Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T00:32:05.231888Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 96 of 96 outbound references and 0 inbound Pith citation observations for arXiv:2608.01117.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-06T00:32:05.231888Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
96 of 96 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation c32d0f65-0d69-489c-9ff0-cb07f2ccfc5e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Training language models to follow instructions with human feedback,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cd82891b-c1ae-4ae3-b844-6d4fa39a3ae8 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LongMemEval: Benchmarking Chat Assistants on Long-Term Interactive Memory
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7cf4770b-9453-4016-9da2-d844e599d76a · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Evaluating llm-based agents for multi-turn conversations: A survey,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 107e38ed-712a-419d-85e0-0507dde3a437 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Asleep at the keyboard? assessing the security of github copilot’s code contributions,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 97099a72-e91f-4f57-b75a-7eefc586c561 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Lost at c: A user study on the security implications of large language model code assistants,
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3076b682-3e56-43ed-a759-6efd71551ece · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on large language models for code generation,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 55dc6c33-1b30-438c-8ed6-44eed6e324d7 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a2029bb6-0699-46e5-a514-291b31988b8d · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks WorkflowLLM: Enhancing Workflow Orchestration Capability of Large Language Models
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cbf01be6-2260-4685-b781-8e80b89937c9 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agent security bench (asb): Formalizing and benchmark- ing attacks and defenses in llm-based agents,
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 00a3030a-f506-45f2-99f2-4f8c3aba4af9 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Isolategpt: An execution isolation architecture for llm-based agentic systems,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 294706d6-3404-4cd6-a2af-2386fbb77804 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 57277511-3f49-40d6-8416-6bc08c094404 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on agentic security: Applications, threats and defenses,
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 170be5de-46f6-4207-a713-99b883c15d5e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Ai agents under threat: A survey of key security challenges and future pathways,
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c9361ab2-8938-4ab0-9d3b-f02beb5b963b · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbroken: How does llm safety training fail?
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eab0f278-d10d-438e-813b-2401a695d349 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Malla: Demystifying real-world large language model integrated malicious services,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fa50e402-3b42-4b94-9033-1fb12224bd83 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Gptracker: A large- scale measurement of misused gpts,
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 038be16a-9700-4916-9d97-d048760d7abb · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Don’t listen to me: Understanding and exploring jailbreak prompts of large language models,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 60dbaa07-8da6-4ee7-9aca-fd1c3509bd56 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 78956061-563d-4bdb-b0e7-1ca23eca0450 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks From chatbots to phishbots?: Phishing scam generation in commercial large language models,
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8060fc06-a6e4-4195-b008-5e04a5731d9f · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Constitutional AI: Harmlessness from AI Feedback
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 73063fe6-64c2-48a2-b150-135e3e1c7b4f · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Improving llm safety alignment with dual-objective optimization,
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 03f8496c-c33c-4731-b267-3c85ee7978a7 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Fine-tuning aligned language models compromises safety, even when users do not intend to!
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f0b4a246-1771-4366-950b-a6ea4fb9a2d4 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Harmbench: a standardized evaluation framework for automated red teaming and robust refusal,
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation b3bf5573-465f-4cc6-a3df-eca75d6a31ef · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Wildteaming at scale: From in-the-wild jailbreaks to (adversarially) safer language models,
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 5b131fb9-1d32-43d0-b2c8-84fee66d32eb · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Improving alignment and robustness with circuit breakers,
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 0a567a2d-8569-43b6-b558-250895a07e85 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks PARDEN, Can You Repeat That? Defending against Jailbreaks via Repetition
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7b6a9354-23ae-494b-b36b-e17cfdf33fe1 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks On large language models’ resilience to coercive interrogation,
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 607fab59-35c0-40d8-bccb-8fae18d893b3 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks You only prompt once: On the capabilities of prompt learning on large language models to tackle toxic content,
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 97d673b5-a034-4a14-b363-f1f52f210252 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks {LLM-Fuzzer}: Scaling as- sessment of large language model jailbreaks,
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 5702cdc3-0182-421c-ab3c-01beae57348e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Mind the inconspicuous: Revealing the hidden weakness in aligned {LLMs}’refusal boundaries,
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 63bf2d99-03d0-4d2b-9737-81695d561695 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safety misalignment against large language models
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 95cc5bf5-3c65-4186-a227-0f87cad7268d · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Refusal is not an option: Unlearning safety alignment of large language models,
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation cbaabaae-24ed-4322-b4ec-65742247ef1c · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Mission impossible: A statistical perspective on jailbreaking llms,
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 4f185973-70e3-4682-a0b9-95ae43890d1e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A comprehensive study of jailbreak attack versus defense for large language models,
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation d11cbd9f-6724-4819-ac50-75b5cf13daed · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks “do anything now
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 4b5db5ce-47dc-452a-8e0e-c6cbdc633682 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks {TwinBreak}: Jailbreak- ing{LLM}security alignments based on twin prompts,
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 29beb297-5cc5-44cb-82c7-5a76d12c1f92 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 11b63b8b-e254-4c37-8a6c-8ed4a6a9cb93 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking black box large language models in twenty queries,
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 249ac1dd-68a7-4ef4-b4b0-651d0878fecc · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Tree of attacks: Jailbreaking black- box llms automatically,
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ea90a336-85bc-43ba-a0c0-1ee8f387c924 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction,
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f739a255-c0a2-4b4d-b79e-156ba68e789a · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sneakyprompt: Jailbreaking text-to-image generative models,
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 8a562615-5a73-4fbb-8794-286120f838d3 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Fuzz-testing meets llm- based agents: An automated and efficient framework for jailbreaking text-to-image generation models,
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation e7f34c33-4d5a-4f83-95c0-3c4f7292b930 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Modifier unlocked: Jailbreak- ing text-to-image models through prompts,
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 183d512f-8525-4ef8-a2bf-694b927d5b79 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 859f1718-dc3d-40f5-a1d7-a871b7cc5e00 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Exposing the guardrails:{Reverse- Engineering}and jailbreaking safety filters in{DALL· E}{Text-to- Image}pipelines,
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation ec09ada3-3d7f-404b-9b02-48bfb673b00d · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking llms: A survey of attacks, defenses and evaluation,
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 981c0708-ece5-4ac1-bbd4-364e0cf01a29 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Surrogateprompt: Bypassing the safety filter of text-to-image models via substitution,
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 54230e98-0de6-4e71-b28a-49d00c5cc524 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreakbench: An open robustness benchmark for jail- breaking large language models,
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation a4288414-39ae-4d79-9bd6-4c362022ffff · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LLMs Get Lost In Multi-Turn Conversation
Reference 50
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ef96daba-4418-4710-b59b-2fe6b172e9b7 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks A Survey on Multi-Turn Interaction Capabilities of Large Language Models
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 51f6832f-3f61-4b2a-8830-0224e9affcb8 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet
Reference 52
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 343c3b41-3deb-4a72-996f-2c4756e87d8c · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Great, now write an article about that: The crescendo{Multi-Turn}{LLM}jailbreak attack,
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 7cf8fb96-4b28-4bd2-817f-0cd67b59cda9 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Foot-in-the-door: A multi- turn jailbreak for LLMs,
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 2f6ab5d0-e13c-4c95-9801-f73d70b71723 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Leveraging the Context through Multi-Round Interactions for Jailbreaking Attacks
Reference 55
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c1c959c2-b2b0-483c-b504-5c3df9b3b704 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Multi-Turn Context Jailbreak Attack on Large Language Models From First Principles
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ecbe0251-ec47-484f-ac2e-f34112f266d0 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Masterkey: Automated jailbreaking of large language model chatbots,
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 6b42f3bf-9a72-418f-a5ee-904ff7ee36c9 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Automated Red Teaming with GOAT: the Generative Offensive Agent Tester
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0a5ba394-e867-4c2b-b1cd-633f2d686784 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Strategize Globally, Adapt Locally: A Multi-Turn Red Teaming Agent with Dual-Level Learning
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation aa2b3761-a635-4c4f-b46f-7bfb360c4877 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Tempest: Autonomous Multi-Turn Jailbreaking of Large Language Models with Tree Search
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d588199e-7137-435a-a72d-6bda0eea9447 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks X-Teaming: Multi-Turn Jailbreaks and Defenses with Adaptive Multi-Agents
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c6e00d92-fd8d-4195-a142-246f2e5e3803 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safe in isolation, dangerous together: Agent-driven multi-turn decomposition jailbreaks on LLMs,
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 5c6a294a-45b9-4ab2-9cb9-9e6a3bdf7d9d · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Prompt, Divide, and Conquer: Bypassing Large Language Model Safety Filters via Segmented and Distributed Prompt Processing
Reference 63
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7ed41cf7-1526-48e1-8dd2-6471e029d600 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d42c154f-a99c-45f2-a7ea-8f2cd01181ce · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sok: Evaluating jailbreak guardrails for large language models,
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b7c6a29f-a859-4520-9795-22f6528b60c9 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Prompt-based jailbreaking of leading llm chatbots: A survey of attacks and defenses,
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f9cbcb8c-5570-4e46-a76b-b0d6fa736dd8 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d6c9d96-6eec-4edc-a17e-bed509f768e8 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Hon- eytrap: Deceiving large language model attackers to honeypot traps with resilient multi-agent defense,
Reference 68
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8ea8cf3-74fc-45e5-90a4-e0ecdcc7f1af · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks SoK: Robustness in Large Language Models against Jailbreak Attacks
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f3521345-0fb3-4029-b89f-16ddec124c0e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Security and privacy challenges of large language models: A survey,
Reference 70
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a97d428a-fceb-4be6-8fc4-ca17cae119cd · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreak Attacks and Defenses Against Large Language Models: A Survey
Reference 71
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82304e3e-518f-454f-b115-e4f1deaee3ea · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks How alignment and jailbreak work: Explain LLM safety through interme- diate hidden states,
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 926fc726-8b48-467b-92d0-81271a535805 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Refusal in language models is mediated by a single direction,
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 043cceac-e061-467a-ba4f-5526c9b4e407 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Analogy-based multi-turn jailbreak against large language models,
Reference 74
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 3d3786ea-ab62-4bf5-9dcd-f29c6f26dcd6 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Derail Yourself: Multi-turn LLM Jailbreak Attack through Self-discovered Clues,
Reference 75
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ab8bfe1c-295d-4435-bdd2-caee2c1d7bf3 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Reasoning-Augmented Conversation for Multi-Turn Jailbreak Attacks on Large Language Models
Reference 76
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d9fc73cf-d792-4d98-94ae-f5207bc627d2 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Icon: Intent-context coupling for efficient multi-turn jailbreak attack,
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 92d2c651-a785-4a19-863e-3548618c009f · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Imposter.AI: Adversarial Attacks with Hidden Intentions towards Aligned Large Language Models
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 66772022-4e13-4091-9227-62da7fa4a7fb · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jigsaw puzzles: Split- ting harmful questions to jailbreak large language models in multi- turn interactions,
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation bab2029c-1c31-41e2-9a7c-9bb63166a6c7 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Speak Out of Turn: Safety Vulnerability of Large Language Models in Multi-turn Dialogue
Reference 80
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0725efb6-4f12-4725-b318-224cac0672b1 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue
Reference 81
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4d993044-2361-400f-928d-bc5f74a9ca81 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Siren: A Learning-Based Multi-Turn Attack Framework for Simulating Real-World Human Jailbreak Behaviors,
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 076552ef-0e08-42a0-8d2f-311aa3765703 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Incremental exploits: Efficient jailbreaks on large language models with multi-round conversational jailbreaking,
Reference 83
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f59ab08c-020d-47f4-b020-addc7789e143 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks CoopGuard: Stateful Cooperative Agents Safeguarding LLMs Against Evolving Multi-Round Attacks
Reference 84
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 61ca63f3-f7cc-4674-aecb-2c6a877b5f42 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Multi- turn jailbreaking large language models via attention shifting,
Reference 85
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 6f2a0adf-ec4f-49fc-913b-16c9ddc03936 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Efficient jailbreak attack sequences on large language models via multi- armed bandit-based context switching,
Reference 86
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 24b1c6a4-27b5-43c1-b0e0-2ecffa2d8602 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Jailbreaking large language models through iterative tool-disguised attacks via reinforcement learning,
Reference 87
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation afb91035-ec2b-4af9-abcf-dae7b523cba3 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Sema: Simple yet effective learning for multi-turn jailbreak attacks,
Reference 88
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7e351c69-5e56-4fc3-9e3b-b3a00197fa6f · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks RedCoder: Automated Multi-Turn Red Teaming for Code LLMs
Reference 89
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation b62a937e-c4f5-481e-b396-deb60e0be59a · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Break Me If You Can: Self-Jailbreaking of Aligned LLMs via Lexical Insertion Prompting
Reference 90
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 483554e4-9234-4e79-9d61-34e7b145731e · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks I know what you asked: Prompt leakage via kv-cache sharing in multi-tenant llm serving
Reference 91
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation bfa78f89-88b1-47e5-a5d2-b4ece3ff5afa · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Pleak: Prompt leaking attacks against large language model applications,
Reference 92
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 51a76467-7112-4432-ab00-ee5fc85d55c0 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Safedialbench: a fine-grained safety evaluation benchmark for large language models in multi-turn dialogues with diverse jailbreak attacks,
Reference 93
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 7589fda7-9ecb-47db-8d54-013aca918cf6 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agentharm: A benchmark for measuring harmfulness of llm agents,
Reference 94
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation a11d1aff-4c4c-4723-9274-6b40c7dfaca8 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks Agents under siege: Breaking pragmatic multi-agent llm systems with optimized prompt attacks,
Reference 95
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 873285c7-9390-4192-b59f-e258f18a6098 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks MultiBreak: A Scalable and Diverse Multi-turn Jailbreak Benchmark for Evaluating LLM Safety
Reference 96
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e1951eec-5ccd-47d1-af44-5d220ed27450 · outbound
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks For the MRCJ-side experiment, auxiliary questions and malice-level labels follow the MRCJ release [83] without modification
Reference 97
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
No inbound Pith citation observations are available.