{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:4J45FYYCEWARX25T5ETFVFFJD5","short_pith_number":"pith:4J45FYYC","schema_version":"1.0","canonical_sha256":"e279d2e30225811bebb3e9265a94a91f6a9e45661573995831d00db6695fe1ac","source":{"kind":"arxiv","id":"2402.08416","version":1},"attestation_state":"computed","paper":{"title":"Pandora: Jailbreak GPTs by Retrieval Augmented Generation Poisoning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Gelei Deng, Kailong Wang, Tianwei Zhang, Yang Liu, Yi Liu, Yuekang Li","submitted_at":"2024-02-13T12:40:39Z","abstract_excerpt":"Large Language Models~(LLMs) have gained immense popularity and are being increasingly applied in various domains. Consequently, ensuring the security of these models is of paramount importance. Jailbreak attacks, which manipulate LLMs to generate malicious content, are recognized as a significant vulnerability. While existing research has predominantly focused on direct jailbreak attacks on LLMs, there has been limited exploration of indirect methods. The integration of various plugins into LLMs, notably Retrieval Augmented Generation~(RAG), which enables LLMs to incorporate external knowledg"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.08416","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-02-13T12:40:39Z","cross_cats_sorted":[],"title_canon_sha256":"f25241b1ea7ffdaf8d2b76802bc2554ad6faad9b0660f54aa2a3870a2faa7874","abstract_canon_sha256":"b16881e64c2124293bac4849bd5013135ef987d799f12c28f76bd9ac1bfa08f7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:44:32.276488Z","signature_b64":"4S3gWghBfNSBFkji/N9VIfpNCROJ654SzwLMmEC/+WJWg4XGmBZKq9D/hR9MUFkNBWHSPqeiQZWRu7bt/vPgBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e279d2e30225811bebb3e9265a94a91f6a9e45661573995831d00db6695fe1ac","last_reissued_at":"2026-07-05T07:44:32.276068Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:44:32.276068Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Pandora: Jailbreak GPTs by Retrieval Augmented Generation Poisoning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Gelei Deng, Kailong Wang, Tianwei Zhang, Yang Liu, Yi Liu, Yuekang Li","submitted_at":"2024-02-13T12:40:39Z","abstract_excerpt":"Large Language Models~(LLMs) have gained immense popularity and are being increasingly applied in various domains. Consequently, ensuring the security of these models is of paramount importance. Jailbreak attacks, which manipulate LLMs to generate malicious content, are recognized as a significant vulnerability. While existing research has predominantly focused on direct jailbreak attacks on LLMs, there has been limited exploration of indirect methods. The integration of various plugins into LLMs, notably Retrieval Augmented Generation~(RAG), which enables LLMs to incorporate external knowledg"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.08416","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.08416/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.08416","created_at":"2026-07-05T07:44:32.276125+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.08416v1","created_at":"2026-07-05T07:44:32.276125+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.08416","created_at":"2026-07-05T07:44:32.276125+00:00"},{"alias_kind":"pith_short_12","alias_value":"4J45FYYCEWAR","created_at":"2026-07-05T07:44:32.276125+00:00"},{"alias_kind":"pith_short_16","alias_value":"4J45FYYCEWARX25T","created_at":"2026-07-05T07:44:32.276125+00:00"},{"alias_kind":"pith_short_8","alias_value":"4J45FYYC","created_at":"2026-07-05T07:44:32.276125+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":8,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.27157","citing_title":"Detecting Is Not Resolving: The Monitoring Control Gap in Retrieval Augmented LLMs","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.29224","citing_title":"Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2405.13068","citing_title":"Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2501.00309","citing_title":"Retrieval-Augmented Generation with Graphs (GraphRAG)","ref_index":79,"is_internal_anchor":false},{"citing_arxiv_id":"2602.02280","citing_title":"RACC: Representation-Aware Coverage Criteria for LLM Safety Testing","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2602.11327","citing_title":"Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP","ref_index":73,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01782","citing_title":"Needle-in-RAG: Prompt-Conditioned Character-Level Traceback of Poisoned Spans in Retrieved Evidence","ref_index":17,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5","json":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5.json","graph_json":"https://pith.science/api/pith-number/4J45FYYCEWARX25T5ETFVFFJD5/graph.json","events_json":"https://pith.science/api/pith-number/4J45FYYCEWARX25T5ETFVFFJD5/events.json","paper":"https://pith.science/paper/4J45FYYC"},"agent_actions":{"view_html":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5","download_json":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5.json","view_paper":"https://pith.science/paper/4J45FYYC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.08416&json=true","fetch_graph":"https://pith.science/api/pith-number/4J45FYYCEWARX25T5ETFVFFJD5/graph.json","fetch_events":"https://pith.science/api/pith-number/4J45FYYCEWARX25T5ETFVFFJD5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5/action/storage_attestation","attest_author":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5/action/author_attestation","sign_citation":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5/action/citation_signature","submit_replication":"https://pith.science/pith/4J45FYYCEWARX25T5ETFVFFJD5/action/replication_record"}},"created_at":"2026-07-05T07:44:32.276125+00:00","updated_at":"2026-07-05T07:44:32.276125+00:00"}