{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:2P2SDAYE5WMPKCBSAMHDKEQODO","short_pith_number":"pith:2P2SDAYE","schema_version":"1.0","canonical_sha256":"d3f5218304ed98f50832030e35120e1b825ad08d19e5adb88cfa062134cc8f60","source":{"kind":"arxiv","id":"2401.18018","version":4},"attestation_state":"computed","paper":{"title":"On Prompt-Driven Safeguarding for Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.LG","authors_text":"Chujie Zheng, Fandong Meng, Fan Yin, Hao Zhou, Jie Zhou, Kai-Wei Chang, Minlie Huang, Nanyun Peng","submitted_at":"2024-01-31T17:28:24Z","abstract_excerpt":"Prepending model inputs with safety prompts is a common practice for safeguarding large language models (LLMs) against queries with harmful intents. However, the underlying working mechanisms of safety prompts have not been unraveled yet, restricting the possibility of automatically optimizing them to improve LLM safety. In this work, we investigate how LLMs' behavior (i.e., complying with or refusing user queries) is affected by safety prompts from the perspective of model representation. We find that in the representation space, the input queries are typically moved by safety prompts in a \"h"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2401.18018","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-01-31T17:28:24Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"72d132d4314cbb87869a5a09f63bc2abdcf3844b51230ca308d47b7a67fbd15a","abstract_canon_sha256":"4efe0c27c6c02921251076ca3800f38e0827c9831b7eb72e2ba8f181997c141e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:26:18.394643Z","signature_b64":"a5vM64Old6lLcAT69uJqmW7aQ77/P/D+JNfNaCDYOkrsamedMwEw1eF7ENtmMWPNNbNqQ0p2JphLdSh55TnWCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d3f5218304ed98f50832030e35120e1b825ad08d19e5adb88cfa062134cc8f60","last_reissued_at":"2026-07-05T08:26:18.394145Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:26:18.394145Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"On Prompt-Driven Safeguarding for Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.LG","authors_text":"Chujie Zheng, Fandong Meng, Fan Yin, Hao Zhou, Jie Zhou, Kai-Wei Chang, Minlie Huang, Nanyun Peng","submitted_at":"2024-01-31T17:28:24Z","abstract_excerpt":"Prepending model inputs with safety prompts is a common practice for safeguarding large language models (LLMs) against queries with harmful intents. However, the underlying working mechanisms of safety prompts have not been unraveled yet, restricting the possibility of automatically optimizing them to improve LLM safety. In this work, we investigate how LLMs' behavior (i.e., complying with or refusing user queries) is affected by safety prompts from the perspective of model representation. We find that in the representation space, the input queries are typically moved by safety prompts in a \"h"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2401.18018","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2401.18018/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2401.18018","created_at":"2026-07-05T08:26:18.394204+00:00"},{"alias_kind":"arxiv_version","alias_value":"2401.18018v4","created_at":"2026-07-05T08:26:18.394204+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2401.18018","created_at":"2026-07-05T08:26:18.394204+00:00"},{"alias_kind":"pith_short_12","alias_value":"2P2SDAYE5WMP","created_at":"2026-07-05T08:26:18.394204+00:00"},{"alias_kind":"pith_short_16","alias_value":"2P2SDAYE5WMPKCBS","created_at":"2026-07-05T08:26:18.394204+00:00"},{"alias_kind":"pith_short_8","alias_value":"2P2SDAYE","created_at":"2026-07-05T08:26:18.394204+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":10,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.15980","citing_title":"Do Activation Monitors Survive Model Updates? Benchmarking, Predicting, and Repairing Activation-Monitor Staleness","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17284","citing_title":"CLAP: Contrastive Latent-space Prompt Optimization for End-to-end Autonomous Driving","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18104","citing_title":"Safety Geometry Collapse in Multimodal LLMs and Adaptive Drift Correction","ref_index":59,"is_internal_anchor":false},{"citing_arxiv_id":"2506.01770","citing_title":"ReGA: Model-Based Safeguard for LLMs via Representation-Guided Abstraction","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2602.02280","citing_title":"RACC: Representation-Aware Coverage Criteria for LLM Safety Testing","ref_index":67,"is_internal_anchor":false},{"citing_arxiv_id":"2602.05946","citing_title":"f-GRPO and Beyond: Divergence-Based Reinforcement Learning Algorithms for General LLM Alignment","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":118,"is_internal_anchor":false},{"citing_arxiv_id":"2406.11717","citing_title":"Refusal in Language Models Is Mediated by a Single Direction","ref_index":206,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08513","citing_title":"A Single Neuron Is Sufficient to Bypass Safety Alignment in Large Language Models","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08846","citing_title":"Dictionary-Aligned Concept Control for Safeguarding Multimodal LLMs","ref_index":131,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO","json":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO.json","graph_json":"https://pith.science/api/pith-number/2P2SDAYE5WMPKCBSAMHDKEQODO/graph.json","events_json":"https://pith.science/api/pith-number/2P2SDAYE5WMPKCBSAMHDKEQODO/events.json","paper":"https://pith.science/paper/2P2SDAYE"},"agent_actions":{"view_html":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO","download_json":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO.json","view_paper":"https://pith.science/paper/2P2SDAYE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2401.18018&json=true","fetch_graph":"https://pith.science/api/pith-number/2P2SDAYE5WMPKCBSAMHDKEQODO/graph.json","fetch_events":"https://pith.science/api/pith-number/2P2SDAYE5WMPKCBSAMHDKEQODO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO/action/storage_attestation","attest_author":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO/action/author_attestation","sign_citation":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO/action/citation_signature","submit_replication":"https://pith.science/pith/2P2SDAYE5WMPKCBSAMHDKEQODO/action/replication_record"}},"created_at":"2026-07-05T08:26:18.394204+00:00","updated_at":"2026-07-05T08:26:18.394204+00:00"}