{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:DY4HZAFBZOALW7J33QWK23Q4Z2","short_pith_number":"pith:DY4HZAFB","schema_version":"1.0","canonical_sha256":"1e387c80a1cb80bb7d3bdc2cad6e1cce92ad58dab2ce6a385222c5e6d81c48ca","source":{"kind":"arxiv","id":"2402.14020","version":1},"attestation_state":"computed","paper":{"title":"Coercing LLMs to do and reveal (almost) anything","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Alex Stein, Jonas Geiping, Khalid Saifullah, Manli Shu, Tom Goldstein, Yuxin Wen","submitted_at":"2024-02-21T18:59:13Z","abstract_excerpt":"It has recently been shown that adversarial attacks on large language models (LLMs) can \"jailbreak\" the model into making harmful statements. In this work, we argue that the spectrum of adversarial attacks on LLMs is much larger than merely jailbreaking. We provide a broad overview of possible attack surfaces and attack goals. Based on a series of concrete examples, we discuss, categorize and systematize attacks that coerce varied unintended behaviors, such as misdirection, model control, denial-of-service, or data extraction.\n  We analyze these attacks in controlled experiments, and find that"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.14020","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-02-21T18:59:13Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"f0c855b87e00d2d8229cf8667141d61d2547e4aaa64fc57ca6610a889276c106","abstract_canon_sha256":"28f7fa54f5f1e53d4ecd790e4a2f1070a95ed6dc91a4037f12be3a8d1d10085c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:47:51.403202Z","signature_b64":"V9fstydVRhGh2e4rmo/vslNmxzWkrnb9aPNf+5f7g4MPEoNh4pw5TeMHSSX2jTDadWAALFUZwYmued69J/0FDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1e387c80a1cb80bb7d3bdc2cad6e1cce92ad58dab2ce6a385222c5e6d81c48ca","last_reissued_at":"2026-07-05T07:47:51.402782Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:47:51.402782Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Coercing LLMs to do and reveal (almost) anything","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Alex Stein, Jonas Geiping, Khalid Saifullah, Manli Shu, Tom Goldstein, Yuxin Wen","submitted_at":"2024-02-21T18:59:13Z","abstract_excerpt":"It has recently been shown that adversarial attacks on large language models (LLMs) can \"jailbreak\" the model into making harmful statements. In this work, we argue that the spectrum of adversarial attacks on LLMs is much larger than merely jailbreaking. We provide a broad overview of possible attack surfaces and attack goals. Based on a series of concrete examples, we discuss, categorize and systematize attacks that coerce varied unintended behaviors, such as misdirection, model control, denial-of-service, or data extraction.\n  We analyze these attacks in controlled experiments, and find that"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.14020","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.14020/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.14020","created_at":"2026-07-05T07:47:51.402840+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.14020v1","created_at":"2026-07-05T07:47:51.402840+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.14020","created_at":"2026-07-05T07:47:51.402840+00:00"},{"alias_kind":"pith_short_12","alias_value":"DY4HZAFBZOAL","created_at":"2026-07-05T07:47:51.402840+00:00"},{"alias_kind":"pith_short_16","alias_value":"DY4HZAFBZOALW7J3","created_at":"2026-07-05T07:47:51.402840+00:00"},{"alias_kind":"pith_short_8","alias_value":"DY4HZAFB","created_at":"2026-07-05T07:47:51.402840+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":10,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07968","citing_title":"RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2606.07943","citing_title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2506.14493","citing_title":"LingoLoop Attack: Trapping MLLMs via Linguistic Context and State Entrapment into Endless Loops","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2507.12720","citing_title":"FLEXITOKENS: Flexible Tokenization for Evolving Language Models","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2406.13352","citing_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2404.13208","citing_title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05116","citing_title":"On the Hardness of Junking LLMs","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00236","citing_title":"Attention Is Where You Attack","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08519","citing_title":"Cram Less to Fit More: Training Data Pruning Improves Memorization of Facts","ref_index":28,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2","json":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2.json","graph_json":"https://pith.science/api/pith-number/DY4HZAFBZOALW7J33QWK23Q4Z2/graph.json","events_json":"https://pith.science/api/pith-number/DY4HZAFBZOALW7J33QWK23Q4Z2/events.json","paper":"https://pith.science/paper/DY4HZAFB"},"agent_actions":{"view_html":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2","download_json":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2.json","view_paper":"https://pith.science/paper/DY4HZAFB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.14020&json=true","fetch_graph":"https://pith.science/api/pith-number/DY4HZAFBZOALW7J33QWK23Q4Z2/graph.json","fetch_events":"https://pith.science/api/pith-number/DY4HZAFBZOALW7J33QWK23Q4Z2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2/action/storage_attestation","attest_author":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2/action/author_attestation","sign_citation":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2/action/citation_signature","submit_replication":"https://pith.science/pith/DY4HZAFBZOALW7J33QWK23Q4Z2/action/replication_record"}},"created_at":"2026-07-05T07:47:51.402840+00:00","updated_at":"2026-07-05T07:47:51.402840+00:00"}