{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:CASFHT776N3W6KSHO22JQPUUA4","short_pith_number":"pith:CASFHT77","schema_version":"1.0","canonical_sha256":"102453cffff3776f2a4776b4983e94071b5542278173f61a19cb24fef705fa14","source":{"kind":"arxiv","id":"2402.11753","version":4},"attestation_state":"computed","paper":{"title":"ArtPrompt: ASCII Art-based Jailbreak Attacks against Aligned LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Bhaskar Ramasubramanian, Bo Li, Fengqing Jiang, Luyao Niu, Radha Poovendran, Zhangchen Xu, Zhen Xiang","submitted_at":"2024-02-19T00:43:31Z","abstract_excerpt":"Safety is critical to the usage of large language models (LLMs). Multiple techniques such as data filtering and supervised fine-tuning have been developed to strengthen LLM safety. However, currently known techniques presume that corpora used for safety alignment of LLMs are solely interpreted by semantics. This assumption, however, does not hold in real-world applications, which leads to severe vulnerabilities in LLMs. For example, users of forums often use ASCII art, a form of text-based art, to convey image information. In this paper, we propose a novel ASCII art-based jailbreak attack and "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.11753","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-19T00:43:31Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"273bd762eeda217272e57dfbac49a56b5b95fa29f2c1734fb05c49c9b87e2e58","abstract_canon_sha256":"e8478c0668188f29a6f3fe892f2409008573e3bb0ecba20f3573bf8188677dc6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:28:38.537220Z","signature_b64":"2wBodMRyxnbXgTK1V1sRtNKphircehX1Za9q7mfgq8ix5uHKYbAtiGOha0YQyYtePTSQS5O3t7SPjhI8mORBBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"102453cffff3776f2a4776b4983e94071b5542278173f61a19cb24fef705fa14","last_reissued_at":"2026-07-05T08:28:38.536786Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:28:38.536786Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ArtPrompt: ASCII Art-based Jailbreak Attacks against Aligned LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Bhaskar Ramasubramanian, Bo Li, Fengqing Jiang, Luyao Niu, Radha Poovendran, Zhangchen Xu, Zhen Xiang","submitted_at":"2024-02-19T00:43:31Z","abstract_excerpt":"Safety is critical to the usage of large language models (LLMs). Multiple techniques such as data filtering and supervised fine-tuning have been developed to strengthen LLM safety. However, currently known techniques presume that corpora used for safety alignment of LLMs are solely interpreted by semantics. This assumption, however, does not hold in real-world applications, which leads to severe vulnerabilities in LLMs. For example, users of forums often use ASCII art, a form of text-based art, to convey image information. In this paper, we propose a novel ASCII art-based jailbreak attack and "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.11753","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.11753/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.11753","created_at":"2026-07-05T08:28:38.536847+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.11753v4","created_at":"2026-07-05T08:28:38.536847+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.11753","created_at":"2026-07-05T08:28:38.536847+00:00"},{"alias_kind":"pith_short_12","alias_value":"CASFHT776N3W","created_at":"2026-07-05T08:28:38.536847+00:00"},{"alias_kind":"pith_short_16","alias_value":"CASFHT776N3W6KSH","created_at":"2026-07-05T08:28:38.536847+00:00"},{"alias_kind":"pith_short_8","alias_value":"CASFHT77","created_at":"2026-07-05T08:28:38.536847+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2511.02356","citing_title":"ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2512.10100","citing_title":"Robust AI Security and Alignment: A Sisyphean Endeavor?","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":40,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4","json":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4.json","graph_json":"https://pith.science/api/pith-number/CASFHT776N3W6KSHO22JQPUUA4/graph.json","events_json":"https://pith.science/api/pith-number/CASFHT776N3W6KSHO22JQPUUA4/events.json","paper":"https://pith.science/paper/CASFHT77"},"agent_actions":{"view_html":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4","download_json":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4.json","view_paper":"https://pith.science/paper/CASFHT77","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.11753&json=true","fetch_graph":"https://pith.science/api/pith-number/CASFHT776N3W6KSHO22JQPUUA4/graph.json","fetch_events":"https://pith.science/api/pith-number/CASFHT776N3W6KSHO22JQPUUA4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4/action/storage_attestation","attest_author":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4/action/author_attestation","sign_citation":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4/action/citation_signature","submit_replication":"https://pith.science/pith/CASFHT776N3W6KSHO22JQPUUA4/action/replication_record"}},"created_at":"2026-07-05T08:28:38.536847+00:00","updated_at":"2026-07-05T08:28:38.536847+00:00"}