":"2026-08-16T22:50:02.447684Z","submitted_at":"2026-04-06T07:27:04Z","title":"A Patch-based Cross-view Regularized Framework for Backdoor Defense in Multimodal Large Language Models","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-05-10T20:14:02.553313Z"},"links":{"cited_paper":"/paper/2506.12430","citing_paper":"/paper/2604.04488"},"observation_digest":"sha256:8b78fbceaeb9dd59420ad65b30215980562a2fa14d63bdfbc2b20449395add8f","observation_id":"b3ab311e-9aff-4b77-873c-ea444aa4f29d","resolution":{"observed_at":"2026-05-10T22:05:49.310638Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.12430","snapshot_observed_at":"2026-07-30T19:40:15.494000Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2607.26836","last_updated":"2026-07-29T12:26:41Z","snapshot_observed_at":"2026-08-19T04:17:08.807255Z","submitted_at":"2026-07-29T12:26:41Z","title":"Before Agents Speak: Pre-hoc Failure Risk Inference in Multi-Agent Systems","version":1},"reference_index":96,"source":"arxiv_source","source_observed_at":"2026-07-30T19:40:15.494000Z"},"links":{"cited_paper":"/paper/2506.12430","citing_paper":"/paper/2607.26836"},"observation_digest":"sha256:fe9372c01ff60599b537378b96462020b5b8240f4407aa8649bdb8638d06eb89","observation_id":"b46e91eb-d5d8-4892-a19e-6cdca8a2adfd","resolution":{"observed_at":"2026-07-30T19:40:15.494000Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.12430","snapshot_observed_at":"2026-08-12T14:01:41.521564Z","title":"Pushing the limits of safety: A tech- nical report on the atlas challenge 2025.arXiv preprint arXiv:2506.12430, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.10933","last_updated":"2026-08-11T14:01:24Z","snapshot_observed_at":"2026-08-20T07:22:54.467247Z","submitted_at":"2026-08-11T14:01:24Z","title":"SafeCA: Safe Cross-Attention Localization and Regulation for Text-to-Video Jailbreak Defense","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-12T14:01:41.521564Z"},"links":{"cited_paper":"/paper/2506.12430","citing_paper":"/paper/2608.10933"},"observation_digest":"sha256:05051cd0c2ad3338f828978ee64dab0fa03377dbf466463093772f37d320e2cf","observation_id":"f9a84e0f-5891-4928-8125-6b618b3d553f","resolution":{"observed_at":"2026-08-12T14:01:41.521564Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2506.12430/citation-record","integrity":"/paper/2506.12430/integrity","json":"/paper/2506.12430/citation-record.json","paper":"/paper/2506.12430"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2410.02355","last_updated":"2025-04-22T16:15:47Z","snapshot_observed_at":"2026-08-20T17:53:55.997357Z","submitted_at":"2024-10-03T10:06:27Z","title":"AlphaEdit: Null-Space Constrained Knowledge Editing for Language Models","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.02355","snapshot_observed_at":"2026-08-07T00:57:13.689552Z","title":"Alphaedit: Null-space constrained knowledge editing for language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.689552Z"},"links":{"cited_paper":"/paper/2410.02355","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:52fe3fc34457cadaa0f9a327ad090fe1f870900e1c5cc7cde7d0692c10dbd452","observation_id":"f54fb324-a2c2-4622-92b2-cd0a9dbbbada","resolution":{"observed_at":"2026-08-07T00:57:13.689552Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.08813","last_updated":"2025-04-09T06:53:23Z","snapshot_observed_at":"2026-08-16T12:42:48.086753Z","submitted_at":"2025-04-09T06:53:23Z","title":"SafeMLRM: Demystifying Safety in Multi-modal Large Reasoning Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.08813","snapshot_observed_at":"2026-08-07T00:57:13.693926Z","title":"Safemlrm: Demystifying safety in multi-modal large reasoning models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.693926Z"},"links":{"cited_paper":"/paper/2504.08813","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:2465676a100ec29e3baba3ce2b874103fdd9162810c6b845d92f1b46845fcc3c","observation_id":"a2592e23-781a-4075-8f1d-cf50b905047c","resolution":{"observed_at":"2026-08-07T00:57:13.693926Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2204.05862","last_updated":"2022-04-12T15:02:38Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-04-12T15:02:38Z","title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2204.05862","snapshot_observed_at":"2026-08-07T00:57:13.676103Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.676103Z"},"links":{"cited_paper":"/paper/2204.05862","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:e6f638619dac53d874425074e21cf1be1aae9d38952036a5edef99cfecd8615c","observation_id":"76826419-df01-434d-9e2f-87d04a9e904a","resolution":{"observed_at":"2026-08-07T00:57:13.676103Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.16261","last_updated":"2024-11-07T15:35:52Z","snapshot_observed_at":"2026-08-20T00:39:37.165133Z","submitted_at":"2024-10-21T17:58:20Z","title":"Mini-InternVL: A Flexible-Transfer Pocket Multimodal Model with 5% Parameters and 90% Performance","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.16261","snapshot_observed_at":"2026-08-07T00:57:13.702701Z","title":"Mini-internvl: A flexible- transfer pocket multimodal model with 5% parameters and 90% performance","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.702701Z"},"links":{"cited_paper":"/paper/2410.16261","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:80c8dbd91d83b3c7bfeab98a14a282695c5e6c26d0046dff473c7b25c69ee0f4","observation_id":"05f04817-a770-4ae9-a563-be7b0d121e73","resolution":{"observed_at":"2026-08-07T00:57:13.702701Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.18000","last_updated":"2024-11-28T02:19:55Z","snapshot_observed_at":"2026-08-21T00:00:38.564980Z","submitted_at":"2024-11-27T02:40:29Z","title":"Exploring Visual Vulnerabilities via Multi-Loss Adversarial Search for Jailbreaking Vision-Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.18000","snapshot_observed_at":"2026-08-07T00:57:13.707276Z","title":"Exploring visual vulnerabilities via multi-loss ad- versarial search for jailbreaking vision-language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.707276Z"},"links":{"cited_paper":"/paper/2411.18000","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:46c01b0f7c3c4f6a060abf054e4d9e9f55278ab5d75acfe66a59114cf2f44642","observation_id":"6c06f9c9-f2db-42b1-9c5b-fb8df3fbfd5f","resolution":{"observed_at":"2026-08-07T00:57:13.707276Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.05056","last_updated":"2024-11-07T16:21:18Z","snapshot_observed_at":"2026-08-16T13:02:03.032787Z","submitted_at":"2024-11-07T16:21:18Z","title":"Seeing is Deceiving: Exploitation of Visual Pathways in Multi-Modal Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.05056","snapshot_observed_at":"2026-08-07T00:57:13.711395Z","title":"Seeing is deceiving: Exploitation of visual pathways in multi-modal language models.arXiv preprint arXiv:2411.05056,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.711395Z"},"links":{"cited_paper":"/paper/2411.05056","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:fcbc1c5269b411c6656a47dca9c627e5dffbce1a28bbf3a58d48c5856317aed4","observation_id":"87d8930b-e5f0-4047-b43f-a683871c85f6","resolution":{"observed_at":"2026-08-07T00:57:13.711395Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.00601","last_updated":"2024-03-01T15:27:57Z","snapshot_observed_at":"2026-08-20T14:00:42.041297Z","submitted_at":"2024-03-01T15:27:57Z","title":"Large spin shuttling oscillations enabling high-fidelity single qubit gates","version":1},"cited_work":{"arxiv_id":"2403.00601","doi":null,"metadata_source":"pith","pith_arxiv_id":"2403.00601","snapshot_observed_at":"2026-08-07T00:57:14.266370Z","title":"Large spin shuttling oscillations enabling high-fidelity single qubit gates","venue":"quant-ph","work_id":"6b545d37-28dd-4f54-af44-e59a8b151fef","year":2024},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.715523Z"},"links":{"cited_paper":"/paper/2403.00601","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:a244c16d880e10236a37454fd095b4af7aa62a2c8ee582194045409f0704335e","observation_id":"047b88bb-3472-48e1-aab5-69bb68dd4043","resolution":{"observed_at":"2026-08-07T00:57:14.270803Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2408.03326","last_updated":"2024-10-26T16:35:13Z","snapshot_observed_at":"2026-08-18T11:56:50.710310Z","submitted_at":"2024-08-06T17:59:44Z","title":"LLaVA-OneVision: Easy Visual Task Transfer","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2408.03326","snapshot_observed_at":"2026-08-07T00:57:13.719507Z","title":"Llava- onevision: Easy visual task transfer","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.719507Z"},"links":{"cited_paper":"/paper/2408.03326","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:e2f757edbfafc1a79469cc8c3de083525672bb6da5b84a4c742dea593551458b","observation_id":"1490e152-a044-48dc-a8c0-e666c07c1b53","resolution":{"observed_at":"2026-08-07T00:57:13.719507Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.11473","last_updated":"2024-02-18T06:31:05Z","snapshot_observed_at":"2026-08-16T22:50:36.518159Z","submitted_at":"2024-02-18T06:31:05Z","title":"Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery Detection","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.11473","snapshot_observed_at":"2026-08-07T00:57:13.723670Z","title":"Poisoned forgery face: Towards backdoor attacks on face forgery detection","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.723670Z"},"links":{"cited_paper":"/paper/2402.11473","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:2b9fea45184871db8b9f431600fc72a3aaabca64058757e24cb00f1174579a2c","observation_id":"0f17fc3f-73ed-49e7-b3d1-6284028ad93b","resolution":{"observed_at":"2026-08-07T00:57:13.723670Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2412.11471","doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:57:14.202639Z","title":"Red pill and blue pill: Controllable website fingerprinting defense via dynamic backdoor learning","venue":null,"work_id":"008e8b14-efc8-4012-82b0-6ed0e376170d","year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.736094Z"},"links":{"citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:86ec9dc7eb71e476263b4740176d119ff77e4cc484b16eb43cb9c5ae27a8f890","observation_id":"399aa97c-18fe-4305-89cd-308654c59abe","resolution":{"observed_at":"2026-08-07T00:57:14.209630Z","resolver_source":"raw_fallback","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.16205","last_updated":"2025-06-18T02:41:56Z","snapshot_observed_at":"2026-08-20T14:42:28.552459Z","submitted_at":"2024-07-23T06:14:41Z","title":"LLMs can be Dangerous Reasoners: Analyzing-based Jailbreak Attack on Large Language Models","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.16205","snapshot_observed_at":"2026-08-07T00:57:13.739840Z","title":"Figure it out: Analyzing-based jailbreak attack on large language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.739840Z"},"links":{"cited_paper":"/paper/2407.16205","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:5a189859e4c6daa87cdcaa2c17e5ab47fb9c248d276921ba7274e440c1e1771d","observation_id":"8e69c3d7-c8e4-4647-9ce5-9575afcc51e9","resolution":{"observed_at":"2026-08-07T00:57:13.739840Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2304.08485","last_updated":"2023-12-11T17:46:14Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-04-17T17:59:25Z","title":"Visual Instruction Tuning","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2304.08485","snapshot_observed_at":"2026-08-07T00:57:13.743808Z","title":"X-adv: Physical adversarial object attacks against x-ray prohibited item detection","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.743808Z"},"links":{"cited_paper":"/paper/2304.08485","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:f9572d9a698cec6c9216b4d086a989fd946e2157dc04ec1f1fb216f60c031d96","observation_id":"cc1aa81f-8116-40cc-bdf6-76e3bc66671e","resolution":{"observed_at":"2026-08-07T00:57:13.743808Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2203.02155","last_updated":"2022-03-04T07:04:42Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-03-04T07:04:42Z","title":"Training language models to follow instructions with human feedback","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2203.02155","snapshot_observed_at":"2026-08-07T00:57:13.751706Z","title":"Ouyang, L","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.751706Z"},"links":{"cited_paper":"/paper/2203.02155","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:598c54f1a1e7da3d1edfbb76a688b1908fdc7b9e0440c22e4f70464ae9dc9cf5","observation_id":"47713456-a413-4c7d-9934-b4ecac8b5e06","resolution":{"observed_at":"2026-08-07T00:57:13.751706Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2306.13213","last_updated":"2023-08-16T22:38:55Z","snapshot_observed_at":"2026-08-16T15:21:48.065276Z","submitted_at":"2023-06-22T22:13:03Z","title":"Visual Adversarial Examples Jailbreak Aligned Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.13213","snapshot_observed_at":"2026-08-07T00:57:13.759973Z","title":"org/abs/2306.13213","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.759973Z"},"links":{"cited_paper":"/paper/2306.13213","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:3dbb2eb8e8816d54c7057268b7188d1c867cd0f03504e8334ea6a71d76788637","observation_id":"925b90e8-dbdf-43e8-b2ee-94e35ed6c82c","resolution":{"observed_at":"2026-08-07T00:57:13.759973Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2505.06579","last_updated":"2025-05-10T09:36:28Z","snapshot_observed_at":"2026-08-18T03:47:09.424279Z","submitted_at":"2025-05-10T09:36:28Z","title":"POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.06579","snapshot_observed_at":"2026-08-07T00:57:13.763982Z","title":"Poisoncraft: Practical poisoning of retrieval- augmented generation for large language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.763982Z"},"links":{"cited_paper":"/paper/2505.06579","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:ef6d2e4fdebf83e4b51e35d020a234ae56f98b298229ade39982eb6f182b81e0","observation_id":"afdb5252-2c67-4a4e-afaa-f85f19f35af5","resolution":{"observed_at":"2026-08-07T00:57:13.763982Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.14539","last_updated":"2023-10-10T22:17:17Z","snapshot_observed_at":"2026-08-16T15:12:59.003865Z","submitted_at":"2023-07-26T23:11:15Z","title":"Jailbreak in pieces: Compositional Adversarial Attacks on Multi-Modal Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.14539","snapshot_observed_at":"2026-08-07T00:57:13.767811Z","title":"Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.767811Z"},"links":{"cited_paper":"/paper/2307.14539","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:2d31a5a9cdcc98c24bbe1cd38d55541ee65ae5808d7413738537272396fc80f1","observation_id":"f774a9d4-d82c-4377-99ac-5ce50c7c1e4f","resolution":{"observed_at":"2026-08-07T00:57:13.767811Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20773","last_updated":"2024-06-12T07:13:48Z","snapshot_observed_at":"2026-08-17T15:14:45.354691Z","submitted_at":"2024-05-25T17:17:18Z","title":"Visual-RolePlay: Universal Jailbreak Attack on MultiModal Large Language Models via Role-playing Image Character","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20773","snapshot_observed_at":"2026-08-07T00:57:13.747840Z","title":"4711–4728, Philadelphia, PA, August 2024a","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.747840Z"},"links":{"cited_paper":"/paper/2405.20773","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:36391ca6debc1339349ff3f0c916c9d210dd60453a4377790ddc5a1b70a2b5b0","observation_id":"c2d64ec6-2de9-4e5a-b235-bc0f4f94626a","resolution":{"observed_at":"2026-08-07T00:57:13.747840Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.17704","last_updated":"2025-05-24T12:50:56Z","snapshot_observed_at":"2026-08-19T22:04:02.585395Z","submitted_at":"2025-04-24T16:11:01Z","title":"Safety in Large Reasoning Models: A Survey","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.17704","snapshot_observed_at":"2026-08-07T00:57:13.771631Z","title":"URL https://aclanthology.org/2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.771631Z"},"links":{"cited_paper":"/paper/2504.17704","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:c385130b3f6e2ff5df0a6d56897115dc8a3ba4bd70a39fd32e5bce4e53b2e512","observation_id":"a80fabca-9bde-4030-9093-a4157f3c9600","resolution":{"observed_at":"2026-08-07T00:57:13.771631Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2408.07666","last_updated":"2025-12-31T04:06:49Z","snapshot_observed_at":"2026-08-07T23:28:24.025478Z","submitted_at":"2024-08-14T16:58:48Z","title":"Model Merging in LLMs, MLLMs, and Beyond: Methods, Theories, Applications and Opportunities","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2408.07666","snapshot_observed_at":"2026-08-07T00:57:13.779681Z","title":"Model merging in llms, mllms, and beyond: Methods, theories, applications and opportunities","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.779681Z"},"links":{"cited_paper":"/paper/2408.07666","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:1f6361aed99e88342f9325329121cd67227d7442d3f26a80ec69cd184d4c3fb6","observation_id":"c04dfc90-25fc-4837-98a1-7b20cfc5188b","resolution":{"observed_at":"2026-08-07T00:57:13.779681Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.10794","last_updated":"2025-06-17T02:28:34Z","snapshot_observed_at":"2026-08-16T12:58:08.877248Z","submitted_at":"2025-02-15T13:25:12Z","title":"Distraction is All You Need for Multimodal Large Language Model Jailbreaking","version":2},"cited_work":{"arxiv_id":"2502.10794","doi":null,"metadata_source":"pith","pith_arxiv_id":"2502.10794","snapshot_observed_at":"2026-08-07T00:57:13.989364Z","title":"Distraction is All You Need for Multimodal Large Language Model Jailbreaking","venue":"cs.CV","work_id":"bfef571e-94fe-4d59-8ec4-54144276722b","year":2025},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.783535Z"},"links":{"cited_paper":"/paper/2502.10794","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:9bcc59c636ea362aa90b550cba056d2b65e20df854b7d86d8592f815513b237e","observation_id":"d87738e8-71f4-41d6-a1ca-80f50c110c1e","resolution":{"observed_at":"2026-08-07T00:57:13.995549Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.18927","last_updated":"2024-10-24T17:14:40Z","snapshot_observed_at":"2026-08-19T22:03:55.835550Z","submitted_at":"2024-10-24T17:14:40Z","title":"SafeBench: A Safety Evaluation Framework for Multimodal Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.18927","snapshot_observed_at":"2026-08-07T00:57:13.787678Z","title":"and Wu, B","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.787678Z"},"links":{"cited_paper":"/paper/2410.18927","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:956cf123e34d7622ea3e7650a9acf30de975e402a1fdb940071e254f7344d6bb","observation_id":"3f02041a-4b63-4f7e-904c-fb8306e3faa0","resolution":{"observed_at":"2026-08-07T00:57:13.787678Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.09648","last_updated":"2025-03-12T08:42:05Z","snapshot_observed_at":"2026-08-18T12:48:28.228590Z","submitted_at":"2025-03-12T08:42:05Z","title":"A Survey on Trustworthy LLM Agents: Threats and Countermeasures","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.09648","snapshot_observed_at":"2026-08-07T00:57:13.791531Z","title":"A survey on trustworthy llm agents: Threats and countermeasures","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.791531Z"},"links":{"cited_paper":"/paper/2503.09648","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:df8c3e54f186d7145e14d0b7d76e88bae9f94140b0ed9d161806929dabd10d60","observation_id":"cb7a3ac4-85eb-4c0d-9a8e-37721d4c5e1d","resolution":{"observed_at":"2026-08-07T00:57:13.791531Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2302.00923","last_updated":"2024-05-20T06:43:48Z","snapshot_observed_at":"2026-08-11T00:52:12.225793Z","submitted_at":"2023-02-02T07:51:19Z","title":"Multimodal Chain-of-Thought Reasoning in Language Models","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2302.00923","snapshot_observed_at":"2026-08-07T00:57:13.795355Z","title":"doi: 10.18653/v1/2024.acl-long.773","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.795355Z"},"links":{"cited_paper":"/paper/2302.00923","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:fbc0cccb74e3d3b6ef428e7fd98308c3550a3c661231524d7d1a9d6c5030efb1","observation_id":"52a76e6f-afc4-4d0e-84de-11b6b2635d1d","resolution":{"observed_at":"2026-08-07T00:57:13.795355Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:57:13.799845Z","title":"Zhou, Z., Yu, H., Zhang, X., Xu, R., Huang, F., Wang, K., Liu, Y ., Fang, J., and Li, Y","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.799845Z"},"links":{"citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:922f60d36ef9d43d30c99d90b65be61910d4330ba70133871b8dff3c7ae3a13c","observation_id":"936bf545-aaa9-464c-9b0b-ae57ea48e7c0","resolution":{"observed_at":"2026-08-07T00:57:13.799845Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2304.10592","last_updated":"2023-10-02T16:38:35Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-04-20T18:25:35Z","title":"MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2304.10592","snapshot_observed_at":"2026-08-07T00:57:13.803299Z","title":"Minigpt-4: Enhancing vision-language understanding with advanced large language models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.803299Z"},"links":{"cited_paper":"/paper/2304.10592","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:22254bd904ca6c54b686b7ed5dc401d16b1280c1248715df44ad839031ff3136","observation_id":"fdd7c126-5720-4a37-8806-068fde23779c","resolution":{"observed_at":"2026-08-07T00:57:13.803299Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-08-12T09:06:50.363435Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-07T00:57:13.807101Z","title":"Z., and Fredrikson, M","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.807101Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:29f32a677098d297ace6beb59fd2123c5eb2dcedba5335f77db6172968e8556d","observation_id":"1a955208-7a70-4d16-bd12-0ca9b74111d7","resolution":{"observed_at":"2026-08-07T00:57:13.807101Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.00600","last_updated":"2024-06-30T05:55:15Z","snapshot_observed_at":"2026-08-16T13:38:26.464420Z","submitted_at":"2024-06-30T05:55:15Z","title":"GenderBias-\\emph{VL}: Benchmarking Gender Bias in Vision Language Models via Counterfactual Probing","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.00600","snapshot_observed_at":"2026-08-07T00:57:13.775636Z","title":"Latent imitator: Gen- erating natural individual discriminatory instances for black-box fairness testing","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2018,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.775636Z"},"links":{"cited_paper":"/paper/2407.00600","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:52c7121ded9daea6b5f42aa0034ee818e5ff6c118d74c5235e681930a74b9887","observation_id":"c896b4db-e086-417c-99ee-bb679231b378","resolution":{"observed_at":"2026-08-07T00:57:13.775636Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:57:14.411776Z","title":"Generate more impercepti- ble adversarial examples for object detection","venue":null,"work_id":"03dab4d5-b004-4030-b5dd-142bea0c74ea","year":2021},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2020,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.728012Z"},"links":{"citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:cb48d301abb5042b0c92b589955916f15e7d9805f28df4ff88545ff52b3d1b0b","observation_id":"13b6f4bb-5afc-4a5f-b0a8-a65c255310e3","resolution":{"observed_at":"2026-08-07T00:57:14.416041Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2201.08970","last_updated":"2022-01-22T06:00:17Z","snapshot_observed_at":"2026-08-20T04:31:27.748088Z","submitted_at":"2022-01-22T06:00:17Z","title":"Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2201.08970","snapshot_observed_at":"2026-08-07T00:57:13.731835Z","title":"A large-scale multiple-objective method for black-box attack against object detection","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2021,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.731835Z"},"links":{"cited_paper":"/paper/2201.08970","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:3eb329ba1c176bc765ade0fdcabda8008d5bcfd9820e54d65a2ae36c9fcf68fb","observation_id":"218de7a9-17bd-4f9f-87a0-8b5f770bdce1","resolution":{"observed_at":"2026-08-07T00:57:13.731835Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:57:14.398724Z","title":"Leveraging multimodal llm for inspirational user interface search","venue":null,"work_id":"4f09d529-0ffb-41b3-9037-eb1c33c6c0ca","year":2025},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.756027Z"},"links":{"citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:3aa8c29f086e1ca72c7652737f977de2cdd28cb90e176e093246322d383703bf","observation_id":"2196c723-a62e-4edc-b08a-5aea255af0fd","resolution":{"observed_at":"2026-08-07T00:57:14.402863Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:57:14.425215Z","title":"Unbridled icarus: A survey of the potential perils of image inputs in multimodal large language model security","venue":null,"work_id":"63be2490-f626-450c-9583-afd808fda6c6","year":2024},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.685345Z"},"links":{"citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:5cfd2b5319d07cc99aa9e40c3f51df856e1885d02b00ae4f72ce506ed711456a","observation_id":"e1fea86c-5706-42b9-ba5c-46f1286240d8","resolution":{"observed_at":"2026-08-07T00:57:14.429797Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2310.06474","last_updated":"2024-03-04T04:03:54Z","snapshot_observed_at":"2026-08-20T04:04:43.980873Z","submitted_at":"2023-10-10T09:44:06Z","title":"Multilingual Jailbreak Challenges in Large Language Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.06474","snapshot_observed_at":"2026-08-07T00:57:13.680823Z","title":"J., and Bing, L","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.680823Z"},"links":{"cited_paper":"/paper/2310.06474","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:cfbefd1d947393f875a9b4a7775326366f58f6e62688a6f2e2ae75b80317b258","observation_id":"77dcf9e1-d1f8-4a47-be3f-9f06bc13eea7","resolution":{"observed_at":"2026-08-07T00:57:13.680823Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.03683","last_updated":"2025-06-04T08:13:53Z","snapshot_observed_at":"2026-08-20T12:19:15.706476Z","submitted_at":"2025-06-04T08:13:53Z","title":"PRJ: Perception-Retrieval-Judgement for Generated Images","version":1},"cited_work":{"arxiv_id":"2506.03683","doi":null,"metadata_source":"pith","pith_arxiv_id":"2506.03683","snapshot_observed_at":"2026-08-07T00:57:14.329077Z","title":"PRJ: Perception-Retrieval-Judgement for Generated Images","venue":"cs.CV","work_id":"957f7938-3c0e-4cd9-89da-d37d96944210","year":2025},"citing_paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025","version":2},"reference_index":2025,"source":"pdf_text","source_observed_at":"2026-08-07T00:57:13.698449Z"},"links":{"cited_paper":"/paper/2506.03683","citing_paper":"/paper/2506.12430"},"observation_digest":"sha256:d7548ebfcabf25e2fa87ccae29ebc1ada6ed136b594992c351106bcd40fe0ac4","observation_id":"c11a93f9-8b02-4731-ac6c-08d5e1f7a551","resolution":{"observed_at":"2026-08-07T00:57:14.333337Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2506.12430","last_updated":"2025-07-11T02:01:54Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-20T09:37:30.315236Z","submitted_at":"2025-06-14T10:03:17Z","title":"Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025"},"reference_resolution":{"displayed":33,"state_counts":{"malformed_identifier":0,"metadata_mismatch":1,"parse_uncertain":0,"unresolved":26,"verified_exact":3,"verified_fuzzy":3},"total_outbound_references":33},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-20T06:33:59.587034+00:00","source":"crossref"},{"observed_at":"2026-08-20T06:33:54.927442+00:00","source":"retraction_watch"}],"thesis":"As of 21 August 2026, this Paper Citation Record lists 33 of 33 outbound references and 5 inbound Pith citation observations for arXiv:2506.12430."}