{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:JOHEVSJM6DDVMWBY3EIWWD2R6V","short_pith_number":"pith:JOHEVSJM","schema_version":"1.0","canonical_sha256":"4b8e4ac92cf0c7565838d9116b0f51f5444ae2ebe377dd720439e2c8f07aa7c7","source":{"kind":"arxiv","id":"2405.05610","version":1},"attestation_state":"computed","paper":{"title":"Chain of Attack: a Semantic-Driven Contextual Multi-Turn attacker for LLM","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CL","authors_text":"Jizhong Han, Songlin Hu, Xikang Yang, Xuehai Tang","submitted_at":"2024-05-09T08:15:21Z","abstract_excerpt":"Large language models (LLMs) have achieved remarkable performance in various natural language processing tasks, especially in dialogue systems. However, LLM may also pose security and moral threats, especially in multi round conversations where large models are more easily guided by contextual content, resulting in harmful or biased responses. In this paper, we present a novel method to attack LLMs in multi-turn dialogues, called CoA (Chain of Attack). CoA is a semantic-driven contextual multi-turn attack method that adaptively adjusts the attack policy through contextual feedback and semantic"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.05610","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2024-05-09T08:15:21Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"ae88f980d75f14391aa6d6ab7e490716e824ef12248bdf2cd2bd7a8866cf9ccb","abstract_canon_sha256":"20a1e1fa65fd12528c1206568638c4b8c668ce8011a43b0e9063609275c5e950"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:17:20.510745Z","signature_b64":"md6kDXnwa+L3f5hS/FDK7rO8NUOh05iO5OMuYu+AKI93hTlv3Yo2N/fKEGheQzKBX6EuTIgn6MNP/V1AJoFpBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4b8e4ac92cf0c7565838d9116b0f51f5444ae2ebe377dd720439e2c8f07aa7c7","last_reissued_at":"2026-07-05T08:17:20.510270Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:17:20.510270Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Chain of Attack: a Semantic-Driven Contextual Multi-Turn attacker for LLM","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CL","authors_text":"Jizhong Han, Songlin Hu, Xikang Yang, Xuehai Tang","submitted_at":"2024-05-09T08:15:21Z","abstract_excerpt":"Large language models (LLMs) have achieved remarkable performance in various natural language processing tasks, especially in dialogue systems. However, LLM may also pose security and moral threats, especially in multi round conversations where large models are more easily guided by contextual content, resulting in harmful or biased responses. In this paper, we present a novel method to attack LLMs in multi-turn dialogues, called CoA (Chain of Attack). CoA is a semantic-driven contextual multi-turn attack method that adaptively adjusts the attack policy through contextual feedback and semantic"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.05610","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.05610/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.05610","created_at":"2026-07-05T08:17:20.510361+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.05610v1","created_at":"2026-07-05T08:17:20.510361+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.05610","created_at":"2026-07-05T08:17:20.510361+00:00"},{"alias_kind":"pith_short_12","alias_value":"JOHEVSJM6DDV","created_at":"2026-07-05T08:17:20.510361+00:00"},{"alias_kind":"pith_short_16","alias_value":"JOHEVSJM6DDVMWBY","created_at":"2026-07-05T08:17:20.510361+00:00"},{"alias_kind":"pith_short_8","alias_value":"JOHEVSJM","created_at":"2026-07-05T08:17:20.510361+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24267","citing_title":"Pigeonholing: how bad prompts hurt models, causing collapse and mistakes","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2511.12710","citing_title":"Evolve the Method, Not the Prompts: Evolutionary Synthesis of Jailbreak Attacks on LLMs","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11002","citing_title":"MT-JailBench: A Modular Benchmark for Understanding Multi-Turn Jailbreak Attacks","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10386","citing_title":"GuardAD: Safeguarding Autonomous Driving MLLMs via Markovian Safety Logic","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24082","citing_title":"Jailbreaking Frontier Foundation Models Through Intention Deception","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08608","citing_title":"Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V","json":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V.json","graph_json":"https://pith.science/api/pith-number/JOHEVSJM6DDVMWBY3EIWWD2R6V/graph.json","events_json":"https://pith.science/api/pith-number/JOHEVSJM6DDVMWBY3EIWWD2R6V/events.json","paper":"https://pith.science/paper/JOHEVSJM"},"agent_actions":{"view_html":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V","download_json":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V.json","view_paper":"https://pith.science/paper/JOHEVSJM","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.05610&json=true","fetch_graph":"https://pith.science/api/pith-number/JOHEVSJM6DDVMWBY3EIWWD2R6V/graph.json","fetch_events":"https://pith.science/api/pith-number/JOHEVSJM6DDVMWBY3EIWWD2R6V/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V/action/storage_attestation","attest_author":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V/action/author_attestation","sign_citation":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V/action/citation_signature","submit_replication":"https://pith.science/pith/JOHEVSJM6DDVMWBY3EIWWD2R6V/action/replication_record"}},"created_at":"2026-07-05T08:17:20.510361+00:00","updated_at":"2026-07-05T08:17:20.510361+00:00"}