Pith. sign in

Paper Citation Record · LEDGER

NonTextual Target Attack

As of 7 August 2026, this Paper Citation Record lists 30 of 30 outbound references and 4 inbound Pith citation observations for arXiv:2510.02999.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2510.02999 v5

Coverage vector

measured 30 of 30 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-04T12:44:04.461847Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-01T11:40:26.849024Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

30 of 30 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved30
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 82f96f9a-b0a9-4f8f-ac2d-7706310b02d7 · outbound

This paper cites write newline.

NonTextual Target Attack write newline

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.737579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.737579Z digest=sha256:6f75244d3e2573bac4a7f92a7d3499c9be5abb16588b02b1d093d10e9164e142

Observation f8c0db2f-5f99-4ce6-aee7-d9bdc022b6e6 · outbound

This paper cites Detecting language model attacks with perplexity, 2023.

NonTextual Target Attack Detecting language model attacks with perplexity, 2023

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.801628Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.801628Z digest=sha256:f37894f5c16e64c24476c459e3c0ddb693582f0e18d03b95d0690111faaaba67

Observation fbf97da5-0632-4a24-b406-ea975802cafa · outbound

This paper cites Jailbreaking leading safety-aligned llms with simple adaptive attacks, 2025.

NonTextual Target Attack Jailbreaking leading safety-aligned llms with simple adaptive attacks, 2025

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.838175Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.838175Z digest=sha256:6433e38468390c85542a9ce70e311b04ccac38e68cf2f448c101988938f6bb47

Observation f4e7b09f-f16f-44a9-bf22-7d086c6f9127 · outbound

This paper cites When llm meets drl: Advancing jailbreaking efficiency via drl-guided search, 2025.

NonTextual Target Attack When llm meets drl: Advancing jailbreaking efficiency via drl-guided search, 2025

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.853490Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.853490Z digest=sha256:015d1a027b94baebeffff43107fe4634bc5fc333e08003f2081157208ac1759e

Observation 0655558e-3480-4fac-8b8a-c19c5d93c94a · outbound

This paper cites The llama 3 herd of models, 2024.

NonTextual Target Attack The llama 3 herd of models, 2024

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.906304Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.906304Z digest=sha256:aa7811c2e9dabcdaf5d86d0322325cfe0250803290261d631da510003faeb394

Observation 65e9bb05-6045-47f1-947a-ed2c986149ff · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

NonTextual Target Attack DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:01.973418Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:01.973418Z digest=sha256:9db575d6ae1d0240c462dd32028a95f0820b533fd2ea8febadb088edba1f49e5

Observation f85f29fa-0e5a-4a00-9619-75833c22f9b9 · outbound

This paper cites COLD -attack: Jailbreaking LLM s with stealthiness and controllability.

NonTextual Target Attack COLD -attack: Jailbreaking LLM s with stealthiness and controllability

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.127701Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.127701Z digest=sha256:4100a8f7eb010117a5dbafcda793b9469b5bbb93eee4142bc4319af76c31877d

Observation a5e43586-68ea-4a67-8ec3-00cd0cc12845 · outbound

This paper cites Dualbreach: Efficient dual-jailbreaking via target-driven initialization and multi-target optimization, 2025.

NonTextual Target Attack Dualbreach: Efficient dual-jailbreaking via target-driven initialization and multi-target optimization, 2025

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.271719Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.271719Z digest=sha256:1cc42287d23cdaee9c0e451b4c5e2f24ca9a1e42a8148ac448d14db66d30d5ab

Observation 3f93b502-44bc-4e6f-83d2-814a79c7a246 · outbound

This paper cites Baseline defenses for adversarial attacks against aligned language models, 2023.

NonTextual Target Attack Baseline defenses for adversarial attacks against aligned language models, 2023

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.387598Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.387598Z digest=sha256:0325084066db35525d2cdad10c5e575a00edecd500ab713c07137f8cf953026c

Observation fff08df8-39aa-41d5-b004-62c15b0ab9fb · outbound

This paper cites Improved techniques for optimization-based jailbreaking on large language models, 2024.

NonTextual Target Attack Improved techniques for optimization-based jailbreaking on large language models, 2024

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.442919Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.442919Z digest=sha256:8aa535766f6fe917a6b051ebe902cfd691a595a70873e0161dfc90c55b3b90de

Observation 8bfc140f-61b2-4c86-86fb-b6828864a443 · outbound

This paper cites Mistral 7B.

NonTextual Target Attack Mistral 7B

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.493204Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.493204Z digest=sha256:91163007b3aa7b0d94fa1b674547e5ef932984ff1a78c47090f62c5c1d9715a4

Observation 7dba98d0-cf5b-4e8a-99c1-a17eb67de622 · outbound

This paper cites Amplegcg: Learning a universal and transferable generative model of adversarial suffixes for jailbreaking both open and closed llms, 2024.

NonTextual Target Attack Amplegcg: Learning a universal and transferable generative model of adversarial suffixes for jailbreaking both open and closed llms, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.560937Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.560937Z digest=sha256:7d939b6e2450824fb4143007c074e52c64b883654de0bf2b380f8993a00dba2d

Observation 58e52490-cba5-4881-a061-cd720e76e114 · outbound

This paper cites Advancing adversarial suffix transfer learning on aligned large language models, 2024 a.

NonTextual Target Attack Advancing adversarial suffix transfer learning on aligned large language models, 2024 a

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.617654Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.617654Z digest=sha256:eb66ee20976526a1933ae3bfe0efe40e94aecf47f0a25d21159cac9069172242

Observation 44b3c29d-f3e4-46b4-8285-6587885d555d · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models.

NonTextual Target Attack Autodan: Generating stealthy jailbreak prompts on aligned large language models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.722697Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.722697Z digest=sha256:a23b6caca3e61a4414a0bc72c08c80cad8dd59b80dcc461b3a32600a439850ec

Observation 3cd4317f-86a4-4275-8337-adf3c5de1c7a · outbound

This paper cites Harmbench: a standardized evaluation framework for automated red teaming and robust refusal.

NonTextual Target Attack Harmbench: a standardized evaluation framework for automated red teaming and robust refusal

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.854141Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.854141Z digest=sha256:cbf169ebd4f8d026abef26db4ed29afd5ac91b69f09f992ff81b39c924d35488

Observation d5e3f272-3013-4265-819e-714de8ba0ef3 · outbound

This paper cites Language models are unsupervised multitask learners.

NonTextual Target Attack Language models are unsupervised multitask learners

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:02.945466Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:02.945466Z digest=sha256:42808d23fb2ee01ea843e0ef6d35f0bd479e0882fbc882b12c36e6243860b015

Observation 99627969-14ce-4bd0-b05e-fe0ea133414e · outbound

This paper cites an unresolved cited work.

NonTextual Target Attack Unresolved cited work

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.057308Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.057308Z digest=sha256:b1e79dcf90af4ebdd3b9d46c9bca2a6fdcd67253eac9f1446d236e4bbebe5cd3

Observation 32d837dd-7eaa-4fe7-8d42-732477ff0ded · outbound

This paper cites do anything now.

NonTextual Target Attack do anything now

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.124554Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.124554Z digest=sha256:4a347bc33a37f7ebd44a8f304cdd222930f3317a432775c015424c97b2ca4a4c

Observation 7806188e-7aba-43ba-b7d4-a4f9f494df4e · outbound

This paper cites Dynamic target attack, 2025.

NonTextual Target Attack Dynamic target attack, 2025

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.210753Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.210753Z digest=sha256:8563f60b12cc00d37e15c4023ce731957f3d8773da8762dc396298a2df918441

Observation b17adb40-a580-4eb9-9260-f52588f8032d · outbound

This paper cites Qwen2 technical report, 2024.

NonTextual Target Attack Qwen2 technical report, 2024

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.321275Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.321275Z digest=sha256:1868291f24186e1e7ee1f79590ce7e39ce8ff55aec4ff2324db2d9a6271a900e

Observation 619c801a-228a-4d86-9dfc-d5b11d3d7384 · outbound

This paper cites Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts, 2024.

NonTextual Target Attack Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts, 2024

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.446300Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.446300Z digest=sha256:ec5d75d503635bcd1bfd16fbc530aec1b864872e16dfa35a4e8408b572ff7cf4

Observation 92389e98-7191-44e0-a0a7-55c69ca94434 · outbound

This paper cites How johnny can persuade LLM s to jailbreak them: Rethinking persuasion to challenge AI safety by humanizing LLM s.

NonTextual Target Attack How johnny can persuade LLM s to jailbreak them: Rethinking persuasion to challenge AI safety by humanizing LLM s

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.545057Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.545057Z digest=sha256:c60b3e524eac10ac11366ee851e103d8f5399b87d5166533ea669e32e5a49111

Observation a48dec15-8ace-45e8-854b-6c682d6fe931 · outbound

This paper cites A survey of large language models, 2024.

NonTextual Target Attack A survey of large language models, 2024

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.688438Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.688438Z digest=sha256:831d20b52d454b6a4b7da0eb7ef0af8c2d3f4b77a2af117022d37d629a49eecb

Observation f4366f98-df0b-4921-9643-28e5a42d7dde · outbound

This paper cites Xing, Hao Zhang, Joseph E.

NonTextual Target Attack Xing, Hao Zhang, Joseph E

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.750088Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.750088Z digest=sha256:2c46f49a5419fc79a9b8631372a2aeea44577ba524c793969ed58384f10cdb68

Observation f3904a3b-a2ad-48a4-8344-8b8da8182906 · outbound

This paper cites Don't say no: Jailbreaking llm by suppressing refusal, 2024.

NonTextual Target Attack Don't say no: Jailbreaking llm by suppressing refusal, 2024

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.877815Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.877815Z digest=sha256:ae62f41486ef013db8d8c32d583b337f4968da084f0a26b9e4f3b392a25c921a

Observation cf7c6c90-be23-4f6a-ac7c-75d7edf1e75e · outbound

This paper cites Advprefix: An objective for nuanced llm jailbreaks, 2024.

NonTextual Target Attack Advprefix: An objective for nuanced llm jailbreaks, 2024

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:03.993700Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:03.993700Z digest=sha256:8ffce36b09bc868f0744ee93def4e6ef877015e78ef1173105ec489cb124f545

Observation 333e0d5b-f6d2-40cd-b99a-810623c48468 · outbound

This paper cites Zico Kolter, and Matt Fredrikson.

NonTextual Target Attack Zico Kolter, and Matt Fredrikson

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:04.106273Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:04.106273Z digest=sha256:8a7ec929fe0568f804de73941b0a83fd66c5a2dcca4cde6ec17bf78dad1b488b

Observation dcd6837f-5457-4384-a74a-a6b412d7e5da · outbound

This paper cites @esa (Ref.

NonTextual Target Attack @esa (Ref

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:04.216844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:04.216844Z digest=sha256:1415ea534468bd2d9deaa5bb8fa9b85e3e83f1593366d7f03e2c4106f493008e

Observation 35a50faf-5cfd-4624-b20b-e546bc9580f5 · outbound

This paper cites an unresolved cited work.

NonTextual Target Attack Unresolved cited work

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:04.364109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:04.364109Z digest=sha256:5b729b8c469da81ab17f10f2e421c84bf3d65f40614aea606685a204440417e3

Observation 846fbc99-492c-400e-a1ed-32a4121e9599 · outbound

This paper cites an unresolved cited work.

NonTextual Target Attack Unresolved cited work

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-04T12:44:04.461847Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T12:44:04.461847Z digest=sha256:6a81081434019a3d509d6fdab27b2c428e2ed41640eeac31a9106c2efb591550

Pith citing papers

Observation ab0e3d04-815c-404d-a926-28f32950a061 · inbound

Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization cites this paper.

Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization NonTextual Target Attack

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-07-09T01:19:04.946819Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-12T03:37:02.206788Z digest=sha256:24f1ec95b45ef0401f8a809670cb3cf5244f17c9aed074ef8bf0c64eb097179b

Observation 4d471524-fb69-49e7-a637-52a4588d4159 · inbound

Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization cites this paper.

Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization NonTextual Target Attack

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-07-09T01:19:04.946819Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-30T22:36:35.008744Z digest=sha256:275d0c16a23c62e37f313f1e1f3a152d983e8691a341b1c04af9255988557ace

Observation ca9c06c3-4896-4420-bc99-9c0576a0a024 · inbound

RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry cites this paper.

RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry NonTextual Target Attack

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-07-09T01:19:04.946819Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-30T00:33:35.235214Z digest=sha256:219c3881c31b25a8c4b1c7574c4df548bff109c33583a2729c70068dd290ac90

Observation e8aaf750-6a18-4fec-9160-935d9589216e · inbound

DARWIN: Evolving Jailbreak Adversary and Guardrail for LLM Safety Evaluation and Protection cites this paper.

DARWIN: Evolving Jailbreak Adversary and Guardrail for LLM Safety Evaluation and Protection NonTextual Target Attack

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-01T11:40:26.849024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T11:40:26.849024Z digest=sha256:cf9cacb31b7f75d01274fea2dabffcb8631ab5fc96da10f330c248094ea22fae