{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:CLN7SEMY3I54DDDBLIV3BS5IKB","short_pith_number":"pith:CLN7SEMY","schema_version":"1.0","canonical_sha256":"12dbf91198da3bc18c615a2bb0cba85062461425a703df1fcb5bb52702d96f16","source":{"kind":"arxiv","id":"2503.08195","version":1},"attestation_state":"computed","paper":{"title":"Dialogue Injection Attack: Jailbreaking LLMs through Context Manipulation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Chengkun Wei, Fan Zhang, Wendao Yao, Wenlong Meng, Wenzhi Chen, Yuwei Li, Zhenyuan Guo","submitted_at":"2025-03-11T09:00:45Z","abstract_excerpt":"Large language models (LLMs) have demonstrated significant utility in a wide range of applications; however, their deployment is plagued by security vulnerabilities, notably jailbreak attacks. These attacks manipulate LLMs to generate harmful or unethical content by crafting adversarial prompts. While much of the current research on jailbreak attacks has focused on single-turn interactions, it has largely overlooked the impact of historical dialogues on model behavior. In this paper, we introduce a novel jailbreak paradigm, Dialogue Injection Attack (DIA), which leverages the dialogue history "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.08195","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-03-11T09:00:45Z","cross_cats_sorted":[],"title_canon_sha256":"44387cf48df0363cda0f5db280e844225014def134d02f6e27dac6800964d018","abstract_canon_sha256":"5c48c62eddd0bd85d1590f1321f3c775de7693abe88be79e59f84c778f9b3495"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:28:53.551935Z","signature_b64":"A5svFutzApJNpPOyYkNFo8brjyScyA9RUTURoHd5tge82LJCuE+wXL1SPexXRruAwmoa/tA9Hbt0QiIUW+73DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"12dbf91198da3bc18c615a2bb0cba85062461425a703df1fcb5bb52702d96f16","last_reissued_at":"2026-07-05T10:28:53.551090Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:28:53.551090Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Dialogue Injection Attack: Jailbreaking LLMs through Context Manipulation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Chengkun Wei, Fan Zhang, Wendao Yao, Wenlong Meng, Wenzhi Chen, Yuwei Li, Zhenyuan Guo","submitted_at":"2025-03-11T09:00:45Z","abstract_excerpt":"Large language models (LLMs) have demonstrated significant utility in a wide range of applications; however, their deployment is plagued by security vulnerabilities, notably jailbreak attacks. These attacks manipulate LLMs to generate harmful or unethical content by crafting adversarial prompts. While much of the current research on jailbreak attacks has focused on single-turn interactions, it has largely overlooked the impact of historical dialogues on model behavior. In this paper, we introduce a novel jailbreak paradigm, Dialogue Injection Attack (DIA), which leverages the dialogue history "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.08195","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.08195/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.08195","created_at":"2026-07-05T10:28:53.551219+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.08195v1","created_at":"2026-07-05T10:28:53.551219+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.08195","created_at":"2026-07-05T10:28:53.551219+00:00"},{"alias_kind":"pith_short_12","alias_value":"CLN7SEMY3I54","created_at":"2026-07-05T10:28:53.551219+00:00"},{"alias_kind":"pith_short_16","alias_value":"CLN7SEMY3I54DDDB","created_at":"2026-07-05T10:28:53.551219+00:00"},{"alias_kind":"pith_short_8","alias_value":"CLN7SEMY","created_at":"2026-07-05T10:28:53.551219+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.00150","citing_title":"Persona Attack: Incremental Memory Injection Jailbreak Attack against Large Language Models","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB","json":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB.json","graph_json":"https://pith.science/api/pith-number/CLN7SEMY3I54DDDBLIV3BS5IKB/graph.json","events_json":"https://pith.science/api/pith-number/CLN7SEMY3I54DDDBLIV3BS5IKB/events.json","paper":"https://pith.science/paper/CLN7SEMY"},"agent_actions":{"view_html":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB","download_json":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB.json","view_paper":"https://pith.science/paper/CLN7SEMY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.08195&json=true","fetch_graph":"https://pith.science/api/pith-number/CLN7SEMY3I54DDDBLIV3BS5IKB/graph.json","fetch_events":"https://pith.science/api/pith-number/CLN7SEMY3I54DDDBLIV3BS5IKB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB/action/storage_attestation","attest_author":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB/action/author_attestation","sign_citation":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB/action/citation_signature","submit_replication":"https://pith.science/pith/CLN7SEMY3I54DDDBLIV3BS5IKB/action/replication_record"}},"created_at":"2026-07-05T10:28:53.551219+00:00","updated_at":"2026-07-05T10:28:53.551219+00:00"}