Pith. sign in

Paper Citation Record · LEDGER

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks

As of 7 August 2026, this Paper Citation Record lists 96 of 96 outbound references and 0 inbound Pith citation observations for arXiv:2608.01117.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.01117 v1

Coverage vector

measured 96 of 96 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T00:32:05.231888Z

measured 96 of 96 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

96 of 96 outbound references displayed

  • verified exact7
  • verified fuzzy39
  • unresolved50
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation c32d0f65-0d69-489c-9ff0-cb07f2ccfc5e · outbound

This paper cites Training language models to follow instructions with human feedback,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Training language models to follow instructions with human feedback,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:55.514906Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:55.514906Z digest=sha256:2f8a7ede9988d16399742c3be1536cc8c38dbb19f3583c1769561da458db5ef3

Observation cd82891b-c1ae-4ae3-b844-6d4fa39a3ae8 · outbound

This paper cites LongMemEval: Benchmarking Chat Assistants on Long-Term Interactive Memory.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LongMemEval: Benchmarking Chat Assistants on Long-Term Interactive Memory

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:55.637427Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:55.637427Z digest=sha256:06e8b3c31cfc55a0df6bcf8f6139dcca0b0f92f636c5df10a28d8a97cd0d8ee0

Observation 7cf4770b-9453-4016-9da2-d844e599d76a · outbound

This paper cites Evaluating llm-based agents for multi-turn conversations: A survey,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Evaluating llm-based agents for multi-turn conversations: A survey,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:55.784784Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:55.784784Z digest=sha256:28d21c0980a115c34fabf589b2418dcd1d3291d83f786cba4fee88948d97bd98

Observation 107e38ed-712a-419d-85e0-0507dde3a437 · outbound

This paper cites Asleep at the keyboard? assessing the security of github copilot’s code contributions,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Asleep at the keyboard? assessing the security of github copilot’s code contributions,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:55.875537Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:55.875537Z digest=sha256:dcddb6078c690bbdd3fb1f287c53863f858b4949975175a80ead56f61e025f2e

Observation 97099a72-e91f-4f57-b75a-7eefc586c561 · outbound

This paper cites Lost at c: A user study on the security implications of large language model code assistants,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Lost at c: A user study on the security implications of large language model code assistants,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:55.975024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:55.975024Z digest=sha256:2e703322ca55ee5d5a8b1196b9021c1e1b763ee5d49083b74c7cff0c9e537083

Observation 3076b682-3e56-43ed-a759-6efd71551ece · outbound

This paper cites A survey on large language models for code generation,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on large language models for code generation,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.092950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.092950Z digest=sha256:a7e70d816898855c94d0d718a5ab1191f96e64cb998c8ff7dea868e9a9af1f41

Observation 55dc6c33-1b30-438c-8ed6-44eed6e324d7 · outbound

This paper cites Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.211615Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.211615Z digest=sha256:ccacf89487b24f2a9bf0c6fd1a214451869086374dd6b3004a979fcba7dd54c9

Observation a2029bb6-0699-46e5-a514-291b31988b8d · outbound

This paper cites WorkflowLLM: Enhancing Workflow Orchestration Capability of Large Language Models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks WorkflowLLM: Enhancing Workflow Orchestration Capability of Large Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.329166Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.329166Z digest=sha256:bdfd17c93d91f9abcdd291710b5c8adbcb5c992ce4598b5ef4cd35b035b583a1

Observation cbf01be6-2260-4685-b781-8e80b89937c9 · outbound

This paper cites Agent security bench (asb): Formalizing and benchmark- ing attacks and defenses in llm-based agents,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agent security bench (asb): Formalizing and benchmark- ing attacks and defenses in llm-based agents,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.406535Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.406535Z digest=sha256:b9b8db10cd81ac27774520886921059eed99e5b62889f11fc9387966503539c8

Observation 00a3030a-f506-45f2-99f2-4f8c3aba4af9 · outbound

This paper cites Isolategpt: An execution isolation architecture for llm-based agentic systems,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Isolategpt: An execution isolation architecture for llm-based agentic systems,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.526998Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.526998Z digest=sha256:a04a5220b6b5464aa56c0083d9490f6f1b0669ed4c2099e19e623184c9026dbd

Observation 294706d6-3404-4cd6-a2af-2386fbb77804 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.648922Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.648922Z digest=sha256:c42e635a8cc966e39ecc9bd126ecb4fc43a4ab6b935049c68a6bf2c173c846e5

Observation 57277511-3f49-40d6-8416-6bc08c094404 · outbound

This paper cites A survey on agentic security: Applications, threats and defenses,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on agentic security: Applications, threats and defenses,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.724764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.724764Z digest=sha256:18ac301640303bbe784c1e7203031b09b1fa6b1dfa9c75f91179e0e5c3308ca8

Observation 170be5de-46f6-4207-a713-99b883c15d5e · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Ai agents under threat: A survey of key security challenges and future pathways,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.872871Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.872871Z digest=sha256:ea0b6ad80dda177cb340551245afd75bcf384371732e1c8ed5a8e1474f4fe7e5

Observation c9361ab2-8938-4ab0-9d3b-f02beb5b963b · outbound

This paper cites Jailbroken: How does llm safety training fail?.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbroken: How does llm safety training fail?

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:56.987406Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:56.987406Z digest=sha256:c9f4204cf45d42035108c9e40a6320cdc6ce4450bc447d025c6848f91280e484

Observation eab0f278-d10d-438e-813b-2401a695d349 · outbound

This paper cites Malla: Demystifying real-world large language model integrated malicious services,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Malla: Demystifying real-world large language model integrated malicious services,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.101800Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.101800Z digest=sha256:c0c3870c292d14ae1f7dbee356a857e8f4e883134afa8f0da608c6abde5c2c6e

Observation fa50e402-3b42-4b94-9033-1fb12224bd83 · outbound

This paper cites Gptracker: A large- scale measurement of misused gpts,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Gptracker: A large- scale measurement of misused gpts,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.218426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.218426Z digest=sha256:68049d3249f76ce35ede437ab8555f7a27d3efd547a22649a3c87a08c8d6da3b

Observation 038be16a-9700-4916-9d97-d048760d7abb · outbound

This paper cites Don’t listen to me: Understanding and exploring jailbreak prompts of large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Don’t listen to me: Understanding and exploring jailbreak prompts of large language models,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.300020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.300020Z digest=sha256:081b1d601dfb2cfd2efc4c5912211a68bf54b1cd2d7cd029d69816dac7de6d67

Observation 60dbaa07-8da6-4ee7-9aca-fd1c3509bd56 · outbound

This paper cites A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.413110Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.413110Z digest=sha256:43edfc3ccd11e3516dd8be5b9e4f3b13bac97a4dccf3679bc0864be11bfe1880

Observation 78956061-563d-4bdb-b0e7-1ca23eca0450 · outbound

This paper cites From chatbots to phishbots?: Phishing scam generation in commercial large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks From chatbots to phishbots?: Phishing scam generation in commercial large language models,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.441651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.441651Z digest=sha256:f53ab22940bf93d9b8ba57b003b954eebf6cd755d2aaa89d6ab3e319c0eab5f9

Observation 8060fc06-a6e4-4195-b008-5e04a5731d9f · outbound

This paper cites Constitutional AI: Harmlessness from AI Feedback.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Constitutional AI: Harmlessness from AI Feedback

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:57.515679Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:57.515679Z digest=sha256:5b29a6a46db1c8b1673f30250dcb3ee7325f5f244577cdb0809d80de12a4a7d5

Observation 73063fe6-64c2-48a2-b150-135e3e1c7b4f · outbound

This paper cites Improving llm safety alignment with dual-objective optimization,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Improving llm safety alignment with dual-objective optimization,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.545421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:57.641455Z digest=sha256:756c5dd5aaee3e9456bce9ecc3473a4b28e10cbd630a816da636288f6fb93884

Observation 03f8496c-c33c-4731-b267-3c85ee7978a7 · outbound

This paper cites Fine-tuning aligned language models compromises safety, even when users do not intend to!.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Fine-tuning aligned language models compromises safety, even when users do not intend to!

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.521615Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:57.801433Z digest=sha256:18170e3aac58b209f921b79d1c0bf46ee24270afcf69815338ef8b1947f2bf93

Observation f0b4a246-1771-4366-950b-a6ea4fb9a2d4 · outbound

This paper cites Harmbench: a standardized evaluation framework for automated red teaming and robust refusal,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Harmbench: a standardized evaluation framework for automated red teaming and robust refusal,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.496713Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:57.966371Z digest=sha256:bc8103915938b97bebcea25f5e2a9b15954303f29165972a7973b3d77ba81410

Observation b3bf5573-465f-4cc6-a3df-eca75d6a31ef · outbound

This paper cites Wildteaming at scale: From in-the-wild jailbreaks to (adversarially) safer language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Wildteaming at scale: From in-the-wild jailbreaks to (adversarially) safer language models,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.472015Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.093785Z digest=sha256:2b80a449a707f03e2f37066c4a3b30d8b8055e4b02a54b99976eb8f246662fef

Observation 5b131fb9-1d32-43d0-b2c8-84fee66d32eb · outbound

This paper cites Improving alignment and robustness with circuit breakers,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Improving alignment and robustness with circuit breakers,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.452404Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.197875Z digest=sha256:76ca03ca8744815aaefe39eaf6463e16b3565b92152f201722df72384a71d0ef

Observation 0a567a2d-8569-43b6-b558-250895a07e85 · outbound

This paper cites PARDEN, Can You Repeat That? Defending against Jailbreaks via Repetition.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks PARDEN, Can You Repeat That? Defending against Jailbreaks via Repetition

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:58.285828Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:58.285828Z digest=sha256:6f59c0e5ac872354569f0674321322f03c7ba1c7c10681fc16a928d824ec3eef

Observation 7b6a9354-23ae-494b-b36b-e17cfdf33fe1 · outbound

This paper cites On large language models’ resilience to coercive interrogation,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks On large language models’ resilience to coercive interrogation,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:58.376585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:58.376585Z digest=sha256:8e038af826ca538ac9bcccf4bb2dc6568275c1d7c6a4d7f3603c97a9aac2da23

Observation 607fab59-35c0-40d8-bccb-8fae18d893b3 · outbound

This paper cites You only prompt once: On the capabilities of prompt learning on large language models to tackle toxic content,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks You only prompt once: On the capabilities of prompt learning on large language models to tackle toxic content,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.421869Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.486508Z digest=sha256:09fc90a70c996db2013b32db9777ea745dd853a407de141b89c4dbecb37a0ee0

Observation 97d673b5-a034-4a14-b363-f1f52f210252 · outbound

This paper cites {LLM-Fuzzer}: Scaling as- sessment of large language model jailbreaks,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks {LLM-Fuzzer}: Scaling as- sessment of large language model jailbreaks,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.403495Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.604802Z digest=sha256:f0114e21492569b5d3bc884d876d497aa380109145eabd282fabe5b06d0578bb

Observation 5702cdc3-0182-421c-ab3c-01beae57348e · outbound

This paper cites Mind the inconspicuous: Revealing the hidden weakness in aligned {LLMs}’refusal boundaries,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Mind the inconspicuous: Revealing the hidden weakness in aligned {LLMs}’refusal boundaries,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.384412Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.660865Z digest=sha256:1943ada55276a719666ea6637298a5c9f4d23fec46fd350efa4978e43e1f5f8a

Observation 63bf2d99-03d0-4d2b-9737-81695d561695 · outbound

This paper cites Safety misalignment against large language models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safety misalignment against large language models

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.354697Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.735355Z digest=sha256:ee90a6bb60d7070e977557f72149b9fd5e7d9dc3dcc7dacb5374d54ca523dc94

Observation 95cc5bf5-3c65-4186-a227-0f87cad7268d · outbound

This paper cites Refusal is not an option: Unlearning safety alignment of large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Refusal is not an option: Unlearning safety alignment of large language models,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.322834Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.818726Z digest=sha256:b145c172be9229616640973bcd0158c0832c4ffe5706590eb07c9fc04171084d

Observation cbaabaae-24ed-4322-b4ec-65742247ef1c · outbound

This paper cites Mission impossible: A statistical perspective on jailbreaking llms,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Mission impossible: A statistical perspective on jailbreaking llms,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.297721Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:58.902116Z digest=sha256:366ddcb58d0836668268e9cf89c4ae72274ef9b2dea35013e3feff89d1ebabfa

Observation 4f185973-70e3-4682-a0b9-95ae43890d1e · outbound

This paper cites A comprehensive study of jailbreak attack versus defense for large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A comprehensive study of jailbreak attack versus defense for large language models,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.245227Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.106919Z digest=sha256:8a8140e38de4a7cad7458209a3c2bf4621f1b345cb97f6a47f317ce7adb1bd04

Observation d11cbd9f-6724-4819-ac50-75b5cf13daed · outbound

This paper cites “do anything now.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks “do anything now

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.144803Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.217860Z digest=sha256:b78b6de4052747d4084e3bd6323dc2cd44efda42362b5bd5e240a14a6f7c554f

Observation 4b5db5ce-47dc-452a-8e0e-c6cbdc633682 · outbound

This paper cites {TwinBreak}: Jailbreak- ing{LLM}security alignments based on twin prompts,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks {TwinBreak}: Jailbreak- ing{LLM}security alignments based on twin prompts,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:12.073308Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.324764Z digest=sha256:25a5d980b5770bbbff8e9d7777657229b20c5c781b8b4b783d53a95577c4a84a

Observation 29beb297-5cc5-44cb-82c7-5a76d12c1f92 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:59.438314Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:59.438314Z digest=sha256:a271786cce977af93bfc016f08323d3c619f80c332e156692897588330fb5fe6

Observation 11b63b8b-e254-4c37-8a6c-8ed4a6a9cb93 · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking black box large language models in twenty queries,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:59.550901Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:59.550901Z digest=sha256:321a61302dbf41160006a11186be764d3608d1efbc4b04dc751cfaf67e4a811e

Observation 249ac1dd-68a7-4ef4-b4b0-651d0878fecc · outbound

This paper cites Tree of attacks: Jailbreaking black- box llms automatically,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Tree of attacks: Jailbreaking black- box llms automatically,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-06T00:31:59.629647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:31:59.629647Z digest=sha256:841de7ef211ad82f36120098f351064713f4aa76612f23aaa2bc37e44d8a66d1

Observation ea90a336-85bc-43ba-a0c0-1ee8f387c924 · outbound

This paper cites Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction,

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.965032Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.696322Z digest=sha256:9e69564ef8d34eb384487021a59293d1b1ae8cb59fdf557ebeb7ac0f90500dc8

Observation f739a255-c0a2-4b4d-b79e-156ba68e789a · outbound

This paper cites Sneakyprompt: Jailbreaking text-to-image generative models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sneakyprompt: Jailbreaking text-to-image generative models,

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.897782Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.807161Z digest=sha256:7ccb42e601521df2e8b6b15e3ce37ca5d832bd69374982d7e39268345934da32

Observation 8a562615-5a73-4fbb-8794-286120f838d3 · outbound

This paper cites Fuzz-testing meets llm- based agents: An automated and efficient framework for jailbreaking text-to-image generation models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Fuzz-testing meets llm- based agents: An automated and efficient framework for jailbreaking text-to-image generation models,

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.824151Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:31:59.918315Z digest=sha256:5ba3bb58d183afa0fda1b69bdce725a9d054d706266cbf389e76cdbcdea96d6b

Observation e7f34c33-4d5a-4f83-95c0-3c4f7292b930 · outbound

This paper cites Modifier unlocked: Jailbreak- ing text-to-image models through prompts,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Modifier unlocked: Jailbreak- ing text-to-image models through prompts,

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.762977Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:00.012596Z digest=sha256:1201455cdf68ac19334cc07fde775e810a5ff8f97d68b78a3dd529b54f8f34aa

Observation 183d512f-8525-4ef8-a2bf-694b927d5b79 · outbound

This paper cites From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:00.146044Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:00.146044Z digest=sha256:2095d1122729ce559b15e6931174d7929c4f68b3b5845573df6ee668f06a7f10

Observation 859f1718-dc3d-40f5-a1d7-a871b7cc5e00 · outbound

This paper cites Exposing the guardrails:{Reverse- Engineering}and jailbreaking safety filters in{DALL· E}{Text-to- Image}pipelines,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Exposing the guardrails:{Reverse- Engineering}and jailbreaking safety filters in{DALL· E}{Text-to- Image}pipelines,

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.692657Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:00.250823Z digest=sha256:f578fe9f512f81be3fb203c58a1a4c9fca7e851b2425e6541ada9590059d800d

Observation ec09ada3-3d7f-404b-9b02-48bfb673b00d · outbound

This paper cites Jailbreaking llms: A survey of attacks, defenses and evaluation,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking llms: A survey of attacks, defenses and evaluation,

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.621183Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:00.328425Z digest=sha256:4b695c73ef9be68676346bab5ef654aac4429bb4949b137864135d0bac839dc7

Observation 981c0708-ece5-4ac1-bbd4-364e0cf01a29 · outbound

This paper cites Surrogateprompt: Bypassing the safety filter of text-to-image models via substitution,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Surrogateprompt: Bypassing the safety filter of text-to-image models via substitution,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.549592Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:00.424873Z digest=sha256:34d8b338c83549cacee66b99a46fc27044e5543c5dcc0be644781973d0cb1afd

Observation 54230e98-0de6-4e71-b28a-49d00c5cc524 · outbound

This paper cites Jailbreakbench: An open robustness benchmark for jail- breaking large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreakbench: An open robustness benchmark for jail- breaking large language models,

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.477370Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:00.502530Z digest=sha256:28bd3704d701e3a3a517834fb3c8b1198327fad561273b37f6e144565f805316

Observation a4288414-39ae-4d79-9bd6-4c362022ffff · outbound

This paper cites LLMs Get Lost In Multi-Turn Conversation.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LLMs Get Lost In Multi-Turn Conversation

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:00.631410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:00.631410Z digest=sha256:623b19700aa31cfdf13417d81fa35531971568987faec088a9c887cbd6943953

Observation ef96daba-4418-4710-b59b-2fe6b172e9b7 · outbound

This paper cites A Survey on Multi-Turn Interaction Capabilities of Large Language Models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A Survey on Multi-Turn Interaction Capabilities of Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:00.805296Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:00.805296Z digest=sha256:6546937e06d589cffd44824157e38b1a5c0447b354b82b676f1d48f11202842b

Observation 51f6832f-3f61-4b2a-8830-0224e9affcb8 · outbound

This paper cites LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:00.935942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:00.935942Z digest=sha256:5f053eded338bbab6266c20cb0ab6c2acb04a125b4c515c398287d461600ade1

Observation 343c3b41-3deb-4a72-996f-2c4756e87d8c · outbound

This paper cites Great, now write an article about that: The crescendo{Multi-Turn}{LLM}jailbreak attack,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Great, now write an article about that: The crescendo{Multi-Turn}{LLM}jailbreak attack,

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.406388Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:01.070590Z digest=sha256:b7168c7577881d51d7f5852297fc644a33f4a9c1c276c66199755463d53a6ea6

Observation 7cf8fb96-4b28-4bd2-817f-0cd67b59cda9 · outbound

This paper cites Foot-in-the-door: A multi- turn jailbreak for LLMs,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Foot-in-the-door: A multi- turn jailbreak for LLMs,

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.319328Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:01.201235Z digest=sha256:cc6f7a899c06f3f7e9f5660cc0265a31bc2dc5bf87c5c40ff33c79244972eaff

Observation 2f6ab5d0-e13c-4c95-9801-f73d70b71723 · outbound

This paper cites Leveraging the Context through Multi-Round Interactions for Jailbreaking Attacks.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Leveraging the Context through Multi-Round Interactions for Jailbreaking Attacks

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:01.366073Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:01.366073Z digest=sha256:25a08c51b54ff18f753c16fa98f66c4fadde8d89333606f6c2f2d487d549233e

Observation c1c959c2-b2b0-483c-b504-5c3df9b3b704 · outbound

This paper cites Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:01.466125Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:01.466125Z digest=sha256:64b993b04c986ea4d6115bdf7591ea54f5d019c424d3195705c092225af3dc27

Observation ecbe0251-ec47-484f-ac2e-f34112f266d0 · outbound

This paper cites Masterkey: Automated jailbreaking of large language model chatbots,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Masterkey: Automated jailbreaking of large language model chatbots,

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.247675Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:01.557122Z digest=sha256:eda988dde46f87e6541bc6bab5432744ed2ac1a48535a19dc287158373d34640

Observation 6b42f3bf-9a72-418f-a5ee-904ff7ee36c9 · outbound

This paper cites Automated Red Teaming with GOAT: the Generative Offensive Agent Tester.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Automated Red Teaming with GOAT: the Generative Offensive Agent Tester

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:01.641441Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:01.641441Z digest=sha256:2b2a590b17b34221d41fa2bb14f3383b5a3b4175be810c08a9ab602f5305a57b

Observation 0a5ba394-e867-4c2b-b1cd-633f2d686784 · outbound

This paper cites Strategize Globally, Adapt Locally: A Multi-Turn Red Teaming Agent with Dual-Level Learning.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Strategize Globally, Adapt Locally: A Multi-Turn Red Teaming Agent with Dual-Level Learning

Reference 59

Resolution
verified exact
local_arxiv, observed 2026-08-06T00:32:08.142664Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:01.734958Z digest=sha256:86c6a6467caaf48d099b65849d8016f06518838698150617b0372c484ce7ce3a

Observation aa2b3761-a635-4c4f-b46f-7bfb360c4877 · outbound

This paper cites Tempest: Autonomous Multi-Turn Jailbreaking of Large Language Models with Tree Search.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Tempest: Autonomous Multi-Turn Jailbreaking of Large Language Models with Tree Search

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:01.874179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:01.874179Z digest=sha256:e1a80c0612b87a392982163a5e7c6f60cf1f17f55ce6ababc1683be81faf0fe6

Observation d588199e-7137-435a-a72d-6bda0eea9447 · outbound

This paper cites X-Teaming: Multi-Turn Jailbreaks and Defenses with Adaptive Multi-Agents.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks X-Teaming: Multi-Turn Jailbreaks and Defenses with Adaptive Multi-Agents

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:01.993974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:01.993974Z digest=sha256:9516980c43007e15080a1f821350d239e3101d5a72c7e456b0f58824ff33f805

Observation c6e00d92-fd8d-4195-a142-246f2e5e3803 · outbound

This paper cites Safe in isolation, dangerous together: Agent-driven multi-turn decomposition jailbreaks on LLMs,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safe in isolation, dangerous together: Agent-driven multi-turn decomposition jailbreaks on LLMs,

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.074461Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:02.065580Z digest=sha256:99c1ccc94d766b44348409e011e17fbd1b0e4dce0533e858552260cfb47977ab

Observation 5c6a294a-45b9-4ab2-9cb9-9e6a3bdf7d9d · outbound

This paper cites Prompt, Divide, and Conquer: Bypassing Large Language Model Safety Filters via Segmented and Distributed Prompt Processing.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Prompt, Divide, and Conquer: Bypassing Large Language Model Safety Filters via Segmented and Distributed Prompt Processing

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.155613Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.155613Z digest=sha256:9a21afb53ceb2b900898170a74d9c941969ff6733e6789cfdca124bf3ff8d127

Observation 7ed41cf7-1526-48e1-8dd2-6471e029d600 · outbound

This paper cites Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.310068Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.310068Z digest=sha256:b487072ade1b5c73e103a903ca9f18f457b4eec1e51027a112d4fe5341d272bb

Observation d42c154f-a99c-45f2-a7ea-8f2cd01181ce · outbound

This paper cites Sok: Evaluating jailbreak guardrails for large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sok: Evaluating jailbreak guardrails for large language models,

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.401447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.401447Z digest=sha256:552484e131592da089f5cd51db6e438744a3fda87552388e7982f1377ce85d73

Observation b7c6a29f-a859-4520-9795-22f6528b60c9 · outbound

This paper cites Prompt-based jailbreaking of leading llm chatbots: A survey of attacks and defenses,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Prompt-based jailbreaking of leading llm chatbots: A survey of attacks and defenses,

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.048115Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:02.544339Z digest=sha256:ab9bb68768b7d33d8c06cc4b8cc9ec779bfa5889142a18cc7ff6d9f4cb38d3e4

Observation f9cbcb8c-5570-4e46-a76b-b0d6fa736dd8 · outbound

This paper cites SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.668360Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.668360Z digest=sha256:ae7f6756a6b25b26d51d6bf0f2416d7295e6245c0d4ad8fecf7845e27ec577f9

Observation 7d6c9d96-6eec-4edc-a17e-bed509f768e8 · outbound

This paper cites Hon- eytrap: Deceiving large language model attackers to honeypot traps with resilient multi-agent defense,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Hon- eytrap: Deceiving large language model attackers to honeypot traps with resilient multi-agent defense,

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.757612Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.757612Z digest=sha256:1cd68accffb326e9e15536c34fdcc32905654d3d598338c7aa9fcd7d8b849e6c

Observation b8ea8cf3-74fc-45e5-90a4-e0ecdcc7f1af · outbound

This paper cites SoK: Robustness in Large Language Models against Jailbreak Attacks.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks SoK: Robustness in Large Language Models against Jailbreak Attacks

Reference 69

Resolution
verified exact
local_arxiv, observed 2026-08-06T00:32:07.498813Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:02.888403Z digest=sha256:be17d4ec32e4d4ece6a28406390ca89aaa6c510abe6a38b8565da6635c540cd4

Observation f3521345-0fb3-4029-b89f-16ddec124c0e · outbound

This paper cites Security and privacy challenges of large language models: A survey,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Security and privacy challenges of large language models: A survey,

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:02.957358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:02.957358Z digest=sha256:cba52e9d108ec4ccfd0f4dfc3a19fa4e84130265ff5fc8f0df8c971a3d60f7d5

Observation a97d428a-fceb-4be6-8fc4-ca17cae119cd · outbound

This paper cites Jailbreak Attacks and Defenses Against Large Language Models: A Survey.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreak Attacks and Defenses Against Large Language Models: A Survey

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:03.047259Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:03.047259Z digest=sha256:6fff8f907f5e3e677ae24d7cb51c2e7e59e7ddf8fb106df0bc7b6cdab3f9cabb

Observation 82304e3e-518f-454f-b115-e4f1deaee3ea · outbound

This paper cites How alignment and jailbreak work: Explain LLM safety through interme- diate hidden states,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks How alignment and jailbreak work: Explain LLM safety through interme- diate hidden states,

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:11.003027Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.114301Z digest=sha256:f6f75b34be3935323f3e5e80a71ad41c57068e3bbbf207bc27591f3b1ccb51b0

Observation 926fc726-8b48-467b-92d0-81271a535805 · outbound

This paper cites Refusal in language models is mediated by a single direction,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Refusal in language models is mediated by a single direction,

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:10.887691Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.163474Z digest=sha256:9c8fe0c6439bac5876c7a3bd4c1d658b0e7eea5e3dfc86aaac5f55c7d25bbaa6

Observation 043cceac-e061-467a-ba4f-5526c9b4e407 · outbound

This paper cites Analogy-based multi-turn jailbreak against large language models,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Analogy-based multi-turn jailbreak against large language models,

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:10.679596Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.252443Z digest=sha256:620d4978d6e80be8308196d81b4657eba9eba19b5565e1e7154cb5cc16577154

Observation 3d3786ea-ab62-4bf5-9dcd-f29c6f26dcd6 · outbound

This paper cites Derail Yourself: Multi-turn LLM Jailbreak Attack through Self-discovered Clues,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Derail Yourself: Multi-turn LLM Jailbreak Attack through Self-discovered Clues,

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:03.338865Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:03.338865Z digest=sha256:542ee459422bc762bad3708ad1f79ac463c6ca110d26b20f2b3a64c9d2c580c9

Observation ab8bfe1c-295d-4435-bdd2-caee2c1d7bf3 · outbound

This paper cites Reasoning-Augmented Conversation for Multi-Turn Jailbreak Attacks on Large Language Models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Reasoning-Augmented Conversation for Multi-Turn Jailbreak Attacks on Large Language Models

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:03.417230Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:03.417230Z digest=sha256:efe5bc7a1cb23541f0bfccf977ec254c72ec28cdb664abe08caab3721704dcd8

Observation d9fc73cf-d792-4d98-94ae-f5207bc627d2 · outbound

This paper cites Icon: Intent-context coupling for efficient multi-turn jailbreak attack,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Icon: Intent-context coupling for efficient multi-turn jailbreak attack,

Reference 77

Resolution
verified exact
raw_fallback, observed 2026-08-06T00:32:07.159559Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.494338Z digest=sha256:728387e2003beef373b2eb9c8cb926ab3ca42c7a7a0fbc8d1ef5cba3c5fb6dcb

Observation 92d2c651-a785-4a19-863e-3548618c009f · outbound

This paper cites Imposter.AI: Adversarial Attacks with Hidden Intentions towards Aligned Large Language Models.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Imposter.AI: Adversarial Attacks with Hidden Intentions towards Aligned Large Language Models

Reference 78

Resolution
verified exact
local_arxiv, observed 2026-08-06T00:32:06.789503Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.566097Z digest=sha256:407c492603c1b9b716753cdd3769d38b056aab9c5faba431f6ac3e6717e90cdc

Observation 66772022-4e13-4091-9227-62da7fa4a7fb · outbound

This paper cites Jigsaw puzzles: Split- ting harmful questions to jailbreak large language models in multi- turn interactions,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jigsaw puzzles: Split- ting harmful questions to jailbreak large language models in multi- turn interactions,

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:10.488423Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.632919Z digest=sha256:610ecd7a8be8c0a56ee04da5c2374e032ba4b0ad8fd9ec73995bb34701afb67d

Observation bab2029c-1c31-41e2-9a7c-9bb63166a6c7 · outbound

This paper cites Speak Out of Turn: Safety Vulnerability of Large Language Models in Multi-turn Dialogue.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Speak Out of Turn: Safety Vulnerability of Large Language Models in Multi-turn Dialogue

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:03.725656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:03.725656Z digest=sha256:61f11433ac4f3c83ebb208ff14c6166309d3e51643d0c7278a4d35e676574cd5

Observation 0725efb6-4f12-4725-b318-224cac0672b1 · outbound

This paper cites MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:03.813752Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:03.813752Z digest=sha256:4173a4d6d0e772fc0003e34e214d971801e01094ea52cd30c2fcf16172e1eac2

Observation 4d993044-2361-400f-928d-bc5f74a9ca81 · outbound

This paper cites Siren: A Learning-Based Multi-Turn Attack Framework for Simulating Real-World Human Jailbreak Behaviors,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Siren: A Learning-Based Multi-Turn Attack Framework for Simulating Real-World Human Jailbreak Behaviors,

Reference 82

Resolution
verified exact
raw_fallback, observed 2026-08-06T00:32:06.406267Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.894827Z digest=sha256:98f6bc1bb1e5e79987b9d4ea851dd3a938ee1fcbab3b7c4ba202eaefc7a9acd3

Observation 076552ef-0e08-42a0-8d2f-311aa3765703 · outbound

This paper cites Incremental exploits: Efficient jailbreaks on large language models with multi-round conversational jailbreaking,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Incremental exploits: Efficient jailbreaks on large language models with multi-round conversational jailbreaking,

Reference 83

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:10.300942Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:03.969138Z digest=sha256:f1ba11350a395bd10163baa04a798ee1111cfbefa30eb25874a227568d4e0744

Observation f59ab08c-020d-47f4-b020-addc7789e143 · outbound

This paper cites CoopGuard: Stateful Cooperative Agents Safeguarding LLMs Against Evolving Multi-Round Attacks.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks CoopGuard: Stateful Cooperative Agents Safeguarding LLMs Against Evolving Multi-Round Attacks

Reference 84

Resolution
verified exact
local_arxiv, observed 2026-08-06T00:32:06.083513Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.056738Z digest=sha256:d7f7fb71a5a4182453717d51d6f8f0fa727adbba63f5114f4fbafcd41cd63178

Observation 61ca63f3-f7cc-4674-aecb-2c6a877b5f42 · outbound

This paper cites Multi- turn jailbreaking large language models via attention shifting,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Multi- turn jailbreaking large language models via attention shifting,

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:09.892715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.125373Z digest=sha256:97eb74926d82139ea5bd39d04803fe569c4e2540e68c3b1ec6d3ffa41b9e9c92

Observation 6f2a0adf-ec4f-49fc-913b-16c9ddc03936 · outbound

This paper cites Efficient jailbreak attack sequences on large language models via multi- armed bandit-based context switching,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Efficient jailbreak attack sequences on large language models via multi- armed bandit-based context switching,

Reference 86

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:09.660541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.224060Z digest=sha256:4180cdfb21e275e6f58709d3c2e7a513de88b384a1c7de26a637ab4b972d4745

Observation 24b1c6a4-27b5-43c1-b0e0-2ecffa2d8602 · outbound

This paper cites Jailbreaking large language models through iterative tool-disguised attacks via reinforcement learning,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking large language models through iterative tool-disguised attacks via reinforcement learning,

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:04.319422Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:04.319422Z digest=sha256:f70413d6a53532bd6b3ea66e3162ed4f855d19cbde3706f28d26e577882ba10f

Observation afb91035-ec2b-4af9-abcf-dae7b523cba3 · outbound

This paper cites Sema: Simple yet effective learning for multi-turn jailbreak attacks,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sema: Simple yet effective learning for multi-turn jailbreak attacks,

Reference 88

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:04.435709Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:04.435709Z digest=sha256:2969794bfde8f2f17fb33ff079f92778a41e59ab38cbfecaf320f6b1954b247c

Observation 7e351c69-5e56-4fc3-9e3b-b3a00197fa6f · outbound

This paper cites RedCoder: Automated Multi-Turn Red Teaming for Code LLMs.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks RedCoder: Automated Multi-Turn Red Teaming for Code LLMs

Reference 89

Resolution
verified exact
local_arxiv, observed 2026-08-06T00:32:05.527855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.530222Z digest=sha256:855e5ffb3d20f76abc9868f87ba77d5b08a6be75421c547a500f0c4795547af3

Observation b62a937e-c4f5-481e-b396-deb60e0be59a · outbound

This paper cites Break Me If You Can: Self-Jailbreaking of Aligned LLMs via Lexical Insertion Prompting.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Break Me If You Can: Self-Jailbreaking of Aligned LLMs via Lexical Insertion Prompting

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:04.600055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:04.600055Z digest=sha256:ab91d240f6caf70e811b643417d8bd2bbe03f13dc93ebd3551c18504d4506dd5

Observation 483554e4-9234-4e79-9d61-34e7b145731e · outbound

This paper cites I know what you asked: Prompt leakage via kv-cache sharing in multi-tenant llm serving.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks I know what you asked: Prompt leakage via kv-cache sharing in multi-tenant llm serving

Reference 91

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:09.473026Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.668588Z digest=sha256:6d48bb8438d3b689cee56bda1ca59cb6609dc0f20f59f63b0f44442cec6f9f45

Observation bfa78f89-88b1-47e5-a5d2-b4ece3ff5afa · outbound

This paper cites Pleak: Prompt leaking attacks against large language model applications,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Pleak: Prompt leaking attacks against large language model applications,

Reference 92

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:09.315622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.737414Z digest=sha256:2d4ed04d2405a911e0ffdc72725cc7583ca8e5df48c0071a2f37d32a1028f0e6

Observation 51a76467-7112-4432-ab00-ee5fc85d55c0 · outbound

This paper cites Safedialbench: a fine-grained safety evaluation benchmark for large language models in multi-turn dialogues with diverse jailbreak attacks,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safedialbench: a fine-grained safety evaluation benchmark for large language models in multi-turn dialogues with diverse jailbreak attacks,

Reference 93

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:09.167357Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.831040Z digest=sha256:0d30bc28ea17d7de907fc83947ebaaf9f281ca934d41ae080d14c91a92b645b8

Observation 7589fda7-9ecb-47db-8d54-013aca918cf6 · outbound

This paper cites Agentharm: A benchmark for measuring harmfulness of llm agents,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agentharm: A benchmark for measuring harmfulness of llm agents,

Reference 94

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:08.981778Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:04.919048Z digest=sha256:b4328aebfa5fadcaf8955797a035fca3dbdeb8349329805351349ca8d60e8acb

Observation a11d1aff-4c4c-4723-9274-6b40c7dfaca8 · outbound

This paper cites Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:04.995556Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:04.995556Z digest=sha256:694e3508a1f72f6f168f41cb8176f1663562ab48649d140b2449b971871bef57

Observation 873285c7-9390-4192-b59f-e258f18a6098 · outbound

This paper cites MultiBreak: A Scalable and Diverse Multi-turn Jailbreak Benchmark for Evaluating LLM Safety.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks MultiBreak: A Scalable and Diverse Multi-turn Jailbreak Benchmark for Evaluating LLM Safety

Reference 96

Resolution
unresolved
no resolver link, observed 2026-08-06T00:32:05.121298Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T00:32:05.121298Z digest=sha256:4cb7e127b68e5843fd7979ce438c4f35192b26e9d43f9f4ea778b788e277ebaa

Observation e1951eec-5ccd-47d1-af44-5d220ed27450 · outbound

This paper cites For the MRCJ-side experiment, auxiliary questions and malice-level labels follow the MRCJ release [83] without modification.

SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks For the MRCJ-side experiment, auxiliary questions and malice-level labels follow the MRCJ release [83] without modification

Reference 97

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T00:32:08.781491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-06T00:32:05.231888Z digest=sha256:0defb27c209811f8aef1dc438ad63769d7cc3b9552822be2e1d8906b94ec7e51

Pith citing papers

No inbound Pith citation observations are available.