Pith. sign in

Paper Citation Record · LEDGER

Adversarial Suffix Filtering: a Defense Pipeline for LLMs

As of 17 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 4 inbound Pith citation observations for arXiv:2505.09602.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.09602 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-15T21:32:35.094736Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 4 of 4 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-02T13:17:51.071271Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-02T13:26:59.313678Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy3
  • unresolved25
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9672373d-2124-4ca1-bcc8-f8e75c1136c1 · outbound

This paper cites A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:34.987054Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:34.987054Z digest=sha256:806f535be46ea27f7c497a124695336760cb946d920b0ed02a6275a777ae7e71

Observation 0f422e33-8533-47d6-b7a7-1c29d1544b2b · outbound

This paper cites Llm01:2025 prompt injection, Apr 2025.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Llm01:2025 prompt injection, Apr 2025

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T21:32:35.433836Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-15T21:32:34.991806Z digest=sha256:1fc846f6d5a1e1621b38b97f1e2f4ffda36691f13211477cbc63e5005cd8caed

Observation 748fb07d-0371-4687-9796-952dd541ee81 · outbound

This paper cites AmpleGCG: Learning a Universal and Transferable Generative Model of Adversarial Suffixes for Jailbreaking Both Open and Closed LLMs.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs AmpleGCG: Learning a Universal and Transferable Generative Model of Adversarial Suffixes for Jailbreaking Both Open and Closed LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:34.995516Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:34.995516Z digest=sha256:a45581d8078ffa5521f03445300df73468d5abed39333b801666a89d12cda564

Observation 3653e94c-c99b-491f-bc7a-23122575d2f6 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:34.999281Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:34.999281Z digest=sha256:4fa729896ff98cb5cd66adb99a8ea65d24856f7559aef99e0049db8e9f5f10f3

Observation 5cca18e6-8eae-4798-8b41-8b96311e0aee · outbound

This paper cites Segment any text: A universal approach for robust, efficient and adaptable sentence segmentation.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Segment any text: A universal approach for robust, efficient and adaptable sentence segmentation

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T21:32:35.423493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-15T21:32:35.003512Z digest=sha256:7693a456e79faaa4ff79b3f937ec2631f4369b44e87794ac01449a56d70e0fc8

Observation d3794bae-4d30-4f7c-8d80-6cb247cf57b5 · outbound

This paper cites BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.007373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.007373Z digest=sha256:5183e151fde2238682eee241d756f7d11cfcd072f05787328af24154fa3c543b

Observation 7d8eba85-300b-4352-9b4e-9cf80184c1d6 · outbound

This paper cites Certifying LLM Safety against Adversarial Prompting.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Certifying LLM Safety against Adversarial Prompting

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.011638Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.011638Z digest=sha256:41b40ebd215b804912ba6cbccba83f41245ce3e6045640d3ee52e3829d8c9300

Observation 68da643a-3549-496f-b972-405019b906f3 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.015375Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.015375Z digest=sha256:9188f59ce39bd5ddc07d83e7eb1b30960da680553e977aa27f28d41bc3e43754

Observation 0c449067-1b3b-4579-b62c-c68792d5507b · outbound

This paper cites Adversarial Training: A Survey.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Adversarial Training: A Survey

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.019242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.019242Z digest=sha256:e6924c65c274d4b271fed232b2ff220252bce56b3a2ca43a4aeed6a5fea38b7f

Observation 5e7f85de-d2f6-459e-873a-bd3df7ed1fc5 · outbound

This paper cites Efficient Adversarial Training in LLMs with Continuous Attacks.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Efficient Adversarial Training in LLMs with Continuous Attacks

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.023227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.023227Z digest=sha256:18fc5442649f7dc42cd79e9c04b8607efc6b8f92986293aa99ef31e3e7ab39c2

Observation fc0ff1a2-5a98-4988-b104-25f91b3289b9 · outbound

This paper cites Robust LLM safeguarding via refusal feature adversarial training.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Robust LLM safeguarding via refusal feature adversarial training

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.026829Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.026829Z digest=sha256:495facdc45f9e7af6d3d5ff4c4588a828787f3d3b7a63252248f54f88f25125f

Observation db22b0bd-e267-4afb-a91c-c15a05bf232e · outbound

This paper cites Fine-tuning Language Models with Generative Adversarial Reward Modelling.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Fine-tuning Language Models with Generative Adversarial Reward Modelling

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.030666Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.030666Z digest=sha256:9e2ca0b694287d122c8b1a748f11191b79f8ba77d8396a8479bc70c86aeb2f29

Observation b9333def-0361-4692-a91d-606c1842f185 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs StruQ: Defending Against Prompt Injection with Structured Queries

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.034365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.034365Z digest=sha256:f6ca8dd1e568906427bdb7793db965dbb68a4beabc7e2b85bba735fbff7068e3

Observation 43e3a7e8-dff9-442d-a31f-8b6fade67291 · outbound

This paper cites SafeDecoding: Defending against Jailbreak Attacks via Safety-Aware Decoding.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs SafeDecoding: Defending against Jailbreak Attacks via Safety-Aware Decoding

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.038618Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.038618Z digest=sha256:7ed44d9e1a7b96e68e1a5dc12974cebb93d96baa205536dfe969fd30da7d59ab

Observation 215f0602-dcbb-4f91-a6a3-695604c95c93 · outbound

This paper cites Enhancing Chat Language Models by Scaling High-quality Instructional Conversations.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Enhancing Chat Language Models by Scaling High-quality Instructional Conversations

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.042554Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.042554Z digest=sha256:33a6bc6becc2e9393e7a07d6d0b060918c454d9217becfceef9b306af64f398a

Observation b9eb8ed9-1139-4d70-80f9-b6604ffaa5ee · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.046094Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.046094Z digest=sha256:87a8d92432f5060c154b54c82403d71c413e3ffa9bb27a671d93f06a0628a1b2

Observation 42ac8c90-73cd-4576-a87d-4b9e99366f39 · outbound

This paper cites Bergeron: Combating Adversarial Attacks through a Conscience-Based Alignment Framework.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Bergeron: Combating Adversarial Attacks through a Conscience-Based Alignment Framework

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.049834Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.049834Z digest=sha256:dc5fc336feb4eb5f6d800ac723b2588ca182ea9d93c6827755c62b39909a9a92

Observation 08f47364-eb2f-4d91-93ee-c4c81d8e36c6 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.053550Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.053550Z digest=sha256:149124c4ffe250a3b1f1658867943dea1f6ff873328143e756d4a46d2e3baf57

Observation 06af661b-a81c-4f52-a412-300a2d976d40 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Detecting Language Model Attacks with Perplexity

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.057127Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.057127Z digest=sha256:a22b6e3539a5e30500495b843d801d81c9f3e7c7f39e281523087376f23ec010

Observation 4f57d49e-b0e2-4f83-a6aa-2d1f3a372529 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.060849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.060849Z digest=sha256:df3851bf5103667fdd39599c1ae0216ef443055ec2002b568e51f7689c8e1163

Observation e4c778d1-ec3d-4b31-bc9d-29703b9c7da5 · outbound

This paper cites an unresolved cited work.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Unresolved cited work

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.064483Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.064483Z digest=sha256:95760b0bc64ca48066f08598468bbecda58325c82ce2f7b510d0704aa919952b

Observation d8d3328e-e1f8-4129-8ada-839bbac22144 · outbound

This paper cites AmpleGCG-Plus: A Strong Generative Model of Adversarial Suffixes to Jailbreak LLMs with Higher Success Rates in Fewer Attempts.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs AmpleGCG-Plus: A Strong Generative Model of Adversarial Suffixes to Jailbreak LLMs with Higher Success Rates in Fewer Attempts

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.067969Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.067969Z digest=sha256:0b2f03d3ee38e82aa3a64885aacfe68523926344371b2d22e8834aa87f300b7f

Observation 447eb956-c90b-4bca-b7bd-cb34e5dda05a · outbound

This paper cites Hashimoto.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Hashimoto

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.071789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.071789Z digest=sha256:d913329bd0e8c291871712dea13da84ada74d9074fbd4e7aef1c034404ba902d

Observation e4b30abc-8ed8-4425-85f4-2d62a287d915 · outbound

This paper cites Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.075343Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.075343Z digest=sha256:aa82423f255a5cf8edfa5681f640206f9522ae4352c49e2965bf907651635f4a

Observation 6adaa47e-42d9-4dcf-b9df-e43746716f58 · outbound

This paper cites HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.078942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.078942Z digest=sha256:ac0d5b5bed1ed5b6b44ddf07b4ef5e08b41a1b15d6dece1bcc587fe450f9a084

Observation 838ff448-ce1e-488a-bd6f-d00cda66142b · outbound

This paper cites The language model evaluation harness, 07 2024.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs The language model evaluation harness, 07 2024

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.082718Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.082718Z digest=sha256:636f9bf725d36e3c9207c1b3e076c7408761ab41a5b512e5d7319752a0041111

Observation b8d89fc6-b39e-45fc-894f-f318517b86e4 · outbound

This paper cites The art of defending: A systematic evaluation and analysis of LLM defense strategies on safety and over-defensiveness.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs The art of defending: A systematic evaluation and analysis of LLM defense strategies on safety and over-defensiveness

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-15T21:32:35.086165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:32:35.086165Z digest=sha256:fab6cb00c6fd9ed996ee4b6d5fe6b86828235fdaa0986f9597f2157e4a89949f

Observation 447dab16-63d3-4535-8835-7c90c9826d61 · outbound

This paper cites Limitations.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Limitations

Reference 28

Resolution
malformed identifier
raw_fallback, observed 2026-08-15T21:32:35.400368Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-15T21:32:35.089899Z digest=sha256:7ed50973cb87d551904b42ca7afbeb444f41453389cdbcbf163682741b675bc3

Observation b241e1a0-e37b-4f19-adc7-68f81af1c3d4 · outbound

This paper cites Guidelines: • The answer NA means that the paper does not involve crowdsourcing nor research with human subjects.

Adversarial Suffix Filtering: a Defense Pipeline for LLMs Guidelines: • The answer NA means that the paper does not involve crowdsourcing nor research with human subjects

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-15T21:32:35.389715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-15T21:32:35.094736Z digest=sha256:3badfe25aefda6d492fc7ce8d89216df36a2de2df1c291b632f92b6da11144a2

Pith citing papers

Observation 149a16c1-6fc8-49da-ac1a-51837a15be89 · inbound

When Efficiency Backfires: Cascading LLMs Trigger Cascade Failure under Adversarial Attack cites this paper.

When Efficiency Backfires: Cascading LLMs Trigger Cascade Failure under Adversarial Attack Adversarial Suffix Filtering: a Defense Pipeline for LLMs

Reference 82

Resolution
verified exact
arxiv_id, observed 2026-05-20T00:02:53.687065Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-19T23:58:53.524203Z digest=sha256:de0a43f460be2423a2bbdb5869cedee00481b44d85816413bcae4cac9d24f49b

Observation abdbfdc1-2a74-4658-8510-9419612dd541 · inbound

SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak Attacks cites this paper.

SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak Attacks Adversarial Suffix Filtering: a Defense Pipeline for LLMs

Reference 18

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T13:26:59.315351Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=arxiv_source observed=2026-06-28T01:16:07.252429Z digest=sha256:98c90a9f6abdfe105d2186407c23d55e361d4f503998fcd075c4600b3a71dca8

Observation 13d9fd60-149f-42ea-9603-e4a87f41d5e6 · inbound

Words Speak Louder Than Code: Investigating Cognitive Heuristics in LLM-Based Code Vulnerability Detection cites this paper.

Words Speak Louder Than Code: Investigating Cognitive Heuristics in LLM-Based Code Vulnerability Detection Adversarial Suffix Filtering: a Defense Pipeline for LLMs

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-06-30T04:54:16.782387Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-30T04:52:35.384665Z digest=sha256:8975c04e362e0b4ec25ca55b493fea034957ecc3feae56b667eaef3c37dd4c7b

Observation 3c30d0be-8b2e-44a3-a29e-12e94e0a7653 · inbound

Robust Critics: Defending LLMs Against Multi-Turn Attacks cites this paper.

Robust Critics: Defending LLMs Against Multi-Turn Attacks Adversarial Suffix Filtering: a Defense Pipeline for LLMs

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T13:17:51.071271Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T13:17:51.071271Z digest=sha256:54aeff1eceb2add19107e6f7d5401eab622dc62ae83138457be0ddccdc70d945