Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T11:51:33.211141Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 45 of 45 outbound references and 1 inbound Pith citation observation for arXiv:2506.01307.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T11:51:33.211141Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-05-10T19:04:46.426969Z
A source-named dated measurement, never combined with another source.
Source: arxiv_reference, observed 2026-05-10T23:30:51.277126Z
45 of 45 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 1fb9bb94-5321-44bf-9cbb-be3ed3dcdf9c · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Technical Report
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e72e39d2-d951-4d67-b0e7-71f5f40a6948 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Gemini: A Family of Highly Capable Multimodal Models
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ef0946de-ab69-4161-a9d6-0138554acc8e · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A Survey on Multimodal Large Language Models
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82887369-20a4-46cc-866f-d1f7955af88a · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fc6bae13-b3ab-420e-981c-09a913f748a7 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models VideoChat: Chat-Centric Video Understanding
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e94737b0-a031-499f-b7a7-4779385e11b0 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pengi: An audio language model for audio tasks,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b140f10b-8e32-48a6-b77f-5fb694fbd27c · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Llava-med: Training a large language-and-vision assistant for biomedicine in one day,
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation d294cd55-61f5-4fe2-b256-a9bc23193f35 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 85f15e9a-2344-4c10-ad7f-c18cdf49a089 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 44e84603-c99d-4013-b29f-afa15ba7b79e · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Black Box Large Language Models in Twenty Queries
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 71dff876-f268-4db8-90a7-05b02771e398 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 9ae543c5-0770-4eb5-b2cb-bf6ea664a28b · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 57ac1d65-0182-4a1d-9dac-fd127fb32722 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Yi: Open foundation models by 01.ai,
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation fc9a1c67-4e3c-4534-bfaf-65ac5aa04ea5 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-v2: large language model as a unified interface for vision-language multi-task learning
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3b4e1997-ed96-4122-a888-6bcd1297b8db · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a5a0e50a-313f-495a-8d1e-a3a49a8cab13 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Instructblip: Towards general-purpose vision- language models with instruction tuning,
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 808cb02a-cd49-405e-999e-1fb1ab3722af · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 14a3b5fe-c5da-424c-bd2e-786547a8abcd · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models mplug-owl2: Revolutionizing multi-modal large language model with modality collaboration,
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0ebd9d24-a5ce-477f-ba5d-7558ca94cb4d · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniCPM-V: A GPT-4V Level MLLM on Your Phone
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 80c65fb0-056e-4ca7-9709-2649b5f5fc6d · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models CogVLM: Visual Expert for Pretrained Language Models
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 644770f6-f978-49a1-8c07-841eeb5244af · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 63fcc7da-0de8-450c-9094-c3e55489aac6 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Attack against Multimodal Large Language Model
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ee961af7-a279-4c2c-9283-c6f26bbd0a01 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Cross-shaped adversarial patch attack,
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 1a24ef4f-6ac7-454f-90bf-1019ecc4704b · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Targeted adversarial attack against deep cross-modal hashing retrieval,
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 53e32251-37cf-495c-971e-3e243982e2dc · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Dynamics-aware adversarial attack of adaptive neural networks,
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation dbfd7b8c-da2e-4b6e-9dac-2336b4cfa51f · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Iterative adversarial attack on image- guided story ending generation,
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 9e9df887-7064-4106-8bd4-e12dafd4ba22 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Toward robust neural image compression: Adver- sarial attack and model finetuning,
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 16740d72-5656-4a95-8111-043ba3356ee1 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards adversarial attack on vision- language pre-training models,
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation a6fead6f-3ab2-4daa-9c6e-e8d303eb6951 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Exploring Transferability of Multimodal Adversarial Samples for Vision-Language Pre-training Models with Contrastive Learning
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 039539f4-a146-4f94-afa1-83b8d23ab22f · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Scalable universal adversarial watermark defending against fa- cial forgery,
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation c3142e28-7d08-4ff6-8aaf-64c719910493 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models An unforgeable publicly verifiable watermark for large language models,
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 1cff7bda-554f-4ec0-8768-57ec9584f7c0 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A novel model watermarking for protecting generative adversarial network,
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 02b16ad3-6cfc-4111-8bcc-7a358ee07963 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b81d3f36-170a-408b-8194-6c093c191ddd · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visually adversarial attacks and defenses in the physical world: A survey,
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 215ff0cf-0c24-48e6-ae3d-3b778e38bf4b · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models How to Bridge the Gap between Modalities: Survey on Multimodal Large Language Model
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e1c4d96c-2bd5-4fbe-b6be-214a7bb7eaa5 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards Deep Learning Models Resistant to Adversarial Attacks
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e078d193-ea6c-4d38-a95e-710c97cdccab · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c386dfdb-b3cc-4bfc-beec-60afe310ec2c · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Enhancing the transferability of adversarial attacks through variance tuning,
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 810c9d6f-f753-4bba-a412-6bafc1d7d107 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pytorch: An imperative style, high-performance deep learning library,
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6b7c214f-b5e7-4092-9def-6fdc3742f280 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models,
Reference 40
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 22298515-bd24-4400-84c9-790d5dad6e67 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc92866a-6aa5-44dc-a637-714a814ed871 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3bb0ae46-7edd-488f-a05a-11b2cfd86068 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Self-Guard: Empower the LLM to Safeguard Itself
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24f406f7-dac3-4aae-af34-04176296cb90 · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Refuse Whenever You Feel Unsafe: Improving Safety in LLMs via Decoupled Refusal Training
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2033bf75-41f1-4ab5-8e01-a3f3876b678b · outbound
Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Efficient Adversarial Training in LLMs with Continuous Attacks
Reference 45
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 92a8316e-aa44-4442-94a5-6ce1c411ff39 · inbound
SALLIE: Safeguarding Against Latent Language & Image Exploits Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.