{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:5FFBLSG3CVM3KB4QGWNY3PSWR5","short_pith_number":"pith:5FFBLSG3","schema_version":"1.0","canonical_sha256":"e94a15c8db1559b50790359b8dbe568f467b124065ba15562c34482dad3fdfbb","source":{"kind":"arxiv","id":"2402.15570","version":1},"attestation_state":"computed","paper":{"title":"Fast Adversarial Attacks on Language Models In One GPU Minute","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Atoosa Chegini, Gaurang Sriramanan, Priyatham Kattakinda, Shoumik Saha, Soheil Feizi, Vinu Sankar Sadasivan","submitted_at":"2024-02-23T19:12:53Z","abstract_excerpt":"In this paper, we introduce a novel class of fast, beam search-based adversarial attack (BEAST) for Language Models (LMs). BEAST employs interpretable parameters, enabling attackers to balance between attack speed, success rate, and the readability of adversarial prompts. The computational efficiency of BEAST facilitates us to investigate its applications on LMs for jailbreaking, eliciting hallucinations, and privacy attacks. Our gradient-free targeted attack can jailbreak aligned LMs with high attack success rates within one minute. For instance, BEAST can jailbreak Vicuna-7B-v1.5 under one m"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.15570","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-02-23T19:12:53Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"ba661f83637ad795d4236a766f2d1b4daa0d444a24065bf87fcf427fa169f1ef","abstract_canon_sha256":"63a2f07e00fa6eb86e4eb556f95ba9345fcf31c92d5214f64d4117f798fd30e2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:48:54.822391Z","signature_b64":"rwhJnGWW3W6dEx1Jbats5m2cmm5ATDxu+6o7semJFFsjQZq9jxnGAijB+2aExJrfDpFYcI1w+GT9nYnqQUNcCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e94a15c8db1559b50790359b8dbe568f467b124065ba15562c34482dad3fdfbb","last_reissued_at":"2026-07-05T07:48:54.821909Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:48:54.821909Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Fast Adversarial Attacks on Language Models In One GPU Minute","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Atoosa Chegini, Gaurang Sriramanan, Priyatham Kattakinda, Shoumik Saha, Soheil Feizi, Vinu Sankar Sadasivan","submitted_at":"2024-02-23T19:12:53Z","abstract_excerpt":"In this paper, we introduce a novel class of fast, beam search-based adversarial attack (BEAST) for Language Models (LMs). BEAST employs interpretable parameters, enabling attackers to balance between attack speed, success rate, and the readability of adversarial prompts. The computational efficiency of BEAST facilitates us to investigate its applications on LMs for jailbreaking, eliciting hallucinations, and privacy attacks. Our gradient-free targeted attack can jailbreak aligned LMs with high attack success rates within one minute. For instance, BEAST can jailbreak Vicuna-7B-v1.5 under one m"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.15570","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.15570/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.15570","created_at":"2026-07-05T07:48:54.821964+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.15570v1","created_at":"2026-07-05T07:48:54.821964+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.15570","created_at":"2026-07-05T07:48:54.821964+00:00"},{"alias_kind":"pith_short_12","alias_value":"5FFBLSG3CVM3","created_at":"2026-07-05T07:48:54.821964+00:00"},{"alias_kind":"pith_short_16","alias_value":"5FFBLSG3CVM3KB4Q","created_at":"2026-07-05T07:48:54.821964+00:00"},{"alias_kind":"pith_short_8","alias_value":"5FFBLSG3","created_at":"2026-07-05T07:48:54.821964+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.21077","citing_title":"OTTER: A Red-Teaming System for Toxicity-Evading Jailbreak Prompt Optimization","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2503.02574","citing_title":"LLM-Safety Evaluations Lack Robustness","ref_index":46,"is_internal_anchor":false},{"citing_arxiv_id":"2605.19321","citing_title":"Exploring and Developing a Pre-Model Safeguard with Draft Models","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12813","citing_title":"REALISTA: Realistic Latent Adversarial Attacks that Elicit LLM Hallucinations","ref_index":107,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11418","citing_title":"Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2604.18756","citing_title":"Towards Understanding the Robustness of Sparse Autoencoders","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5","json":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5.json","graph_json":"https://pith.science/api/pith-number/5FFBLSG3CVM3KB4QGWNY3PSWR5/graph.json","events_json":"https://pith.science/api/pith-number/5FFBLSG3CVM3KB4QGWNY3PSWR5/events.json","paper":"https://pith.science/paper/5FFBLSG3"},"agent_actions":{"view_html":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5","download_json":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5.json","view_paper":"https://pith.science/paper/5FFBLSG3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.15570&json=true","fetch_graph":"https://pith.science/api/pith-number/5FFBLSG3CVM3KB4QGWNY3PSWR5/graph.json","fetch_events":"https://pith.science/api/pith-number/5FFBLSG3CVM3KB4QGWNY3PSWR5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5/action/storage_attestation","attest_author":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5/action/author_attestation","sign_citation":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5/action/citation_signature","submit_replication":"https://pith.science/pith/5FFBLSG3CVM3KB4QGWNY3PSWR5/action/replication_record"}},"created_at":"2026-07-05T07:48:54.821964+00:00","updated_at":"2026-07-05T07:48:54.821964+00:00"}