{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:MQ35J3WXEG6FHEIRQSB3R6B3ZN","short_pith_number":"pith:MQ35J3WX","canonical_record":{"source":{"id":"2509.06350","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-08T05:45:37Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"96c29a00a343e318aac18c6f7aed3f8462e7017bee056880bb6c14c619b5df6d","abstract_canon_sha256":"854c52928f607ff77ba13f7f7a2f21c961184888a52d3f81d62e71bccd68fa01"},"schema_version":"1.0"},"canonical_sha256":"6437d4eed721bc5391118483b8f83bcb78ee260e254c3d55f853f470beaf0a68","source":{"kind":"arxiv","id":"2509.06350","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2509.06350","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"arxiv_version","alias_value":"2509.06350v2","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.06350","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_12","alias_value":"MQ35J3WXEG6F","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_16","alias_value":"MQ35J3WXEG6FHEIR","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_8","alias_value":"MQ35J3WX","created_at":"2026-05-28T01:04:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:MQ35J3WXEG6FHEIRQSB3R6B3ZN","target":"record","payload":{"canonical_record":{"source":{"id":"2509.06350","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-08T05:45:37Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"96c29a00a343e318aac18c6f7aed3f8462e7017bee056880bb6c14c619b5df6d","abstract_canon_sha256":"854c52928f607ff77ba13f7f7a2f21c961184888a52d3f81d62e71bccd68fa01"},"schema_version":"1.0"},"canonical_sha256":"6437d4eed721bc5391118483b8f83bcb78ee260e254c3d55f853f470beaf0a68","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-28T01:04:30.308515Z","signature_b64":"4V5uEXD9O77To6MvRClG0yaANKhQ1bGw6ofdAR/XrPfZGYBHer/hJURvseJ9JjZd+feXcM89RbZdgWMjkq9oAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6437d4eed721bc5391118483b8f83bcb78ee260e254c3d55f853f470beaf0a68","last_reissued_at":"2026-05-28T01:04:30.307751Z","signature_status":"signed_v1","first_computed_at":"2026-05-28T01:04:30.307751Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2509.06350","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T01:04:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"onRUW+No/AtSk140UznKTMaQ+y6X2wmayQ0E8DzUpNt8UNJjgvqVqYhxjdqtcFNCt7kACPJlr867BHzvEjcZDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T17:28:53.915974Z"},"content_sha256":"08b404451138537e7b407f0ac1bd5d740501e38ac18525c45b8b4c85b34af094","schema_version":"1.0","event_id":"sha256:08b404451138537e7b407f0ac1bd5d740501e38ac18525c45b8b4c85b34af094"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:MQ35J3WXEG6FHEIRQSB3R6B3ZN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Mask-GCG: Are All Tokens in Adversarial Suffixes Necessary for Jailbreak Attacks?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.CL","authors_text":"Junjie Mu, Quanchen Zou, Wenxin Zhang, Xiangzheng Zhang, Yaoyuan Zhang, Zhekui Fan, Zhengmin Yu, Zonghao Ying, Zonglei Jing","submitted_at":"2025-09-08T05:45:37Z","abstract_excerpt":"Jailbreak attacks on Large Language Models (LLMs) have demonstrated various successful methods whereby attackers manipulate models into generating harmful responses that they are designed to avoid. Among these, Greedy Coordinate Gradient (GCG) has emerged as a general and effective approach that optimizes the tokens in a suffix to generate jailbreakable prompts. While several improved variants of GCG have been proposed, they all rely on fixed-length suffixes. However, the potential redundancy within these suffixes remains unexplored. In this work, we propose Mask-GCG, a plug-and-play method th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.06350","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.06350/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T01:04:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"KpN8gSggXoDfPHuJW+6PAb1R22ohrpdDc5KJGP0QXnakxo+kbyMqbl3NQlDarpaw0/q0/hbfIErZHd9HOjZrDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T17:28:53.916739Z"},"content_sha256":"1188020290d7ee7f0f049676ebc4dcacc7efd2650868a721159542bea5f64f15","schema_version":"1.0","event_id":"sha256:1188020290d7ee7f0f049676ebc4dcacc7efd2650868a721159542bea5f64f15"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/bundle.json","state_url":"https://pith.science/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T17:28:53Z","links":{"resolver":"https://pith.science/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN","bundle":"https://pith.science/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/bundle.json","state":"https://pith.science/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MQ35J3WXEG6FHEIRQSB3R6B3ZN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:MQ35J3WXEG6FHEIRQSB3R6B3ZN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"854c52928f607ff77ba13f7f7a2f21c961184888a52d3f81d62e71bccd68fa01","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-08T05:45:37Z","title_canon_sha256":"96c29a00a343e318aac18c6f7aed3f8462e7017bee056880bb6c14c619b5df6d"},"schema_version":"1.0","source":{"id":"2509.06350","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2509.06350","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"arxiv_version","alias_value":"2509.06350v2","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.06350","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_12","alias_value":"MQ35J3WXEG6F","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_16","alias_value":"MQ35J3WXEG6FHEIR","created_at":"2026-05-28T01:04:30Z"},{"alias_kind":"pith_short_8","alias_value":"MQ35J3WX","created_at":"2026-05-28T01:04:30Z"}],"graph_snapshots":[{"event_id":"sha256:1188020290d7ee7f0f049676ebc4dcacc7efd2650868a721159542bea5f64f15","target":"graph","created_at":"2026-05-28T01:04:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2509.06350/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Jailbreak attacks on Large Language Models (LLMs) have demonstrated various successful methods whereby attackers manipulate models into generating harmful responses that they are designed to avoid. Among these, Greedy Coordinate Gradient (GCG) has emerged as a general and effective approach that optimizes the tokens in a suffix to generate jailbreakable prompts. While several improved variants of GCG have been proposed, they all rely on fixed-length suffixes. However, the potential redundancy within these suffixes remains unexplored. In this work, we propose Mask-GCG, a plug-and-play method th","authors_text":"Junjie Mu, Quanchen Zou, Wenxin Zhang, Xiangzheng Zhang, Yaoyuan Zhang, Zhekui Fan, Zhengmin Yu, Zonghao Ying, Zonglei Jing","cross_cats":["cs.AI","cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-08T05:45:37Z","title":"Mask-GCG: Are All Tokens in Adversarial Suffixes Necessary for Jailbreak Attacks?"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.06350","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:08b404451138537e7b407f0ac1bd5d740501e38ac18525c45b8b4c85b34af094","target":"record","created_at":"2026-05-28T01:04:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"854c52928f607ff77ba13f7f7a2f21c961184888a52d3f81d62e71bccd68fa01","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-08T05:45:37Z","title_canon_sha256":"96c29a00a343e318aac18c6f7aed3f8462e7017bee056880bb6c14c619b5df6d"},"schema_version":"1.0","source":{"id":"2509.06350","kind":"arxiv","version":2}},"canonical_sha256":"6437d4eed721bc5391118483b8f83bcb78ee260e254c3d55f853f470beaf0a68","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6437d4eed721bc5391118483b8f83bcb78ee260e254c3d55f853f470beaf0a68","first_computed_at":"2026-05-28T01:04:30.307751Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T01:04:30.307751Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"4V5uEXD9O77To6MvRClG0yaANKhQ1bGw6ofdAR/XrPfZGYBHer/hJURvseJ9JjZd+feXcM89RbZdgWMjkq9oAw==","signature_status":"signed_v1","signed_at":"2026-05-28T01:04:30.308515Z","signed_message":"canonical_sha256_bytes"},"source_id":"2509.06350","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:08b404451138537e7b407f0ac1bd5d740501e38ac18525c45b8b4c85b34af094","sha256:1188020290d7ee7f0f049676ebc4dcacc7efd2650868a721159542bea5f64f15"],"state_sha256":"9cab9b81556abff4ee263c0959f085f1e2578547e292225399047cc15cc96bbe"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"czTADva2Q3Cp0d/us6+De/hvzKCtXmgGD8/ruzdJrFC39m2QVbUH0Df3dxrvBhw4Hp6XlQgqKfYZWNW9dPFhCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T17:28:53.921136Z","bundle_sha256":"550d24bb704d7eed12cc3a8a963e97927dcb54606db4c786ee2fb3b0c8d60666"}}