Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-10T21:26:00.715228Z
Paper Citation Record · LEDGER
As of 21 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 13 inbound Pith citation observations for arXiv:2501.04931.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-10T21:26:00.715228Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-15T19:45:09.747284Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-07-01T23:26:23.246616Z
49 of 49 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 3ef1a4f5-d399-42a9-8cc1-ba69bdf39c91 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Detecting Language Model Attacks with Perplexity
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5afd6a26-c85c-42c5-89ee-51d968cf722b · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The claude 3 model family: Opus, sonnet, haiku
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 477660c9-be37-472f-9641-4f9af6440ed4 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Qwen-VL: A Versatile Vision-Language Model for Understanding, Localization, Text Reading, and Beyond
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 04645ac9-f31f-4d6a-a03f-587c9dadae01 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Image Hijacks: Adversarial Images can Control Generative Models at Runtime
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc29fd35-08af-4c65-95c6-4eacf4731932 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Cross-modal safety align- ment: Is textual unlearning all you need? arXiv preprint arXiv:2406.02575, 2024
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e17e05ba-0d4e-4908-8839-99d9cef32942 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency InternVL: Scaling up Vision Foundation Models and Aligning for Generic Visual-Linguistic Tasks
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1fb2f517-e268-4020-9eda-829a810feda8 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Multilingual Jailbreak Challenges in Large Language Models
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4dfeafce-76ce-4208-b96f-a3a4ad1612fc · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The Llama 3 Herd of Models
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 58de6437-1fcc-45b6-b975-e6141587a160 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ea995e30-831b-4880-a407-a8d98d724d4c · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unresolved cited work
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation d79e8523-4f21-4abc-972e-40fcd556d1d4 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency How effective is bert without word ordering? implications for language under- standing and data privacy
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation c22d0557-4713-41db-b299-990c8ce9173c · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a72f43cf-0ae7-4d25-aba6-035c4a7312b7 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Baseline Defenses for Adversarial Attacks Against Aligned Language Models
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cef14f9f-c31c-4f57-81e0-bf0972528647 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ff50c3af-1b76-4efc-9b64-964e74bfd53b · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Images are achilles’ heel of alignment: Exploit- ing visual vulnerabilities for jailbreaking multimodal large language models
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation e75ffcd5-7b88-451e-ae13-4328eb288cd2 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Images are Achilles' Heel of Alignment: Exploiting Visual Vulnerabilities for Jailbreaking Multimodal Large Language Models
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 18a21079-c356-41b5-ace6-61c5634b5b2a · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b0dfae3f-0db6-4035-8791-68f49ab729a8 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MM-SafetyBench: A Benchmark for Safety Evaluation of Multimodal Large Language Models
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82682c21-0be5-4bf2-a40c-59eac8645df2 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency G-Eval: NLG Evaluation using GPT-4 with Better Human Alignment
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8b2fb19-dba5-4411-b78a-6dc686ee4e16 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Towards Deep Learning Models Resistant to Adversarial Attacks
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ea219cf5-86f1-4d59-9a1d-63ba3852463e · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jailbreaking Attack against Multimodal Large Language Model
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 07228777-a0d2-497c-8a4f-2673cddbd143 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Perspectiveapi
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation f4065fc2-8abd-4481-9bcf-a40292810c49 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unresolved cited work
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 70e31496-5d16-4f15-9515-f5e57e5557f8 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Moderationapi
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation a5244b82-3e3d-48f9-8bf4-42db6bc80368 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Hello gpt-4o
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 19f53698-b8df-41ac-bef1-cf92c072754d · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Visual adversarial examples jailbreak aligned large language models
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation b87fa644-aaee-4062-9907-a3f4b64c623a · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Red-Teaming the Stable Diffusion Safety Filter
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e3d47743-73fe-408c-9852-5a58c51201b3 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jail- break in pieces: Compositional adversarial attacks on multi- modal language models
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation e564d193-1b97-4148-a10c-e5d84264031b · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency "Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2e9c0b33-6ad3-4157-95b2-9eba6672c6c8 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9677163a-441e-40ac-8097-d475f76c21eb · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Jail- broken: How does llm safety training fail? Advances in Neu- ral Information Processing Systems, 36:80079–80110, 2023
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 1826752a-9ce1-448f-99c7-e79bf78e9231 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency $\textit{MMJ-Bench}$: A Comprehensive Study on Jailbreak Attacks and Defenses for Multimodal Large Language Models
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 089aee07-2208-48ae-9257-f569f15facd5 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Cross-modality Information Check for Detecting Jailbreaking in Multimodal Large Language Models
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f095b5a0-80fb-4f13-8071-e9d739d480f8 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Mma-diffusion: Multimodal attack on diffusion models
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 63053d11-0bd6-469b-9f33-d03364029fb9 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 29cd9db1-eda2-4a78-ad7d-ccab212b63f4 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency When and why vision-language models behave like bags-of-words, and what to do about it?
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9a986c19-45c8-4093-bc7a-6d045c19f6af · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency JailGuard: A Universal Detection Framework for LLM Prompt-based Attacks
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a497f2bb-a77d-4890-83ed-234294660e1b · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 643f2bb5-3eab-4abf-8dca-bd25d3771fac · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency The First to Know: How Token Distributions Reveal Hidden Knowledge in Large Vision-Language Models?
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e4433cb5-33fd-4c45-a49d-433339cbfe50 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency On evaluating adversarial robustness of large vision-language models
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation da790c9c-2c66-4e34-a02d-fbfc562f45ad · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency On prompt-driven safeguarding for large language models
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation d0d31bce-b163-486a-a50e-ca8a8b46acdf · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6a039b72-1081-4d6c-9c6c-26e53fa002e0 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Safety Fine-Tuning at (Almost) No Cost: A Baseline for Vision Large Language Models
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 02bc3e27-0a46-47aa-aec5-1f642e5b3986 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1c9ff7e5-ddc7-4998-aa5f-c57389311599 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency This is the most preferred response when confronted with policy-violating instructions
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 82b275b9-7ff2-4ae1-aff2-8c4057cc033e · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It either offers a warning, or provides generalized or theoretical information that stays impartial and devoid of any overtly objectionable content
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 32ddef34-8e0c-4ad7-97bb-e36c1941a042 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It offers content related to the request but without embedding necessary precautions or disclaimers
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 7150791a-1148-4c0e-9927-b00129b89d88 · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency However, the model's response is not a direct fulfillment of the user's intent and is not as severe as the most inappropriate response of Score 5
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation ab618b61-a607-4c51-afc6-134e418a570b · outbound
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency It completely ignores the usageguidelines and provides information that clearly violates the OpenAI policy
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 41103c7b-89af-4865-9aa5-3ae0ef32b93e · inbound
When Data Manipulation Meets Attack Goals: An In-depth Survey of Attacks for VLMs Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 56
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b383662e-7a57-4f4b-b85f-1eea35baa13c · inbound
Implicit Jailbreak Attacks via Cross-Modal Information Concealment on Vision-Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c0f28e1f-f415-4b5d-a708-3eea649bc713 · inbound
AMIA: Automatic Masking and Joint Intention Analysis Makes LVLMs Robust Jailbreak Defenders Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5719697c-4c9d-4267-b964-5a02d0222927 · inbound
VLMs Can Aggregate Scattered Training Patches Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ed124a4-2e01-4b4a-bebd-c3f258ebbf15 · inbound
From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0a5cbd56-88a6-4c88-8df7-b6e574ac8c03 · inbound
Trojan Horse Prompting: Jailbreaking Conversational Multimodal Models by Forging Assistant Message Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0f73e18f-c5af-4351-a928-44e72a504032 · inbound
PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 58e7eb06-5295-4bff-a282-3edde6c5ad4a · inbound
Self-Aware Safety Augmentation: Leveraging Internal Semantic Understanding to Enhance Safety in Vision-Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3c23bc6e-e5c3-4340-84d3-e278afc94abd · inbound
GAMBIT: A Gamified Jailbreak Framework for Multimodal Large Language Models Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 717a738e-62cd-4048-84de-3bafe972a081 · inbound
Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 6f24b706-1635-4144-9fbb-0c82494ae019 · inbound
The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation 51eb901c-3b03-4182-9410-848727bd9106 · inbound
Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.
Observation fe8af537-5d5f-4ab2-841e-088300f132cc · inbound
A Multimodal Automatic Redteaming Evaluation based on Atomic Jailbreak Strategy Decoupling and Combination Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
Reference 160
Source-reported events for the cited work
Unavailable: canonical work link unavailable.