{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:JQ6CZIYLJZ2RGDLDBUZ6YAUIWE","short_pith_number":"pith:JQ6CZIYL","schema_version":"1.0","canonical_sha256":"4c3c2ca30b4e75130d630d33ec0288b12cbca8e4c7a40e4326ca20cf7ebadad2","source":{"kind":"arxiv","id":"2312.12321","version":2},"attestation_state":"computed","paper":{"title":"Bypassing the Safety Training of Open-Source LLMs with Priming Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Changming Xu, Gagandeep Singh, Isha Chaudhary, Jason Vega","submitted_at":"2023-12-19T16:47:12Z","abstract_excerpt":"With the recent surge in popularity of LLMs has come an ever-increasing need for LLM safety training. In this paper, we investigate the fragility of SOTA open-source LLMs under simple, optimization-free attacks we refer to as $\\textit{priming attacks}$, which are easy to execute and effectively bypass alignment from safety training. Our proposed attack improves the Attack Success Rate on Harmful Behaviors, as measured by Llama Guard, by up to $3.3\\times$ compared to baselines. Source code and data are available at https://github.com/uiuc-focal-lab/llm-priming-attacks."},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2312.12321","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-12-19T16:47:12Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"9adf5facd573caed217df7a48ed5fc17f5651353e17e6082d9151fbc09ad6e9c","abstract_canon_sha256":"68aeea68b057f65d05c3def9444b44116a1ee7b8ac93ab8da0bc77ca78af3c60"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:20:09.200835Z","signature_b64":"P8uuEqaIl3tqY8qah7aaJr4fbuTBFlsPCm/NhsUE0cjf+rIH6cpsZWsNziLAP4SaWEdIvIREMG/JjXthYrvuDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4c3c2ca30b4e75130d630d33ec0288b12cbca8e4c7a40e4326ca20cf7ebadad2","last_reissued_at":"2026-07-05T08:20:09.200403Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:20:09.200403Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Bypassing the Safety Training of Open-Source LLMs with Priming Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Changming Xu, Gagandeep Singh, Isha Chaudhary, Jason Vega","submitted_at":"2023-12-19T16:47:12Z","abstract_excerpt":"With the recent surge in popularity of LLMs has come an ever-increasing need for LLM safety training. In this paper, we investigate the fragility of SOTA open-source LLMs under simple, optimization-free attacks we refer to as $\\textit{priming attacks}$, which are easy to execute and effectively bypass alignment from safety training. Our proposed attack improves the Attack Success Rate on Harmful Behaviors, as measured by Llama Guard, by up to $3.3\\times$ compared to baselines. Source code and data are available at https://github.com/uiuc-focal-lab/llm-priming-attacks."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2312.12321","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2312.12321/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2312.12321","created_at":"2026-07-05T08:20:09.200459+00:00"},{"alias_kind":"arxiv_version","alias_value":"2312.12321v2","created_at":"2026-07-05T08:20:09.200459+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2312.12321","created_at":"2026-07-05T08:20:09.200459+00:00"},{"alias_kind":"pith_short_12","alias_value":"JQ6CZIYLJZ2R","created_at":"2026-07-05T08:20:09.200459+00:00"},{"alias_kind":"pith_short_16","alias_value":"JQ6CZIYLJZ2RGDLD","created_at":"2026-07-05T08:20:09.200459+00:00"},{"alias_kind":"pith_short_8","alias_value":"JQ6CZIYL","created_at":"2026-07-05T08:20:09.200459+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.30989","citing_title":"Wait, am I Being Fair? Characterizing Deductive Stereotyping and Mitigating It with Fair-GCG","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30449","citing_title":"Internal-State Probes Read the Situation, Not the Action: Three Negative Results for Pre-Action Misalignment Monitoring","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15239","citing_title":"Reducing the Safety Tax in LLM Safety Alignment with On-Policy Self-Distillation","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10998","citing_title":"Few-Shot Truly Benign DPO Attack for Jailbreaking LLMs","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE","json":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE.json","graph_json":"https://pith.science/api/pith-number/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/graph.json","events_json":"https://pith.science/api/pith-number/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/events.json","paper":"https://pith.science/paper/JQ6CZIYL"},"agent_actions":{"view_html":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE","download_json":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE.json","view_paper":"https://pith.science/paper/JQ6CZIYL","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2312.12321&json=true","fetch_graph":"https://pith.science/api/pith-number/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/graph.json","fetch_events":"https://pith.science/api/pith-number/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/action/storage_attestation","attest_author":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/action/author_attestation","sign_citation":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/action/citation_signature","submit_replication":"https://pith.science/pith/JQ6CZIYLJZ2RGDLDBUZ6YAUIWE/action/replication_record"}},"created_at":"2026-07-05T08:20:09.200459+00:00","updated_at":"2026-07-05T08:20:09.200459+00:00"}