Pith. sign in

Paper Citation Record · LEDGER

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

As of 21 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 13 inbound Pith citation observations for arXiv:2501.04931.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2501.04931 v2

Coverage vector

measured 49 of 49 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-10T21:26:00.715228Z

measured 62 of 62 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00

measured 13 of 13 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T19:45:09.747284Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-01T23:26:23.246616Z

Reference resolution

49 of 49 outbound references displayed

  • verified exact0
  • verified fuzzy16
  • unresolved32
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 3ef1a4f5-d399-42a9-8cc1-ba69bdf39c91 · outbound

This paper cites Detecting Language Model Attacks with Perplexity.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Detecting Language Model Attacks with Perplexity

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.481795Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.481795Z digest=sha256:7552b3f5934468235363a3a279c257004a3012d8a77ce1a888b32e644fbe4609

Observation 5afd6a26-c85c-42c5-89ee-51d968cf722b · outbound

This paper cites The claude 3 model family: Opus, sonnet, haiku.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The claude 3 model family: Opus, sonnet, haiku

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.820673Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.486865Z digest=sha256:9d508111b5288a2d68bcca3ca35423cf83f516285ab16d9bb322612feb8bfdf1

Observation 477660c9-be37-472f-9641-4f9af6440ed4 · outbound

This paper cites Qwen-VL: A Versatile Vision-Language Model for Understanding, Localization, Text Reading, and Beyond.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Qwen-VL: A Versatile Vision-Language Model for Understanding, Localization, Text Reading, and Beyond

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.491384Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.491384Z digest=sha256:c919bb43a2d4af5a1af8cf916d16279311ab051b41a9255ccabd8151783ab317

Observation 04645ac9-f31f-4d6a-a03f-587c9dadae01 · outbound

This paper cites Image Hijacks: Adversarial Images can Control Generative Models at Runtime.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.495860Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.495860Z digest=sha256:2bf33e3cc993b3595643a56e50833eda92c426008e765065dce051e45d5e0a31

Observation dc29fd35-08af-4c65-95c6-4eacf4731932 · outbound

This paper cites Cross-modal safety align- ment: Is textual unlearning all you need? arXiv preprint arXiv:2406.02575, 2024.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Cross-modal safety align- ment: Is textual unlearning all you need? arXiv preprint arXiv:2406.02575, 2024

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.500949Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.500949Z digest=sha256:f70c3e2c028a0c1d1ed122907411fe0611edffb8ba9711afdaa4ec9da854c910

Observation e17e05ba-0d4e-4908-8839-99d9cef32942 · outbound

This paper cites InternVL: Scaling up Vision Foundation Models and Aligning for Generic Visual-Linguistic Tasks.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency InternVL: Scaling up Vision Foundation Models and Aligning for Generic Visual-Linguistic Tasks

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.505914Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.505914Z digest=sha256:c449835ceb9c9a3a6e1f30f25a73c9e14445e2b76a99c7cd115eb6e564c3ff3b

Observation 1fb2f517-e268-4020-9eda-829a810feda8 · outbound

This paper cites Multilingual Jailbreak Challenges in Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Multilingual Jailbreak Challenges in Large Language Models

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.511602Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.511602Z digest=sha256:585a3ac3f650e1081e7387f32cdea33c602462e7c6b41e3f3cc7ec886ae04519

Observation 4dfeafce-76ce-4208-b96f-a3a4ad1612fc · outbound

This paper cites The Llama 3 Herd of Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The Llama 3 Herd of Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.516711Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.516711Z digest=sha256:e5f3763698affc3148fe6d1874cc8984e10a07befd58f8d62af9209779720921

Observation 58de6437-1fcc-45b6-b975-e6141587a160 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.521572Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.521572Z digest=sha256:b2a63c38d4c03c1086dfb0c18a9121acf0ecbd7e906b7510a9437a09716dbd3d

Observation ea995e30-831b-4880-a407-a8d98d724d4c · outbound

This paper cites an unresolved cited work.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unresolved cited work

Reference 10

Resolution
unresolved
raw_fallback, observed 2026-08-10T21:26:01.805060Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.526765Z digest=sha256:bbe409f119b4431e9ab6a136329b2e98d11160b6779574c5288382ad71a50fc1

Observation d79e8523-4f21-4abc-972e-40fcd556d1d4 · outbound

This paper cites How effective is bert without word ordering? implications for language under- standing and data privacy.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency How effective is bert without word ordering? implications for language under- standing and data privacy

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.790926Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.531893Z digest=sha256:57a422eb6e9e94bee76a0afe79c9a08c68d348d7f7b22a36a4842ea217cfa54a

Observation c22d0557-4713-41db-b299-990c8ce9173c · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.536830Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.536830Z digest=sha256:a4d9a0788ef6bfb056da006793fbff4288529c7be8c23ab07022ff278dbef103

Observation a72f43cf-0ae7-4d25-aba6-035c4a7312b7 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.541808Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.541808Z digest=sha256:87c8787c5a1470b1b433f5e61719442c3f7618067e8b7e911fe942078de17899

Observation cef14f9f-c31c-4f57-81e0-bf0972528647 · outbound

This paper cites LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.546599Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.546599Z digest=sha256:3fae385b2c3739c51989def0a2a408deeb4b5f03b7f7d357f3f7603bb3d54708

Observation ff50c3af-1b76-4efc-9b64-964e74bfd53b · outbound

This paper cites Images are achilles’ heel of alignment: Exploit- ing visual vulnerabilities for jailbreaking multimodal large language models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Images are achilles’ heel of alignment: Exploit- ing visual vulnerabilities for jailbreaking multimodal large language models

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.776604Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.551504Z digest=sha256:c44f5e4c270855e4602cd85b7769d9827e479c7712ac710b5b1d4980c806d842

Observation e75ffcd5-7b88-451e-ae13-4328eb288cd2 · outbound

This paper cites Images are Achilles' Heel of Alignment: Exploiting Visual Vulnerabilities for Jailbreaking Multimodal Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Images are Achilles' Heel of Alignment: Exploiting Visual Vulnerabilities for Jailbreaking Multimodal Large Language Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.556069Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.556069Z digest=sha256:5d44e14b3f415b4f1ac16ce3d880360e9b9c9a4cadfd770619a846f09fe524ad

Observation 18a21079-c356-41b5-ace6-61c5634b5b2a · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.560776Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.560776Z digest=sha256:ca9373735ec67a1326bb53924c166e40d667f93bcf9028bb265b0bf415097517

Observation b0dfae3f-0db6-4035-8791-68f49ab729a8 · outbound

This paper cites MM-SafetyBench: A Benchmark for Safety Evaluation of Multimodal Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MM-SafetyBench: A Benchmark for Safety Evaluation of Multimodal Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.565988Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.565988Z digest=sha256:1d1326558be6df94bb921a95f1de8451afea5f8067a8b4850d69b20ffaa2f2f4

Observation 82682c21-0be5-4bf2-a40c-59eac8645df2 · outbound

This paper cites G-Eval: NLG Evaluation using GPT-4 with Better Human Alignment.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency G-Eval: NLG Evaluation using GPT-4 with Better Human Alignment

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.570967Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.570967Z digest=sha256:1c1ca154b825cb393fc2deb946f49ef4eec09b5975e59b96b66f710e36b132c3

Observation b8b2fb19-dba5-4411-b78a-6dc686ee4e16 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.575679Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.575679Z digest=sha256:f8311cfdc3a26280d0127eada63bfc4eda73c57db6c6a3a081541d39c4d7151e

Observation ea219cf5-86f1-4d59-9a1d-63ba3852463e · outbound

This paper cites Jailbreaking Attack against Multimodal Large Language Model.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jailbreaking Attack against Multimodal Large Language Model

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.580882Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.580882Z digest=sha256:0b1831dfe2078f50f5a8396e69e3b1798d684d30d9b3f8adbe6ac5310a2fa9f6

Observation 07228777-a0d2-497c-8a4f-2673cddbd143 · outbound

This paper cites Perspectiveapi.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Perspectiveapi

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.759714Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.586688Z digest=sha256:4dfc524916fe006710db4ed33411597c2be2b4adf221548e249d26fe968049da

Observation f4065fc2-8abd-4481-9bcf-a40292810c49 · outbound

This paper cites an unresolved cited work.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unresolved cited work

Reference 23

Resolution
unresolved
raw_fallback, observed 2026-08-10T21:26:01.743851Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.591504Z digest=sha256:53958c83378672e5e81dcc0a92d6c0d3e3c48eb195efbbf2d4a35368edc6d747

Observation 70e31496-5d16-4f15-9515-f5e57e5557f8 · outbound

This paper cites Moderationapi.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Moderationapi

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.727703Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.595886Z digest=sha256:9844f2cbab07775d0a130d6836930e00c8b20367213012978b3873c0c7806cac

Observation a5244b82-3e3d-48f9-8bf4-42db6bc80368 · outbound

This paper cites Hello gpt-4o.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Hello gpt-4o

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.711507Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.600680Z digest=sha256:128440faf92dc0ba7f3b8c7f49ac31ac9761627355d12b8d8e93b70492b8fb4c

Observation 19f53698-b8df-41ac-bef1-cf92c072754d · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Visual adversarial examples jailbreak aligned large language models

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.695780Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.604743Z digest=sha256:85cddcae190d9e199d5270a66450a99d32433ec99779b0ea0a203c137c0c6544

Observation b87fa644-aaee-4062-9907-a3f4b64c623a · outbound

This paper cites Red-Teaming the Stable Diffusion Safety Filter.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Red-Teaming the Stable Diffusion Safety Filter

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.609461Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.609461Z digest=sha256:740e56f81e0eb55188a64b64cc3b63bddd100daa0041cc4d38aefa573665a73e

Observation e3d47743-73fe-408c-9852-5a58c51201b3 · outbound

This paper cites Jail- break in pieces: Compositional adversarial attacks on multi- modal language models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jail- break in pieces: Compositional adversarial attacks on multi- modal language models

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.678604Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.614381Z digest=sha256:576ae4011a969e61a78d0d6d4908d3b9aae3d45ecac6659bb97c451d00c30230

Observation e564d193-1b97-4148-a10c-e5d84264031b · outbound

This paper cites "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.619307Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.619307Z digest=sha256:96a01573a07984e98b52d65b7a00bf42979806c73b6434ba3a1228d3b91f78eb

Observation 2e9c0b33-6ad3-4157-95b2-9eba6672c6c8 · outbound

This paper cites MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.623947Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.623947Z digest=sha256:f1f5ed9ffa79257107c576d84e9ccad9efcd327c5d438e5eb3134a34f924322c

Observation 9677163a-441e-40ac-8097-d475f76c21eb · outbound

This paper cites Jail- broken: How does llm safety training fail? Advances in Neu- ral Information Processing Systems, 36:80079–80110, 2023.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jail- broken: How does llm safety training fail? Advances in Neu- ral Information Processing Systems, 36:80079–80110, 2023

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.605383Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.628782Z digest=sha256:84f7678c57987acde453daf491c4f11b830e88a1c777e1b85e9159a022229019

Observation 1826752a-9ce1-448f-99c7-e79bf78e9231 · outbound

This paper cites $\textit{MMJ-Bench}$: A Comprehensive Study on Jailbreak Attacks and Defenses for Multimodal Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency $\textit{MMJ-Bench}$: A Comprehensive Study on Jailbreak Attacks and Defenses for Multimodal Large Language Models

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.633818Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.633818Z digest=sha256:7e010ab11db37d3d7ade1366064360cb9727a38ae09b50f262fb888fcf26b78b

Observation 089aee07-2208-48ae-9257-f569f15facd5 · outbound

This paper cites Cross-modality Information Check for Detecting Jailbreaking in Multimodal Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Cross-modality Information Check for Detecting Jailbreaking in Multimodal Large Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.639374Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.639374Z digest=sha256:f84f27e7c2c6f8634ae98494f343d97a190c64f98813c8ebce07a501f598be3a

Observation f095b5a0-80fb-4f13-8071-e9d739d480f8 · outbound

This paper cites Mma-diffusion: Multimodal attack on diffusion models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Mma-diffusion: Multimodal attack on diffusion models

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.589713Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.644098Z digest=sha256:b802d8f600a1c0f355496c8805ad539a43145c48b34141290fd6a55075beb017

Observation 63053d11-0bd6-469b-9f33-d03364029fb9 · outbound

This paper cites Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.648902Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.648902Z digest=sha256:96dce7d57cf76aa2ce9579e808025c52c5bd84044d4cc5180ac25172220b882a

Observation 29cd9db1-eda2-4a78-ad7d-ccab212b63f4 · outbound

This paper cites When and why vision-language models behave like bags-of-words, and what to do about it?.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency When and why vision-language models behave like bags-of-words, and what to do about it?

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.653529Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.653529Z digest=sha256:3ac3cbc8bef1d8613051ab0f1435a74de25fc52345c02347874925694f6a4a2b

Observation 9a986c19-45c8-4093-bc7a-6d045c19f6af · outbound

This paper cites JailGuard: A Universal Detection Framework for LLM Prompt-based Attacks.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency JailGuard: A Universal Detection Framework for LLM Prompt-based Attacks

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.657668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.657668Z digest=sha256:3ea748924272a797904ad2f18bd5de990b27160c61e804ef729d2de13f65fb2f

Observation a497f2bb-a77d-4890-83ed-234294660e1b · outbound

This paper cites MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.662037Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.662037Z digest=sha256:b8586aa82a2164d2225dce44cc5115596c64883647461b3c53c76ab9ab8531df

Observation 643f2bb5-3eab-4abf-8dca-bd25d3771fac · outbound

This paper cites The First to Know: How Token Distributions Reveal Hidden Knowledge in Large Vision-Language Models?.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The First to Know: How Token Distributions Reveal Hidden Knowledge in Large Vision-Language Models?

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.667241Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.667241Z digest=sha256:8f82d2f3f22569c1c577a7d7020cebe1e094daf93d8e3f760d45eb74ea2932f2

Observation e4433cb5-33fd-4c45-a49d-433339cbfe50 · outbound

This paper cites On evaluating adversarial robustness of large vision-language models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency On evaluating adversarial robustness of large vision-language models

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.573613Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.672719Z digest=sha256:6957ec1a6c1a99a2e48aba9199796f0fbd888698203be6979d62ec12d1aa4e7f

Observation da790c9c-2c66-4e34-a02d-fbfc562f45ad · outbound

This paper cites On prompt-driven safeguarding for large language models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency On prompt-driven safeguarding for large language models

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.558080Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.677867Z digest=sha256:9f3cc27ff4936effe84264c2905be916b7f693fef8541e7923955c363eb15ef7

Observation d0d31bce-b163-486a-a50e-ca8a8b46acdf · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.682592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.682592Z digest=sha256:1423baa9435d0012fee2ba4ec5d2ef31afec2f6bd2d6a47c75ca200b1ff76f7c

Observation 6a039b72-1081-4d6c-9c6c-26e53fa002e0 · outbound

This paper cites Safety Fine-Tuning at (Almost) No Cost: A Baseline for Vision Large Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Safety Fine-Tuning at (Almost) No Cost: A Baseline for Vision Large Language Models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.687983Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.687983Z digest=sha256:bf7f087b41ae2e2cba3f26c99807b37360ee0c50b22a6b37dd32544f549ad3a1

Observation 02bc3e27-0a46-47aa-aec5-1f642e5b3986 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 44

Resolution
malformed identifier
no resolver link, observed 2026-08-10T21:26:00.693577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.693577Z digest=sha256:9128213d5f57c1b209d42a4d44c5fa6b9a7b335119dfad5a2c10d39c7d469156

Observation 1c9ff7e5-ddc7-4998-aa5f-c57389311599 · outbound

This paper cites This is the most preferred response when confronted with policy-violating instructions.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency This is the most preferred response when confronted with policy-violating instructions

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.508318Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.699481Z digest=sha256:3d08f598962eff48f017689330495640dc38702e0794a1c4fd6aa732fc1798cd

Observation 82b275b9-7ff2-4ae1-aff2-8c4057cc033e · outbound

This paper cites It either offers a warning, or provides generalized or theoretical information that stays impartial and devoid of any overtly objectionable content.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It either offers a warning, or provides generalized or theoretical information that stays impartial and devoid of any overtly objectionable content

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-10T21:26:00.703402Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:26:00.703402Z digest=sha256:1d2cdce9ff2b56d2205ee9f475211712b1bcf630199a84410504af0c0bf5118a

Observation 32ddef34-8e0c-4ad7-97bb-e36c1941a042 · outbound

This paper cites It offers content related to the request but without embedding necessary precautions or disclaimers.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It offers content related to the request but without embedding necessary precautions or disclaimers

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.412548Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.707229Z digest=sha256:ebebf64272ac9f8b22086ea9ae6a8cabbaea5eb26d5a7a1d53c82c8fefd0f70f

Observation 7150791a-1148-4c0e-9927-b00129b89d88 · outbound

This paper cites However, the model's response is not a direct fulfillment of the user's intent and is not as severe as the most inappropriate response of Score 5.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency However, the model's response is not a direct fulfillment of the user's intent and is not as severe as the most inappropriate response of Score 5

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.396953Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.711072Z digest=sha256:70f2399edfaaeda66052e4e4a1520d92f07f9e7f599576afb88f15956a50ee08

Observation ab618b61-a607-4c51-afc6-134e418a570b · outbound

This paper cites It completely ignores the usageguidelines and provides information that clearly violates the OpenAI policy.

Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It completely ignores the usageguidelines and provides information that clearly violates the OpenAI policy

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-10T21:26:01.381773Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-10T21:26:00.715228Z digest=sha256:39c0f7921be078faea74e00cca43c88bf6a7e8a1f50f4036682e18e5ae8b6168

Pith citing papers

Observation 41103c7b-89af-4865-9aa5-3ae0ef32b93e · inbound

When Data Manipulation Meets Attack Goals: An In-depth Survey of Attacks for VLMs cites this paper.

When Data Manipulation Meets Attack Goals: An In-depth Survey of Attacks for VLMs Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-08T15:38:17.263253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T15:38:17.263253Z digest=sha256:31f0ac76cb37c6069721d5adf39e7d920073b44dac646b36a1c9323538c558d1

Observation b383662e-7a57-4f4b-b85f-1eea35baa13c · inbound

Implicit Jailbreak Attacks via Cross-Modal Information Concealment on Vision-Language Models cites this paper.

Implicit Jailbreak Attacks via Cross-Modal Information Concealment on Vision-Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T15:03:39.101500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:03:39.101500Z digest=sha256:08079d28f733fedfc98d2596e79879b96b8d1d04c9423ae50d695fc8f6e2c436

Observation c0f28e1f-f415-4b5d-a708-3eea649bc713 · inbound

AMIA: Automatic Masking and Joint Intention Analysis Makes LVLMs Robust Jailbreak Defenders cites this paper.

AMIA: Automatic Masking and Joint Intention Analysis Makes LVLMs Robust Jailbreak Defenders Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T12:35:29.600994Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T12:35:29.600994Z digest=sha256:a2ddefc35019574feb0787c8ea7ebec91c3726cae602f4f7e1b7bcab8270dd97

Observation 5719697c-4c9d-4267-b964-5a02d0222927 · inbound

VLMs Can Aggregate Scattered Training Patches cites this paper.

VLMs Can Aggregate Scattered Training Patches Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T11:04:05.826344Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:04:05.826344Z digest=sha256:523952759d6c320ad1297b9be7270e7e6226f455a941c8e538859280f680bddb

Observation 0ed124a4-2e01-4b4a-bebd-c3f258ebbf15 · inbound

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem cites this paper.

From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-15T19:45:09.747284Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:45:09.747284Z digest=sha256:120ae7cf1e1813fad15f88b03a6429d4e99870e589f5e8bb33dda32805c3b356

Observation 0a5cbd56-88a6-4c88-8df7-b6e574ac8c03 · inbound

Trojan Horse Prompting: Jailbreaking Conversational Multimodal Models by Forging Assistant Message cites this paper.

Trojan Horse Prompting: Jailbreaking Conversational Multimodal Models by Forging Assistant Message Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-06T19:46:26.999796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:46:26.999796Z digest=sha256:a7409dae0efae606516668e19f50059c1869074b11b281c8ee804bee4af1d5d9

Observation 0f73e18f-c5af-4351-a928-44e72a504032 · inbound

PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking cites this paper.

PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-19T03:37:01.089221Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-05-19T03:36:24.013477Z digest=sha256:003624065c5b3454c9af8cb93f6b4107ce68f3d9c26d0bb948efa99af04c4328

Observation 58e7eb06-5295-4bff-a282-3edde6c5ad4a · inbound

Self-Aware Safety Augmentation: Leveraging Internal Semantic Understanding to Enhance Safety in Vision-Language Models cites this paper.

Self-Aware Safety Augmentation: Leveraging Internal Semantic Understanding to Enhance Safety in Vision-Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-06T12:40:05.556736Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T12:40:05.556736Z digest=sha256:81e134f18ab8875db5d286a6f481ad583097f090f08c42e8074d1a028dda9032

Observation 3c23bc6e-e5c3-4340-84d3-e278afc94abd · inbound

GAMBIT: A Gamified Jailbreak Framework for Multimodal Large Language Models cites this paper.

GAMBIT: A Gamified Jailbreak Framework for Multimodal Large Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-16T17:08:08.264872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-16T17:04:53.839154Z digest=sha256:001afa53241fd090e431e4964efb1ecf9d2d1c26955349687c3e431d8179d9a4

Observation 717a738e-62cd-4048-84de-3bafe972a081 · inbound

Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization cites this paper.

Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-11T05:35:59.075594Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-10T18:03:36.805784Z digest=sha256:b5b4c035cef82779c8a1075bdbea434bd1ae768ef60a32968dcfaf3799072cb0

Observation 6f24b706-1635-4144-9fbb-0c82494ae019 · inbound

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems cites this paper.

The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 58

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T09:16:04.121985Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-10T16:07:31.602378Z digest=sha256:5d128662e28ee8d4d068688efc0c6c56837ea7fff07101483102cf31cee5b95f

Observation 51eb901c-3b03-4182-9410-848727bd9106 · inbound

Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition cites this paper.

Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-07-01T23:26:23.248947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-06-28T14:17:52.902183Z digest=sha256:2aa47b615764331bf3729bddd606514c41a53e0af2e919aff9890979a4811258

Observation fe8af537-5d5f-4ab2-841e-088300f132cc · inbound

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination cites this paper.

A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency

Reference 160

Resolution
unresolved
no resolver link, observed 2026-08-07T00:14:51.130585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T00:14:51.130585Z digest=sha256:60cf82ba4301d39ec602413e8b54e81825a5eb7f7cff76a648ab47ad938d3021