{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:F2HGAKBRV7XIAUDRI7MTAYES5Y","short_pith_number":"pith:F2HGAKBR","schema_version":"1.0","canonical_sha256":"2e8e602831afee80507147d9306092ee1294cf3f30bb672e04dcfd0432b041a8","source":{"kind":"arxiv","id":"2501.04931","version":2},"attestation_state":"computed","paper":{"title":"Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Caixin Kang, Chi Chen, Fengxiang Wang, Hui Xue, Jialing Tao, Ranjie Duan, Shiji Zhao, Shouwei Ruan, Xingxing Wei, Yuefeng Chen","submitted_at":"2025-01-09T02:47:01Z","abstract_excerpt":"Multimodal Large Language Models (MLLMs) have achieved impressive performance and have been put into practical use in commercial applications, but they still have potential safety mechanism vulnerabilities. Jailbreak attacks are red teaming methods that aim to bypass safety mechanisms and discover MLLMs' potential risks. Existing MLLMs' jailbreak methods often bypass the model's safety mechanism through complex optimization methods or carefully designed image and text prompts. Despite achieving some progress, they have a low attack success rate on commercial closed-source MLLMs. Unlike previou"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2501.04931","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-01-09T02:47:01Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"ed8bd6495c959ac39f1035c3e1a9bc94b14b1bdfed628cecbe94e07a2593930a","abstract_canon_sha256":"15b73bb2752996a7eff5123f312e85ad48b5c162e77f08b2fbf37bf6385ab0e2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:28:13.460544Z","signature_b64":"1e1fV528rcozpGYRwCF9/ss5jdUJTthNgnseeorG4+0+hbf9djHZh/0VjOhxIUXPHABVQReGQrnPxIVtm1LtDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2e8e602831afee80507147d9306092ee1294cf3f30bb672e04dcfd0432b041a8","last_reissued_at":"2026-07-05T11:28:13.460024Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:28:13.460024Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Caixin Kang, Chi Chen, Fengxiang Wang, Hui Xue, Jialing Tao, Ranjie Duan, Shiji Zhao, Shouwei Ruan, Xingxing Wei, Yuefeng Chen","submitted_at":"2025-01-09T02:47:01Z","abstract_excerpt":"Multimodal Large Language Models (MLLMs) have achieved impressive performance and have been put into practical use in commercial applications, but they still have potential safety mechanism vulnerabilities. Jailbreak attacks are red teaming methods that aim to bypass safety mechanisms and discover MLLMs' potential risks. Existing MLLMs' jailbreak methods often bypass the model's safety mechanism through complex optimization methods or carefully designed image and text prompts. Despite achieving some progress, they have a low attack success rate on commercial closed-source MLLMs. Unlike previou"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2501.04931","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2501.04931/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2501.04931","created_at":"2026-07-05T11:28:13.460084+00:00"},{"alias_kind":"arxiv_version","alias_value":"2501.04931v2","created_at":"2026-07-05T11:28:13.460084+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2501.04931","created_at":"2026-07-05T11:28:13.460084+00:00"},{"alias_kind":"pith_short_12","alias_value":"F2HGAKBRV7XI","created_at":"2026-07-05T11:28:13.460084+00:00"},{"alias_kind":"pith_short_16","alias_value":"F2HGAKBRV7XIAUDR","created_at":"2026-07-05T11:28:13.460084+00:00"},{"alias_kind":"pith_short_8","alias_value":"F2HGAKBR","created_at":"2026-07-05T11:28:13.460084+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.01837","citing_title":"Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2507.21540","citing_title":"PRISM: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2601.03416","citing_title":"GAMBIT: A Gamified Jailbreak Framework for Multimodal Large Language Models","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11309","citing_title":"The Salami Slicing Threat: Exploiting Cumulative Risks in LLM Systems","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09253","citing_title":"Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization","ref_index":44,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y","json":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y.json","graph_json":"https://pith.science/api/pith-number/F2HGAKBRV7XIAUDRI7MTAYES5Y/graph.json","events_json":"https://pith.science/api/pith-number/F2HGAKBRV7XIAUDRI7MTAYES5Y/events.json","paper":"https://pith.science/paper/F2HGAKBR"},"agent_actions":{"view_html":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y","download_json":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y.json","view_paper":"https://pith.science/paper/F2HGAKBR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2501.04931&json=true","fetch_graph":"https://pith.science/api/pith-number/F2HGAKBRV7XIAUDRI7MTAYES5Y/graph.json","fetch_events":"https://pith.science/api/pith-number/F2HGAKBRV7XIAUDRI7MTAYES5Y/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y/action/timestamp_anchor","attest_storage":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y/action/storage_attestation","attest_author":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y/action/author_attestation","sign_citation":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y/action/citation_signature","submit_replication":"https://pith.science/pith/F2HGAKBRV7XIAUDRI7MTAYES5Y/action/replication_record"}},"created_at":"2026-07-05T11:28:13.460084+00:00","updated_at":"2026-07-05T11:28:13.460084+00:00"}