Pith. sign in

Paper Citation Record · LEDGER

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models

As of 7 August 2026, this Paper Citation Record lists 45 of 45 outbound references and 1 inbound Pith citation observation for arXiv:2506.01307.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.01307 v1

Coverage vector

measured 45 of 45 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T11:51:33.211141Z

measured 46 of 46 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-05-10T19:04:46.426969Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-10T23:30:51.277126Z

Reference resolution

45 of 45 outbound references displayed

  • verified exact1
  • verified fuzzy15
  • unresolved29
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 1fb9bb94-5321-44bf-9cbb-be3ed3dcdf9c · outbound

This paper cites GPT-4 Technical Report.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.472465Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.472465Z digest=sha256:e6523b073baa0398d4b21773cac8ee4cae4ac5994ba08a8599e4f358be547b46

Observation e72e39d2-d951-4d67-b0e7-71f5f40a6948 · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Gemini: A Family of Highly Capable Multimodal Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.525374Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.525374Z digest=sha256:094c6cb17807f7d74cbfde44818908014db5d8f3c725339509156b12dc9910f6

Observation ef0946de-ab69-4161-a9d6-0138554acc8e · outbound

This paper cites A Survey on Multimodal Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A Survey on Multimodal Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.594092Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.594092Z digest=sha256:ec4eeefde4ee2ef080e961cfd28c9cd4b44055b13f5ac55f095d28997c803dab

Observation 82887369-20a4-46cc-866f-d1f7955af88a · outbound

This paper cites Visual instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.654714Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.654714Z digest=sha256:4408acedfd40462375a6d28457823dc1b56883e9de38404e51d518582741d52e

Observation fc6bae13-b3ab-420e-981c-09a913f748a7 · outbound

This paper cites VideoChat: Chat-Centric Video Understanding.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models VideoChat: Chat-Centric Video Understanding

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.708631Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.708631Z digest=sha256:09c214562e3cc6d621a6e2cb78f0f81f142f6095bc9b2f9732c9aa02494958c7

Observation e94737b0-a031-499f-b7a7-4779385e11b0 · outbound

This paper cites Pengi: An audio language model for audio tasks,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pengi: An audio language model for audio tasks,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.759161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.759161Z digest=sha256:931ad68f840e8422af60ebbd6f7c915247ba2a281938497d8413b72fbcca41ad

Observation b140f10b-8e32-48a6-b77f-5fb694fbd27c · outbound

This paper cites Llava-med: Training a large language-and-vision assistant for biomedicine in one day,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Llava-med: Training a large language-and-vision assistant for biomedicine in one day,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.538329Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:30.826744Z digest=sha256:aa4b82ebec18763bc7174d12a3ddc2c37ce662a60578566ccf37311364ab2f0f

Observation d294cd55-61f5-4fe2-b256-a9bc23193f35 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.892052Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.892052Z digest=sha256:ef5606fd6b6987b76b3c3fd72cce3ccbbbbfed9f9d01b41f514aab4af3f4f741

Observation 85f15e9a-2344-4c10-ad7f-c18cdf49a089 · outbound

This paper cites GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:30.970995Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:30.970995Z digest=sha256:2015a473f8ad2757576d660f4381ccc9b5a2aff0b5b35a4a339dcc9c0c9ed3c2

Observation 44e84603-c99d-4013-b29f-afa15ba7b79e · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.034488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.034488Z digest=sha256:fe9fda2209344e752eeb85e6c5d6bcd9f16d4e9dc049ef43c66b503b804f0087

Observation 71dff876-f268-4db8-90a7-05b02771e398 · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.427322Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.080590Z digest=sha256:c8bb23ac41ff775b5e9e9069b1e1128548092cf65590c588d4faaf0d935a6645

Observation 9ae543c5-0770-4eb5-b2cb-bf6ea664a28b · outbound

This paper cites Visual instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual instruction tuning,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.127775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.127775Z digest=sha256:73750512f8cf3dcc498c1aa411b723eb3c2bfecd2238a8483e741e64adbe3183

Observation 57ac1d65-0182-4a1d-9dac-fd127fb32722 · outbound

This paper cites Yi: Open foundation models by 01.ai,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Yi: Open foundation models by 01.ai,

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.326526Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.210881Z digest=sha256:8694e6c375120439f6a798166e00e59ac6ca8ae5f7e567afd21606955722464f

Observation fc9a1c67-4e3c-4534-bfaf-65ac5aa04ea5 · outbound

This paper cites MiniGPT-v2: large language model as a unified interface for vision-language multi-task learning.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-v2: large language model as a unified interface for vision-language multi-task learning

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.266316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.266316Z digest=sha256:36b71dea25fa1c91e38486b92b7bea5062511f5df06a4577eb0698e20b479af5

Observation 3b4e1997-ed96-4122-a888-6bcd1297b8db · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.323529Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.323529Z digest=sha256:ee57283984ba27a9ff99dc4ed4d0a03bc3cd6e04acf3e6e7e01b0a2223a5bfb8

Observation a5a0e50a-313f-495a-8d1e-a3a49a8cab13 · outbound

This paper cites Instructblip: Towards general-purpose vision- language models with instruction tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Instructblip: Towards general-purpose vision- language models with instruction tuning,

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.196949Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.355865Z digest=sha256:45a1146fb89b92edbaa0a303656de69ef564adf38525f460f463e5d1c4a5cc99

Observation 808cb02a-cd49-405e-999e-1fb1ab3722af · outbound

This paper cites Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.406556Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.406556Z digest=sha256:6de769cec9b0d9474683568b8e71186e7a7a0ecf05b3064d52972afccb134a0b

Observation 14a3b5fe-c5da-424c-bd2e-786547a8abcd · outbound

This paper cites mplug-owl2: Revolutionizing multi-modal large language model with modality collaboration,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models mplug-owl2: Revolutionizing multi-modal large language model with modality collaboration,

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:35.043145Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.439571Z digest=sha256:d3880409e765c1f86636536e9352d9e32932e267e2d8de4d1578e19f09c99457

Observation 0ebd9d24-a5ce-477f-ba5d-7558ca94cb4d · outbound

This paper cites MiniCPM-V: A GPT-4V Level MLLM on Your Phone.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MiniCPM-V: A GPT-4V Level MLLM on Your Phone

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.473616Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.473616Z digest=sha256:26ab2f5940f895bb0f596109295c26fe47d95a17c3b88a123d871df778fd4615

Observation 80c65fb0-056e-4ca7-9709-2649b5f5fc6d · outbound

This paper cites CogVLM: Visual Expert for Pretrained Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models CogVLM: Visual Expert for Pretrained Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.525668Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.525668Z digest=sha256:d7234035f3203efcb369e095d6fe08a12400eb3d2a484cee71c5b38198bb7793

Observation 644770f6-f978-49a1-8c07-841eeb5244af · outbound

This paper cites COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.581115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.581115Z digest=sha256:b26c698b18c8275b91d56d825d95f8775734d381cee43a88f3b386956e76c78e

Observation 63fcc7da-0de8-450c-9094-c3e55489aac6 · outbound

This paper cites Jailbreaking Attack against Multimodal Large Language Model.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreaking Attack against Multimodal Large Language Model

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:31.629125Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:31.629125Z digest=sha256:3ec623c5c1b514706f02962b55dc8c387f313210a221474815fc3654d121e135

Observation ee961af7-a279-4c2c-9283-c6f26bbd0a01 · outbound

This paper cites Cross-shaped adversarial patch attack,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Cross-shaped adversarial patch attack,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.956625Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.648158Z digest=sha256:a7e2c596d3fa30692575002813484ff74fac84c88c051e28b1e0131e69261ca4

Observation 1a24ef4f-6ac7-454f-90bf-1019ecc4704b · outbound

This paper cites Targeted adversarial attack against deep cross-modal hashing retrieval,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Targeted adversarial attack against deep cross-modal hashing retrieval,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.882627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.697495Z digest=sha256:4c74e2223a55793f746d9add6a91c9e3c4e90f3f6080f4c8c0e3aad2af39a981

Observation 53e32251-37cf-495c-971e-3e243982e2dc · outbound

This paper cites Dynamics-aware adversarial attack of adaptive neural networks,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Dynamics-aware adversarial attack of adaptive neural networks,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.777603Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.762048Z digest=sha256:37b897b1473fbdbd00f9014a619667d662d3797ef000d03ed71123e0592ad463

Observation dbfd7b8c-da2e-4b6e-9dac-2336b4cfa51f · outbound

This paper cites Iterative adversarial attack on image- guided story ending generation,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Iterative adversarial attack on image- guided story ending generation,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.620955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.818425Z digest=sha256:6594d5b4d91c77ed79e8d11948c3af13b9aaa517197483ce27bce8db17059b5b

Observation 9e9df887-7064-4106-8bd4-e12dafd4ba22 · outbound

This paper cites Toward robust neural image compression: Adver- sarial attack and model finetuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Toward robust neural image compression: Adver- sarial attack and model finetuning,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.458925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.888309Z digest=sha256:fe46f8ef1796ae38fd2bc347d4cb0d1c3a0284a00ca6d5174f352fca51cd3da7

Observation 16740d72-5656-4a95-8111-043ba3356ee1 · outbound

This paper cites Towards adversarial attack on vision- language pre-training models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards adversarial attack on vision- language pre-training models,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.301714Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:31.950339Z digest=sha256:52380242cacdf46f7ab7c04f89604b9d908d208375d620fda38b2f43d9ea468c

Observation a6fead6f-3ab2-4daa-9c6e-e8d303eb6951 · outbound

This paper cites Exploring Transferability of Multimodal Adversarial Samples for Vision-Language Pre-training Models with Contrastive Learning.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Exploring Transferability of Multimodal Adversarial Samples for Vision-Language Pre-training Models with Contrastive Learning

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.003169Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.003169Z digest=sha256:a2cea6ac1dd8cf37acb80431e2e937ea4523fc8f73c99ff62544bd0905ee2be5

Observation 039539f4-a146-4f94-afa1-83b8d23ab22f · outbound

This paper cites Scalable universal adversarial watermark defending against fa- cial forgery,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Scalable universal adversarial watermark defending against fa- cial forgery,

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.148747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:32.061863Z digest=sha256:4f50c5e1fa2da961da24db648e8ca1f75ee5c0a2ba601cdc553fbf7ee40a2d28

Observation c3142e28-7d08-4ff6-8aaf-64c719910493 · outbound

This paper cites An unforgeable publicly verifiable watermark for large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models An unforgeable publicly verifiable watermark for large language models,

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:34.031982Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:32.132317Z digest=sha256:81f5023eb3bcace161188e249e7ce7383fecd3a53a53c16c10cb0137a30d9559

Observation 1cff7bda-554f-4ec0-8768-57ec9584f7c0 · outbound

This paper cites A novel model watermarking for protecting generative adversarial network,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models A novel model watermarking for protecting generative adversarial network,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:33.891576Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:32.221165Z digest=sha256:2699ad232d874dcbe6eb6bb29fbffdf931585f380ea4512044d6a900231f8d84

Observation 02b16ad3-6cfc-4111-8bcc-7a358ee07963 · outbound

This paper cites MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.292682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.292682Z digest=sha256:1e2d0dd6d384a9e78c76d2833e4ee9f547f8678cdb59359eafe7789afd66a470

Observation b81d3f36-170a-408b-8194-6c093c191ddd · outbound

This paper cites Visually adversarial attacks and defenses in the physical world: A survey,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visually adversarial attacks and defenses in the physical world: A survey,

Reference 34

Resolution
verified exact
raw_fallback, observed 2026-08-07T11:51:33.486716Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:32.375525Z digest=sha256:a7ba48b5558932686c5716b6e516d07abce61ce0a074b6b7e6b9b5e180e71d7f

Observation 215ff0cf-0c24-48e6-ae3d-3b778e38bf4b · outbound

This paper cites How to Bridge the Gap between Modalities: Survey on Multimodal Large Language Model.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models How to Bridge the Gap between Modalities: Survey on Multimodal Large Language Model

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.442812Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.442812Z digest=sha256:e3b5acb38e543caee095acaba773464514beba2ad3afc8ca4ba4b4dfa869727d

Observation e1c4d96c-2bd5-4fbe-b6be-214a7bb7eaa5 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.503010Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.503010Z digest=sha256:488d201cef0e399989dcfcaf444e7d77211da8d8592446bbec7b5d2f60ec8947

Observation e078d193-ea6c-4d38-a95e-710c97cdccab · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Visual adversarial examples jailbreak aligned large language models,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.593150Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.593150Z digest=sha256:24ff42972b4ad6fb649ca3d8005d6597a484c7d50339dea2227ba42ce7c6fa4c

Observation c386dfdb-b3cc-4bfc-beec-60afe310ec2c · outbound

This paper cites Enhancing the transferability of adversarial attacks through variance tuning,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Enhancing the transferability of adversarial attacks through variance tuning,

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T11:51:33.749670Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T11:51:32.655871Z digest=sha256:1245b50f694df1c52a145bba58ce48c5ced4ff09b40e50c58ccbbd21034495a6

Observation 810c9d6f-f753-4bba-a412-6bafc1d7d107 · outbound

This paper cites Pytorch: An imperative style, high-performance deep learning library,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Pytorch: An imperative style, high-performance deep learning library,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.738478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.738478Z digest=sha256:8ab14f20aae23d2f7202bafec8fc756ad560db4db6131b65a09379d0eefe936b

Observation 6b7c214f-b5e7-4092-9def-6fdc3742f280 · outbound

This paper cites Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models,.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.812440Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.812440Z digest=sha256:bca475e111f6ce105c6487878c4a0610ce3e2834b1b8782de0d30db6eaa2927f

Observation 22298515-bd24-4400-84c9-790d5dad6e67 · outbound

This paper cites Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.894561Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.894561Z digest=sha256:f8f8c6b5f40bad059c99e3428dade84714e5587435b1d53bb3d91dfcd1fb17b0

Observation cc92866a-6aa5-44dc-a637-714a814ed871 · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:32.972848Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:32.972848Z digest=sha256:f10bf14ff8c99ca726e672c537d90bca989741cb923ea7bd4e84a6837839d529

Observation 3bb0ae46-7edd-488f-a05a-11b2cfd86068 · outbound

This paper cites Self-Guard: Empower the LLM to Safeguard Itself.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Self-Guard: Empower the LLM to Safeguard Itself

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.051132Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.051132Z digest=sha256:fca4abbb6e97b51bc9139e2a8a877ab5070d5ce0be20f54c1b75cff853727fc0

Observation 24f406f7-dac3-4aae-af34-04176296cb90 · outbound

This paper cites Refuse Whenever You Feel Unsafe: Improving Safety in LLMs via Decoupled Refusal Training.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Refuse Whenever You Feel Unsafe: Improving Safety in LLMs via Decoupled Refusal Training

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.126948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.126948Z digest=sha256:a1ad3eefa0f8646ecafdaf1db3c92f676a9392e093bd85056cd6e4099a0f66aa

Observation 2033bf75-41f1-4ab5-8e01-a3f3876b678b · outbound

This paper cites Efficient Adversarial Training in LLMs with Continuous Attacks.

Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models Efficient Adversarial Training in LLMs with Continuous Attacks

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T11:51:33.211141Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:51:33.211141Z digest=sha256:8e9f98e41e6b79dd4f121c60b3c402fcb4e17993dcebaf9ad43cb06548de40f4

Pith citing papers

Observation 92a8316e-aa44-4442-94a5-6ce1c411ff39 · inbound

SALLIE: Safeguarding Against Latent Language & Image Exploits cites this paper.

SALLIE: Safeguarding Against Latent Language & Image Exploits Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-10T23:30:51.279710Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-10T19:04:46.426969Z digest=sha256:b88f9ef31d35a9a456623f3a179a7381a275b352405fa5a7cb075eb45a0aa277