{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:AFZSKR6WJWHFPXP3HUGRJP3RK6","short_pith_number":"pith:AFZSKR6W","schema_version":"1.0","canonical_sha256":"01732547d64d8e57ddfb3d0d14bf7157a13c8cf1323f3d36f66a259b32498764","source":{"kind":"arxiv","id":"2401.17256","version":5},"attestation_state":"computed","paper":{"title":"Weak-to-Strong Jailbreaking on Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Chao Du, Lei Li, Tianyu Pang, William Yang Wang, Xianjun Yang, Xuandong Zhao, Yu-Xiang Wang","submitted_at":"2024-01-30T18:48:37Z","abstract_excerpt":"Large language models (LLMs) are vulnerable to jailbreak attacks - resulting in harmful, unethical, or biased text generations. However, existing jailbreaking methods are computationally costly. In this paper, we propose the weak-to-strong jailbreaking attack, an efficient inference time attack for aligned LLMs to produce harmful text. Our key intuition is based on the observation that jailbroken and aligned models only differ in their initial decoding distributions. The weak-to-strong attack's key technical insight is using two smaller models (a safe and an unsafe one) to adversarially modify"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2401.17256","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2024-01-30T18:48:37Z","cross_cats_sorted":[],"title_canon_sha256":"f1fdf0f3b1a8b97bb433da7a8e61f55d094e0417fd62595a3c2d628098e0de3e","abstract_canon_sha256":"71b3b77caba9b97e68addd0b23aadb9dea39863386901a40737b0f4a6a601d7e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:42:20.252722Z","signature_b64":"i+QotwRU4YxatnKAjb10BYD8nk0GlY4p7yj1D5I1l4scfA7VueIpwMBblBD4RkBigKqv8hzMxDnQJ5d1YD+WAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"01732547d64d8e57ddfb3d0d14bf7157a13c8cf1323f3d36f66a259b32498764","last_reissued_at":"2026-07-05T11:42:20.252322Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:42:20.252322Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Weak-to-Strong Jailbreaking on Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Chao Du, Lei Li, Tianyu Pang, William Yang Wang, Xianjun Yang, Xuandong Zhao, Yu-Xiang Wang","submitted_at":"2024-01-30T18:48:37Z","abstract_excerpt":"Large language models (LLMs) are vulnerable to jailbreak attacks - resulting in harmful, unethical, or biased text generations. However, existing jailbreaking methods are computationally costly. In this paper, we propose the weak-to-strong jailbreaking attack, an efficient inference time attack for aligned LLMs to produce harmful text. Our key intuition is based on the observation that jailbroken and aligned models only differ in their initial decoding distributions. The weak-to-strong attack's key technical insight is using two smaller models (a safe and an unsafe one) to adversarially modify"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2401.17256","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2401.17256/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2401.17256","created_at":"2026-07-05T11:42:20.252374+00:00"},{"alias_kind":"arxiv_version","alias_value":"2401.17256v5","created_at":"2026-07-05T11:42:20.252374+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2401.17256","created_at":"2026-07-05T11:42:20.252374+00:00"},{"alias_kind":"pith_short_12","alias_value":"AFZSKR6WJWHF","created_at":"2026-07-05T11:42:20.252374+00:00"},{"alias_kind":"pith_short_16","alias_value":"AFZSKR6WJWHFPXP3","created_at":"2026-07-05T11:42:20.252374+00:00"},{"alias_kind":"pith_short_8","alias_value":"AFZSKR6W","created_at":"2026-07-05T11:42:20.252374+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":9,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22686","citing_title":"The Geometry of Refusal: Linear Instability in Safety-Aligned LLMs","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2606.05609","citing_title":"SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak Attacks","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2606.22686","citing_title":"The Geometry of Refusal: Linear Instability in Safety-Aligned LLMs","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2502.05206","citing_title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","ref_index":97,"is_internal_anchor":false},{"citing_arxiv_id":"2502.01241","citing_title":"Peering Behind the Shield: Guardrail Identification in Large Language Models","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00424","citing_title":"Skills as Verifiable Artifacts: A Trust Schema and a Biconditional Correctness Criterion for Human-in-the-Loop Agent Runtimes","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2506.17299","citing_title":"Toward Principled LLM Safety Testing: Solving the Jailbreak Oracle Problem","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":117,"is_internal_anchor":false},{"citing_arxiv_id":"2604.14602","citing_title":"CausalDetox: Causal Head Selection and Intervention for Language Model Detoxification","ref_index":8,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6","json":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6.json","graph_json":"https://pith.science/api/pith-number/AFZSKR6WJWHFPXP3HUGRJP3RK6/graph.json","events_json":"https://pith.science/api/pith-number/AFZSKR6WJWHFPXP3HUGRJP3RK6/events.json","paper":"https://pith.science/paper/AFZSKR6W"},"agent_actions":{"view_html":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6","download_json":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6.json","view_paper":"https://pith.science/paper/AFZSKR6W","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2401.17256&json=true","fetch_graph":"https://pith.science/api/pith-number/AFZSKR6WJWHFPXP3HUGRJP3RK6/graph.json","fetch_events":"https://pith.science/api/pith-number/AFZSKR6WJWHFPXP3HUGRJP3RK6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6/action/storage_attestation","attest_author":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6/action/author_attestation","sign_citation":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6/action/citation_signature","submit_replication":"https://pith.science/pith/AFZSKR6WJWHFPXP3HUGRJP3RK6/action/replication_record"}},"created_at":"2026-07-05T11:42:20.252374+00:00","updated_at":"2026-07-05T11:42:20.252374+00:00"}