Pith. sign in

Paper Citation Record · LEDGER

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

As of 17 August 2026, this Paper Citation Record lists 56 of 56 outbound references and 6 inbound Pith citation observations for arXiv:2411.11496.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2411.11496 v3

Coverage vector

measured 56 of 56 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T18:32:12.165931Z

measured 62 of 62 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 6 of 6 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-12T20:53:14.962860Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-11T11:11:05.378354Z

Reference resolution

56 of 56 outbound references displayed

  • verified exact0
  • verified fuzzy22
  • unresolved34
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9c8f2ccc-7575-42f4-aefe-3772e2c8516d · outbound

This paper cites https://huggingface.co/ stabilityai/stable- diffusion- xl- base- 1.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://huggingface.co/ stabilityai/stable- diffusion- xl- base- 1

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:13.010120Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.934310Z digest=sha256:37831553e5f67a458dcd1e716f3a2b6ff0d5d63f301150c6d3dadfff65479a51

Observation 7759ad15-81f0-4a11-b74a-4a7abb0b18be · outbound

This paper cites https : / / learn.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / learn

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.997619Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.939024Z digest=sha256:8a13fba99ebaf86ff05e51a02b1376e78e9f2164cdee8aa545deeb35aae33b3e

Observation b78b986a-bdb6-40d4-ba28-59d49f53ac3b · outbound

This paper cites https://perspectiveapi.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://perspectiveapi

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.980128Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.943586Z digest=sha256:b19a3dc1de824767fb37d5a5992f417a8ba382369d223d71169c4118d75afadc

Observation 88b87681-ce57-4009-8c69-20832da283a0 · outbound

This paper cites https : / / about.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / about

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.967954Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.947558Z digest=sha256:0cbe608af48b4b6016038ee4c4f8a57fd86a6be276984801a8f2aeab9a444258

Observation ff49843b-406c-4c22-87c7-61f9d4d666f0 · outbound

This paper cites https://platform.openai.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https://platform.openai

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.954925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.951816Z digest=sha256:58c7fd50a73210e363477d728d2d3c16ff8a120177ab6d3f5515e9c20255834e

Observation e300614c-95c2-413c-862d-8f26ec7287e9 · outbound

This paper cites https : / / openai.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https : / / openai

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.943073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.955900Z digest=sha256:450b5908cdcd7e63bf2c40a7a9d0e5020d675a56401fb53afdf3b0a13137c8b1

Observation cad35705-3506-4f7c-8e1d-646a5639eae7 · outbound

This paper cites https: //cloud.google.com/vision/.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models https: //cloud.google.com/vision/

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.932164Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.960746Z digest=sha256:6e368a5552344fbfa83915bf787bebaaa106644f6236d7b30a279de9ef4af1e1

Observation 4c4b64b6-44a1-4759-b7dd-23dd16ddac3c · outbound

This paper cites Qwen Technical Report.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Qwen Technical Report

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.964701Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.964701Z digest=sha256:39acf64dee82810c8b3f42c263952708044acd45f53572497c7b8d11034b6e5f

Observation 733fa2f7-32fe-4134-8350-d7b33ec50e01 · outbound

This paper cites Finding safety neurons in large language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Finding safety neurons in large language models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.968635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.968635Z digest=sha256:710b414140e09e58c3ecdf9b9dd203bb393eda05b02e62385e12e14dec375d8a

Observation 9b909f08-ad8c-4ce2-9baa-33d94c49e373 · outbound

This paper cites How Far Are We to GPT-4V? Closing the Gap to Commercial Multimodal Models with Open-Source Suites.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How Far Are We to GPT-4V? Closing the Gap to Commercial Multimodal Models with Open-Source Suites

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.972183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.972183Z digest=sha256:1e1732ffe1ce86f8a67b5637874e277c7e662453a1a372e9494af4427c3e88bc

Observation 559cb600-60fa-4efd-8323-6ac6e6e73c67 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.976454Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.976454Z digest=sha256:9c6ca4d4b71b6252d0d19c600a4ce0f66182d9d7e25b8225acbac0ecf76281f5

Observation bf4519cf-146a-441e-98b8-3c50ac0380f6 · outbound

This paper cites Gonzalez, Ion Stoica, and Eric P.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Gonzalez, Ion Stoica, and Eric P

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.921210Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.981451Z digest=sha256:a99357052d4ac9b0eae7915409a1ef2b55c1e86f8462c7a1607e342a2811082b

Observation 9726145c-b106-4194-bf1c-a7325c63c2bc · outbound

This paper cites Instructblip: Towards general-purpose vision-language models with instruction tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Instructblip: Towards general-purpose vision-language models with instruction tuning

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.910280Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.986035Z digest=sha256:9ef37e0c4313896be2c1c09d8159e8143aa868f511f1242d63eeffca944e5fde

Observation 2fa8d6d2-45db-43b6-a5c7-557e62be9617 · outbound

This paper cites The impact of regular expression denial of service (redos) in practice: an empirical study at the ecosys- tem scale.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models The impact of regular expression denial of service (redos) in practice: an empirical study at the ecosys- tem scale

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.898880Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:11.990423Z digest=sha256:397b95194458d20cc14be4fc846280a936226847c3457ee10b2895b25c8cc729

Observation 85136503-5dd9-4cb7-a491-9d14f3192fb8 · outbound

This paper cites Imagenet: A large-scale hierarchical image database.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Imagenet: A large-scale hierarchical image database

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:11.995853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:11.995853Z digest=sha256:cd4473babf8a4ce20c0878df1ea3af4b7fdd41af4635071eaf938d73e669614b

Observation 208fd62b-c3bd-418e-82e3-dd2d5de61188 · outbound

This paper cites How robust is google’s bard to adversarial image attacks? CoRR, 2023.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How robust is google’s bard to adversarial image attacks? CoRR, 2023

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.876656Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.000454Z digest=sha256:0e96de6b79899bec63feb5c8f5d6285ff7fbcdefda55de721779f3978f05e3e5

Observation 3694931c-d538-4b80-a538-880f055f05bc · outbound

This paper cites Quantifying and Attributing the Hallucination of Large Language Models via Association Analysis.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Quantifying and Attributing the Hallucination of Large Language Models via Association Analysis

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.004336Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.004336Z digest=sha256:6832eac02e4725f0f4d7d875d145b3f73fbe50cf58a8657ab4db98d8d54f3222

Observation 7f66642a-eb7d-443e-a0ea-ed7e5c5cbd49 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.008410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.008410Z digest=sha256:995e6bab3b6973f78c5a76cba4798e44625a4610b80b7da3390129c367662d52

Observation 62e3a8c4-c390-445b-a33c-5daf7fdd98a5 · outbound

This paper cites Adversarialeak: External information leakage attack using adversarial sam- ples on face recognition systems.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Adversarialeak: External information leakage attack using adversarial sam- ples on face recognition systems

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.864693Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.013016Z digest=sha256:100d8d48c81647ea21d2d63da2ac4c56eca156665f30b8c3b16e1d52da4b0a49

Observation c73a51b0-0539-404c-9260-ce3311968369 · outbound

This paper cites ART: Automatic Red-teaming for Text-to-Image Models to Protect Benign Users.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models ART: Automatic Red-teaming for Text-to-Image Models to Protect Benign Users

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.016710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.016710Z digest=sha256:306be3c7e88b8806d6762d6c4af12fac2233d4f59830e366c080d0da6af980cc

Observation 4c487f4f-c2a7-4a0b-a67c-cee9873047eb · outbound

This paper cites Blip- 2: Bootstrapping language-image pre-training with frozen image encoders and large language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Blip- 2: Bootstrapping language-image pre-training with frozen image encoders and large language models

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.021824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.021824Z digest=sha256:0fcb31d731a7432c3311bcf09e866ed22002250781ae796150c3aad8a51236a3

Observation 99423525-8070-44d9-b26f-21fefa7a87cb · outbound

This paper cites Vila: On pre-training for visual language models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Vila: On pre-training for visual language models

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.847960Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.025509Z digest=sha256:b5b6d549915168f553104675ee17cfb8adbd766465f2284efaf816b55034fcb4

Observation 4a5b3de6-0611-43d4-8149-34536a215930 · outbound

This paper cites Microsoft coco: Common objects in context.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Microsoft coco: Common objects in context

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.836743Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.029137Z digest=sha256:32a446e7cb1f165d76f238b75d5325309ebaf52942306dd527ea0b5c7b55e35a

Observation 6da0c67e-4709-4544-a206-779cb83e86d6 · outbound

This paper cites Visual instruction tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Visual instruction tuning

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.032637Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.032637Z digest=sha256:7e6bf99ba526b054402fcdc6bbe07e83345946355b250ac2721238dd1a3180f9

Observation 8628bdaa-8cc2-422f-b553-98abb77a0eb0 · outbound

This paper cites Grounding DINO: Marrying DINO with Grounded Pre-Training for Open-Set Object Detection.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Grounding DINO: Marrying DINO with Grounded Pre-Training for Open-Set Object Detection

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.036245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.036245Z digest=sha256:757bbe8a9328a40c65e9a1c1df1324169c7feb07625b3414fa3f8f29dea94747

Observation 04cd695e-8c49-44d7-8fae-e7fa3a4320f7 · outbound

This paper cites Query-relevant images jailbreak large multi-modal models,.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Query-relevant images jailbreak large multi-modal models,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.040329Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.040329Z digest=sha256:b74876c0562ce4bb6865981e48cd8348c05da01ddd1b488bca697fc2bd3d1f99

Observation f7fdd5fc-44cf-4190-8751-c78ce0146c08 · outbound

This paper cites Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.043993Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.043993Z digest=sha256:1fa8a9224e77f45c06dc6528e06df859a7889b68afe9c1d4959786208dbc668b

Observation 07a23e2a-5054-4919-9251-23b983a1a0dc · outbound

This paper cites Leveraging multimodal features and item-level user feedback for bundle construction.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Leveraging multimodal features and item-level user feedback for bundle construction

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.813983Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.048289Z digest=sha256:4bb7a8896a50b439d5053a0d9789f2090b524db7ceef556d52d3ea9e19a2c03e

Observation 03649059-b233-49d2-b99a-09d1d2a96c25 · outbound

This paper cites The parallelism trade- off: Limitations of log-precision transformers.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models The parallelism trade- off: Limitations of log-precision transformers

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.802929Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.051720Z digest=sha256:7d0fb175b7b773280fdcb0a4ca91e7c82df2d11e395f2cf22b2025dcb8657cb4

Observation 2e4b6b9b-68b1-4206-a6fb-b445a88dfcae · outbound

This paper cites Phishing attack, its detections and prevention tech- niques.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Phishing attack, its detections and prevention tech- niques

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.792517Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.055210Z digest=sha256:0b3b86c78849afb76b6d2d42ae7da7bb7645d793e82379c64c75d550fd95084f

Observation 25e094b6-27cb-4b8a-8dec-34d30cd6cc1b · outbound

This paper cites Jailbreaking Attack against Multimodal Large Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreaking Attack against Multimodal Large Language Model

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.059557Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.059557Z digest=sha256:7234c02d39a70502e86277e93ae9f2d51f886d1ff26edd816d9f05fc806647ba

Observation 2e474554-b4ca-49e8-81ca-b3b1978b958e · outbound

This paper cites Gpt-4o system card, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Gpt-4o system card, 2024

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.064029Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.064029Z digest=sha256:6b2c0d79e236ea2c00e2a14c25ae0b719cb2fd3a523484ebf12be37b2a5b3687

Observation 2a3f0dab-be4a-4365-8b34-ff52bead5f38 · outbound

This paper cites Politics 101 dataset, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Politics 101 dataset, 2024

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.772821Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.068315Z digest=sha256:d77f0a941c7cca1242eb1cddff8fac542b93b9c33268229bb0dec25c525d5e4c

Observation 0775c394-2d2c-463d-92ac-39519566bf7d · outbound

This paper cites An empirical study of real-world polymorphic code injection attacks.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models An empirical study of real-world polymorphic code injection attacks

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.760655Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.072999Z digest=sha256:009062ca06da4f54c5873290b4b2978f89313983b54c97ef7ef0519ff19ce36f

Observation e1d8d57f-9090-4a22-9fc6-73018f6b4d3e · outbound

This paper cites Learning transferable visual models from natural language supervi- sion.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Learning transferable visual models from natural language supervi- sion

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.077560Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.077560Z digest=sha256:3c4c200743a3f6210cf1cadd8f488d183ed4f5274290557318ed60ddaed5ffe6

Observation 7ead4504-be1b-44f8-b1af-20b73f9d1e93 · outbound

This paper cites Derail yourself: Multi-turn llm jailbreak attack through self- discovered clues.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Derail yourself: Multi-turn llm jailbreak attack through self- discovered clues

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.083138Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.083138Z digest=sha256:44341e9066de7ccef5de654089d6b152f9ab2d5ddf4efe94f7c9d6a0c5757ba8

Observation b5d7a389-4ce3-4349-9b33-1e1b49ba69d7 · outbound

This paper cites Celebrity face image dataset, 2024.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Celebrity face image dataset, 2024

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.741965Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.087240Z digest=sha256:508521d84c8d35365ae09567a0b18c575c026a18b71b509f15e41256b324d045

Observation fa6e4b4f-1134-4343-866d-d3a83534caa2 · outbound

This paper cites Exploring the Deceptive Power of LLM-Generated Fake News: A Study of Real-World Detection Challenges.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Exploring the Deceptive Power of LLM-Generated Fake News: A Study of Real-World Detection Challenges

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.091515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.091515Z digest=sha256:ad2d9e78053da31f18081ca867056418a2329d4b0129054272810a0de46738c4

Observation db6e23fd-caf5-4cde-bf7c-ee4f14aa05f1 · outbound

This paper cites Imgtrojan: Jailbreaking vision-language models with one im- age.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Imgtrojan: Jailbreaking vision-language models with one im- age

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.095487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.095487Z digest=sha256:14658803f1d2eae686bc8d5266c408c9ff5b2ca7ce3e6926956c7c4852e7802a

Observation a5dd3212-b408-4e6a-bafe-57b6186affd2 · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models LLaMA: Open and Efficient Foundation Language Models

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.099738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.099738Z digest=sha256:311a730d269347a72d6efa73bd8d9f436bcc4c93e4fca35e31a80ed6da65eb42

Observation 443e8014-41de-4700-b6e7-201aa233526c · outbound

This paper cites Bypassing the safety training of open-source llms with priming attacks.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Bypassing the safety training of open-source llms with priming attacks

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.730855Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.103423Z digest=sha256:43bf6501ec33657ddda5e8774e4a795b222e7eb64c0577cc19705ec5e040afed

Observation 0045e78b-a5a8-4029-8941-66841f60e215 · outbound

This paper cites Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.107044Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.107044Z digest=sha256:e8c17c35aeb8afb355b28bf7df7cab38152b27f0d8bbf21076233818d4911c62

Observation 58c6610b-1322-4991-a74b-2966f2b8e71f · outbound

This paper cites White-box Multimodal Jailbreaks Against Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models White-box Multimodal Jailbreaks Against Large Vision-Language Models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.112157Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.112157Z digest=sha256:77fa6a6cc3ce6ae80b14287219abadbc370483e81bef7e1c5ac8a1f7c361e210

Observation 8b07a41e-f589-4850-94ef-e730e811077a · outbound

This paper cites Safe Inputs but Unsafe Output: Benchmarking Cross-modality Safety Alignment of Large Vision-Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Safe Inputs but Unsafe Output: Benchmarking Cross-modality Safety Alignment of Large Vision-Language Model

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.116128Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.116128Z digest=sha256:a28ef0bb55649f206c0c7c2bd1393394218094046d48bfcaec2d7b3733adc080

Observation b2b8e955-d5f6-432c-ac1d-01af3eaae598 · outbound

This paper cites InstructTA: Instruction-Tuned Targeted Attack for Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models InstructTA: Instruction-Tuned Targeted Attack for Large Vision-Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.119717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.119717Z digest=sha256:0016380620750cf1c488db87e2f9dcfa6eef731f0ebc44c2b0ad3989fa6f9738

Observation ac52c24c-3ca5-416f-8f7b-1a5271ba8a31 · outbound

This paper cites MobileVLM: A Vision-Language Model for Better Intra- and Inter-UI Understanding.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models MobileVLM: A Vision-Language Model for Better Intra- and Inter-UI Understanding

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.123346Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.123346Z digest=sha256:e2c29ec6a8d80901630ea7f912e38aa2d8ccd375788edf8d66f6177f1e257898

Observation b0b97456-d873-4fc9-8563-43d88bec2923 · outbound

This paper cites Jailbreaking GPT-4V via Self-Adversarial Attacks with System Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreaking GPT-4V via Self-Adversarial Attacks with System Prompts

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.126647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.126647Z digest=sha256:187719284955f66e3e033298d7fc6e6ff1f6409f8e7acc021f60fe7c3b73d8e2

Observation 703d4bb8-85e8-46e2-89b7-656bb7e29f91 · outbound

This paper cites On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models On the Proactive Generation of Unsafe Images From Text-To-Image Models Using Benign Prompts

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.130886Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.130886Z digest=sha256:cce8407de301658896ea11630ce7323e4698203b79dcd154d90c4cc36e32c224

Observation e1af66a8-8689-4657-acb1-efc641385222 · outbound

This paper cites SEED-Story: Multimodal Long Story Generation with Large Language Model.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models SEED-Story: Multimodal Long Story Generation with Large Language Model

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.134723Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.134723Z digest=sha256:9b155fca62df889b06b740c547899883a294877197dbb43657f11c0e9dc00784

Observation ff31550b-44b9-42cb-9b21-da7caa2da275 · outbound

This paper cites Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.139219Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.139219Z digest=sha256:68cb3876419052cbcbb23ca80c44267f70af28269ceb6d11123ecddc3f6581e0

Observation a1d8d7d7-3004-4dfc-91c6-2fb29da2caa2 · outbound

This paper cites How Language Model Hallucinations Can Snowball.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models How Language Model Hallucinations Can Snowball

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.143681Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.143681Z digest=sha256:7e70ce5c7289f69978ec682dd8a5a5af59d6d87a44193bb1602a6c481fe1ab18

Observation 5d3e1ba2-a3bb-4347-bdc2-0c759dd65477 · outbound

This paper cites SVIT: Scaling up Visual Instruction Tuning.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models SVIT: Scaling up Visual Instruction Tuning

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.148371Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.148371Z digest=sha256:f46ff013fb9f52febeec542bacdcc1e2eef6060e3dd62a73bd7a4a9873eb805e

Observation d7a96450-b615-4b5f-a897-302bce6e66f9 · outbound

This paper cites Investigating and Mitigating the Multimodal Hallucination Snowballing in Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Investigating and Mitigating the Multimodal Hallucination Snowballing in Large Vision-Language Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.152743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.152743Z digest=sha256:ee3edb4549d9eb12e0a5fe07de7f9263650cd41c0f8041b64f935e641b584fc5

Observation 219cf973-3a9f-4f20-b841-18bbe80638b7 · outbound

This paper cites Analyzing and Mitigating Object Hallucination in Large Vision-Language Models.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Analyzing and Mitigating Object Hallucination in Large Vision-Language Models

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.156744Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.156744Z digest=sha256:0c648659ec6ba2b77f6916de1d023c37a9d2bba87d976562d9f04ae0cce88150

Observation 016ccc62-c30c-43da-aeb0-5c22c7b447c2 · outbound

This paper cites Harnessing Large Vision and Language Models in Agriculture: A Review.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Harnessing Large Vision and Language Models in Agriculture: A Review

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-12T18:32:12.161717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:32:12.161717Z digest=sha256:45df2a4e087353b97f042b63ffbbd4f5b686169ec44684befc573950cb5e9367

Observation 445281fe-dddf-4c82-8e29-0f438619d28a · outbound

This paper cites Sure, here are the detailed steps.

Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models Sure, here are the detailed steps

Reference 2024

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T18:32:12.718053Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T18:32:12.165931Z digest=sha256:a825d2eaf78da2547498af676a39427ddbe4c115cbb87d0a962b6fc6944effe4

Pith citing papers

Observation da43780d-4c4b-40d3-b49b-9decc3f873f5 · inbound

Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey cites this paper.

Jailbreak Attacks and Defenses against Multimodal Generative Models: A Survey Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-12T20:53:14.962860Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:53:14.962860Z digest=sha256:53e10c8f98e083d615942cbcada9b6879fcd64aae21c8e61334a698c8ef5bd32

Observation a9b93255-bbec-45b5-a49a-0dc2fe2598b3 · inbound

VLSBench: Unveiling Visual Leakage in Multimodal Safety cites this paper.

VLSBench: Unveiling Visual Leakage in Multimodal Safety Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T05:56:46.349602Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-12T05:56:46.349602Z digest=sha256:4ffde2283026094ddb0a8cd56e35af09ff0a41fc3d1d042fbb038ce306ceba3a

Observation c4445efa-845a-47c7-91c3-2a9bb63aef44 · inbound

AlphaAlign: Incentivizing Safety Alignment with Extremely Simplified Reinforcement Learning cites this paper.

AlphaAlign: Incentivizing Safety Alignment with Extremely Simplified Reinforcement Learning Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T15:48:01.327760Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T15:48:01.327760Z digest=sha256:3e944723c215b50fdcc7e9b0a7332f30bb445b7161713f242c85b30757856839

Observation 855a248a-b925-4a30-a8c6-18d17d876bef · inbound

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems cites this paper.

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-11T09:16:04.272622Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-10T16:07:31.602378Z digest=sha256:5cb15886a3b49c0e1c6874e2431687d1e3d0ac36f14e4aea057eb9010245e09f

Observation 86133c2f-bdc7-43ce-8f57-fa6e2d89ecbf · inbound

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs cites this paper.

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-11T11:11:05.382509Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-10T15:06:43.140580Z digest=sha256:2561591f720052c152f5bf0b8107efab884ef267c0ecc716b7be43c8a86eb62e

Observation 7904c619-980d-4e02-b5e4-df9d686399d9 · inbound

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination cites this paper.

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination Safe + Safe = Unsafe? Exploring How Safe Images Can Be Exploited to Jailbreak Large Vision-Language Models

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T00:14:37.967742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T00:14:37.967742Z digest=sha256:fa4ff00fcec73d932bc90ff077f022f56edca97f860aea980ed837f16f6286c2