{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:2XPCUCDQLBVOH6H6NTEWONB3AA","short_pith_number":"pith:2XPCUCDQ","schema_version":"1.0","canonical_sha256":"d5de2a0870586ae3f8fe6cc967343b002d8fe4ab5c18006de4cde25987b92c0e","source":{"kind":"arxiv","id":"2406.04755","version":4},"attestation_state":"computed","paper":{"title":"LLM Whisperer: An Inconspicuous Attack to Bias LLM Responses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.HC","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anna Gerchanovsky, Lujo Bauer, Matt Fredrikson, Omer Akgul, Weiran Lin, Zifan Wang","submitted_at":"2024-06-07T08:54:55Z","abstract_excerpt":"Writing effective prompts for large language models (LLM) can be unintuitive and burdensome. In response, services that optimize or suggest prompts have emerged. While such services can reduce user effort, they also introduce a risk: the prompt provider can subtly manipulate prompts to produce heavily biased LLM responses. In this work, we show that subtle synonym replacements in prompts can increase the likelihood (by a difference up to 78%) that LLMs mention a target concept (e.g., a brand, political party, nation). We substantiate our observations through a user study, showing that our adve"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2406.04755","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-06-07T08:54:55Z","cross_cats_sorted":["cs.AI","cs.HC","cs.LG"],"title_canon_sha256":"be28d8ae7b2e41161da7a42030504e3f1334127f38c5e017c48e9103d5605592","abstract_canon_sha256":"cdbad2288dca7aa9c35614562bf203bdc4cca880665bbdc744bbced9ad882d77"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:21:20.342358Z","signature_b64":"fnXJctyL65E2kSwdmAH4w9lZluyFWkNgwvx5Gu2Rar1pg88pTrd+79Wn7rbgxd+HgLXOU1IdQNZiE0AHlwiiCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d5de2a0870586ae3f8fe6cc967343b002d8fe4ab5c18006de4cde25987b92c0e","last_reissued_at":"2026-07-05T10:21:20.341767Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:21:20.341767Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LLM Whisperer: An Inconspicuous Attack to Bias LLM Responses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.HC","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anna Gerchanovsky, Lujo Bauer, Matt Fredrikson, Omer Akgul, Weiran Lin, Zifan Wang","submitted_at":"2024-06-07T08:54:55Z","abstract_excerpt":"Writing effective prompts for large language models (LLM) can be unintuitive and burdensome. In response, services that optimize or suggest prompts have emerged. While such services can reduce user effort, they also introduce a risk: the prompt provider can subtly manipulate prompts to produce heavily biased LLM responses. In this work, we show that subtle synonym replacements in prompts can increase the likelihood (by a difference up to 78%) that LLMs mention a target concept (e.g., a brand, political party, nation). We substantiate our observations through a user study, showing that our adve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2406.04755","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2406.04755/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2406.04755","created_at":"2026-07-05T10:21:20.341826+00:00"},{"alias_kind":"arxiv_version","alias_value":"2406.04755v4","created_at":"2026-07-05T10:21:20.341826+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.04755","created_at":"2026-07-05T10:21:20.341826+00:00"},{"alias_kind":"pith_short_12","alias_value":"2XPCUCDQLBVO","created_at":"2026-07-05T10:21:20.341826+00:00"},{"alias_kind":"pith_short_16","alias_value":"2XPCUCDQLBVOH6H6","created_at":"2026-07-05T10:21:20.341826+00:00"},{"alias_kind":"pith_short_8","alias_value":"2XPCUCDQ","created_at":"2026-07-05T10:21:20.341826+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.30207","citing_title":"Persona Conditioning of Brand Recommendations in Retrieval-Augmented Commercial Chat: A Prominence-Stratified Cross-Provider Audit","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA","json":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA.json","graph_json":"https://pith.science/api/pith-number/2XPCUCDQLBVOH6H6NTEWONB3AA/graph.json","events_json":"https://pith.science/api/pith-number/2XPCUCDQLBVOH6H6NTEWONB3AA/events.json","paper":"https://pith.science/paper/2XPCUCDQ"},"agent_actions":{"view_html":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA","download_json":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA.json","view_paper":"https://pith.science/paper/2XPCUCDQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2406.04755&json=true","fetch_graph":"https://pith.science/api/pith-number/2XPCUCDQLBVOH6H6NTEWONB3AA/graph.json","fetch_events":"https://pith.science/api/pith-number/2XPCUCDQLBVOH6H6NTEWONB3AA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA/action/storage_attestation","attest_author":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA/action/author_attestation","sign_citation":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA/action/citation_signature","submit_replication":"https://pith.science/pith/2XPCUCDQLBVOH6H6NTEWONB3AA/action/replication_record"}},"created_at":"2026-07-05T10:21:20.341826+00:00","updated_at":"2026-07-05T10:21:20.341826+00:00"}