pith. sign in
Pith Number

pith:P2T42GVW

pith:2023:P2T42GVWWJOHQJJAWSC3TWPDMC
not attested not anchored not stored refs resolved

Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Gelei Deng, Kailong Wang, Lida Zhao, Tianwei Zhang, Yang Liu, Yaowen Zheng, Yi Liu, Ying Zhang, Yuekang Li, Zhengzi Xu

Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios.

arxiv:2305.13860 v2 · 2023-05-23 · cs.SE · cs.AI · cs.CL

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{P2T42GVWWJOHQJJAWSC3TWPDMC}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

The prompts can consistently evade the restrictions in 40 use-case scenarios.

C2weakest assumption

That the chosen 3,120 questions and 40 use-case scenarios are representative of real jailbreak attempts and that the ten-pattern classification captures the space of effective prompts without major omissions.

C3one line summary

Jailbreak prompts grouped into ten patterns and three categories successfully evade ChatGPT restrictions across 40 scenarios using 3,120 test questions.

References

26 extracted · 26 resolved · 0 Pith anchors

[1] Prompting large language model for machine translation: A case study,
[2] Prompting large language model for machine translation: A case study, · doi:10.48550/arxiv.2301.07069
[3] A complete survey on generative ai (aigc): Is chatgpt from gpt-4 to gpt-5 all you need? 2023 · doi:10.48550/arxiv.2303.11717
[4] Recent advances in deep learning based dialogue systems: a systematic survey, 2023 · doi:10.1007/s10462-022-10248-8
[5] “New chat,” https://chat .openai.com/, (Accessed on 02/02/2023) 2023

Formal links

1 machine-checked theorem link

Cited by

35 papers in Pith

Receipt and verification
First computed 2026-05-17T23:38:46.358544Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f

Aliases

arxiv: 2305.13860 · arxiv_version: 2305.13860v2 · doi: 10.48550/arxiv.2305.13860 · pith_short_12: P2T42GVWWJOH · pith_short_16: P2T42GVWWJOHQJJA · pith_short_8: P2T42GVW
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "5439c127d3c241f075a3a9d933a6d16876d187513c9bfe344027f677c6311ccf",
    "cross_cats_sorted": [
      "cs.AI",
      "cs.CL"
    ],
    "license": "http://creativecommons.org/licenses/by/4.0/",
    "primary_cat": "cs.SE",
    "submitted_at": "2023-05-23T09:33:38Z",
    "title_canon_sha256": "67ebef0ec3638c8906e0b8c2aec6b55a6889eace3355560ae24ca2a601f93717"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2305.13860",
    "kind": "arxiv",
    "version": 2
  }
}