{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:GRTQLQQ66N7LMPYSX64VJIWEFN","short_pith_number":"pith:GRTQLQQ6","schema_version":"1.0","canonical_sha256":"346705c21ef37eb63f12bfb954a2c42b56abeb2809f7253828124a60f6fd1e68","source":{"kind":"arxiv","id":"2402.16914","version":3},"attestation_state":"computed","paper":{"title":"DrAttack: Prompt Decomposition and Reconstruction Makes Powerful LLM Jailbreakers","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Cho-Jui Hsieh, Minhao Cheng, Ruochen Wang, Tianyi Zhou, Xirui Li","submitted_at":"2024-02-25T17:43:29Z","abstract_excerpt":"The safety alignment of Large Language Models (LLMs) is vulnerable to both manual and automated jailbreak attacks, which adversarially trigger LLMs to output harmful content. However, current methods for jailbreaking LLMs, which nest entire harmful prompts, are not effective at concealing malicious intent and can be easily identified and rejected by well-aligned LLMs. This paper discovers that decomposing a malicious prompt into separated sub-prompts can effectively obscure its underlying malicious intent by presenting it in a fragmented, less detectable form, thereby addressing these limitati"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.16914","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-02-25T17:43:29Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"bda6a36098c4674226d9a9d1377feb8e2eda1e8fa29cb493ad6274fedabbba8f","abstract_canon_sha256":"c8a370c6ad4defb64578ace16991449f7e9fb165295347702d5f33c76067a1e9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:34:11.757721Z","signature_b64":"gma9odeQFRabCxDjZ5KIOvsh20Np+AlkDFMyajLhhDZG3F6jW5azExeEx1Pf2RvRi75xyKWE/dUUx82UzBQkAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"346705c21ef37eb63f12bfb954a2c42b56abeb2809f7253828124a60f6fd1e68","last_reissued_at":"2026-07-05T09:34:11.757139Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:34:11.757139Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"DrAttack: Prompt Decomposition and Reconstruction Makes Powerful LLM Jailbreakers","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Cho-Jui Hsieh, Minhao Cheng, Ruochen Wang, Tianyi Zhou, Xirui Li","submitted_at":"2024-02-25T17:43:29Z","abstract_excerpt":"The safety alignment of Large Language Models (LLMs) is vulnerable to both manual and automated jailbreak attacks, which adversarially trigger LLMs to output harmful content. However, current methods for jailbreaking LLMs, which nest entire harmful prompts, are not effective at concealing malicious intent and can be easily identified and rejected by well-aligned LLMs. This paper discovers that decomposing a malicious prompt into separated sub-prompts can effectively obscure its underlying malicious intent by presenting it in a fragmented, less detectable form, thereby addressing these limitati"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.16914","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.16914/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.16914","created_at":"2026-07-05T09:34:11.757197+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.16914v3","created_at":"2026-07-05T09:34:11.757197+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.16914","created_at":"2026-07-05T09:34:11.757197+00:00"},{"alias_kind":"pith_short_12","alias_value":"GRTQLQQ66N7L","created_at":"2026-07-05T09:34:11.757197+00:00"},{"alias_kind":"pith_short_16","alias_value":"GRTQLQQ66N7LMPYS","created_at":"2026-07-05T09:34:11.757197+00:00"},{"alias_kind":"pith_short_8","alias_value":"GRTQLQQ6","created_at":"2026-07-05T09:34:11.757197+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":10,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07335","citing_title":"Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2605.31593","citing_title":"Stateful Online Monitoring Catches Distributed Agent Attacks","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21674","citing_title":"Adversarial Reframing: A Framework for Targeted Generation in Language Models","ref_index":29,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17971","citing_title":"Babel: Jailbreaking Safety Attention via Obfuscation Distribution Optimized Sampling","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2506.06414","citing_title":"Benchmarking Misuse Mitigation Against Covert Adversaries","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2508.20325","citing_title":"GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2511.02356","citing_title":"ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2604.01473","citing_title":"SelfGrader: LLM Jailbreak Detection via Anchored Token-Level Logits","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.10326","citing_title":"Jailbreaking the Matrix: Nullspace Steering for Controlled Model Subversion","ref_index":27,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN","json":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN.json","graph_json":"https://pith.science/api/pith-number/GRTQLQQ66N7LMPYSX64VJIWEFN/graph.json","events_json":"https://pith.science/api/pith-number/GRTQLQQ66N7LMPYSX64VJIWEFN/events.json","paper":"https://pith.science/paper/GRTQLQQ6"},"agent_actions":{"view_html":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN","download_json":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN.json","view_paper":"https://pith.science/paper/GRTQLQQ6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.16914&json=true","fetch_graph":"https://pith.science/api/pith-number/GRTQLQQ66N7LMPYSX64VJIWEFN/graph.json","fetch_events":"https://pith.science/api/pith-number/GRTQLQQ66N7LMPYSX64VJIWEFN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN/action/storage_attestation","attest_author":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN/action/author_attestation","sign_citation":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN/action/citation_signature","submit_replication":"https://pith.science/pith/GRTQLQQ66N7LMPYSX64VJIWEFN/action/replication_record"}},"created_at":"2026-07-05T09:34:11.757197+00:00","updated_at":"2026-07-05T09:34:11.757197+00:00"}