{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2023:P2T42GVWWJOHQJJAWSC3TWPDMC","short_pith_number":"pith:P2T42GVW","canonical_record":{"source":{"id":"2305.13860","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-05-23T09:33:38Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"67ebef0ec3638c8906e0b8c2aec6b55a6889eace3355560ae24ca2a601f93717","abstract_canon_sha256":"5439c127d3c241f075a3a9d933a6d16876d187513c9bfe344027f677c6311ccf"},"schema_version":"1.0"},"canonical_sha256":"7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f","source":{"kind":"arxiv","id":"2305.13860","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2305.13860","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"arxiv_version","alias_value":"2305.13860v2","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.13860","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"pith_short_12","alias_value":"P2T42GVWWJOH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"P2T42GVWWJOHQJJA","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"P2T42GVW","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2023:P2T42GVWWJOHQJJAWSC3TWPDMC","target":"record","payload":{"canonical_record":{"source":{"id":"2305.13860","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-05-23T09:33:38Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"67ebef0ec3638c8906e0b8c2aec6b55a6889eace3355560ae24ca2a601f93717","abstract_canon_sha256":"5439c127d3c241f075a3a9d933a6d16876d187513c9bfe344027f677c6311ccf"},"schema_version":"1.0"},"canonical_sha256":"7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:38:46.358980Z","signature_b64":"wxvFGOYFKSBF8Wrfl3tcT37e8psrKmmfVH/ogPN1vKJ8Z2nRSxWrzvYYtpCSCDGsP3rEzwq92A7CEeVeDIpzAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f","last_reissued_at":"2026-05-17T23:38:46.358544Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:38:46.358544Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2305.13860","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iSknMRO9WN3tF8X4NIIWgii6bqJIfskp6NAbc0/MRmSsxgJUaZdSocYEPedYH2p4lZOArroh+fdShWphZlwNAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T08:20:03.035393Z"},"content_sha256":"b21df61c14c8713929aaa5d3c25bd857360284f6fa2bfc3244cb30771fb3e424","schema_version":"1.0","event_id":"sha256:b21df61c14c8713929aaa5d3c25bd857360284f6fa2bfc3244cb30771fb3e424"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2023:P2T42GVWWJOHQJJAWSC3TWPDMC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios.","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.SE","authors_text":"Gelei Deng, Kailong Wang, Lida Zhao, Tianwei Zhang, Yang Liu, Yaowen Zheng, Yi Liu, Ying Zhang, Yuekang Li, Zhengzi Xu","submitted_at":"2023-05-23T09:33:38Z","abstract_excerpt":"Large Language Models (LLMs), like ChatGPT, have demonstrated vast potential but also introduce challenges related to content constraints and potential misuse. Our study investigates three key research questions: (1) the number of different prompt types that can jailbreak LLMs, (2) the effectiveness of jailbreak prompts in circumventing LLM constraints, and (3) the resilience of ChatGPT against these jailbreak prompts. Initially, we develop a classification model to analyze the distribution of existing prompts, identifying ten distinct patterns and three categories of jailbreak prompts. Subseq"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"The prompts can consistently evade the restrictions in 40 use-case scenarios.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the chosen 3,120 questions and 40 use-case scenarios are representative of real jailbreak attempts and that the ten-pattern classification captures the space of effective prompts without major omissions.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Jailbreak prompts grouped into ten patterns and three categories successfully evade ChatGPT restrictions across 40 scenarios using 3,120 test questions.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"3bebcd9ce6dc1ad32d4e3f6661526df906304b9e15e6fd9ad2be998cb3666606"},"source":{"id":"2305.13860","kind":"arxiv","version":2},"verdict":{"id":"e422244e-6db7-43d5-8bfd-e75ac62a6de6","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-16T22:33:57.809333Z","strongest_claim":"The prompts can consistently evade the restrictions in 40 use-case scenarios.","one_line_summary":"Jailbreak prompts grouped into ten patterns and three categories successfully evade ChatGPT restrictions across 40 scenarios using 3,120 test questions.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the chosen 3,120 questions and 40 use-case scenarios are representative of real jailbreak attempts and that the ten-pattern classification captures the space of effective prompts without major omissions.","pith_extraction_headline":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios."},"references":{"count":26,"sample":[{"doi":"","year":null,"title":"Prompting large language model for machine translation: A case study,","work_id":"d5f3e1fc-3b4f-4bd2-8795-710d807a8a05","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.48550/arxiv.2301.07069","year":null,"title":"Prompting large language model for machine translation: A case study,","work_id":"d5f3e1fc-3b4f-4bd2-8795-710d807a8a05","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.48550/arxiv.2303.11717","year":2023,"title":"A complete survey on generative ai (aigc): Is chatgpt from gpt-4 to gpt-5 all you need?","work_id":"8f840fe7-abbc-4ce1-98c3-c7ddfcbc7d49","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"10.1007/s10462-022-10248-8","year":2023,"title":"Recent advances in deep learning based dialogue systems: a systematic survey,","work_id":"117d0a04-c628-40c0-93a6-8316c4be1f9e","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"“New chat,” https://chat .openai.com/, (Accessed on 02/02/2023)","work_id":"a8a006c8-5c95-4d3d-9ea9-b738970dfe34","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":26,"snapshot_sha256":"b4e1a01f45111fdf92863e0d704dea7dca2b3a673dd22ad8fb1c12bce655229f","internal_anchors":0},"formal_canon":{"evidence_count":1,"snapshot_sha256":"6f9d3c20b5d9fa78bc1690980bc53422f4ac5d0dfc749c179ba6c51a0474e65f"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"e422244e-6db7-43d5-8bfd-e75ac62a6de6"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"TkT7y6kqa0R9GOj8a/626O2RGMOhAIurN+qZ+XAEwAXxMGSsAtM5bVSbBI12y7gUcu2oVMGzqU6IOdDutG8yCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T08:20:03.036498Z"},"content_sha256":"98a0c0d5f13fa9d8a6eaa238bd6c25abbcbdf3d68e080f98336e98162588c273","schema_version":"1.0","event_id":"sha256:98a0c0d5f13fa9d8a6eaa238bd6c25abbcbdf3d68e080f98336e98162588c273"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/bundle.json","state_url":"https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T08:20:03Z","links":{"resolver":"https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC","bundle":"https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/bundle.json","state":"https://pith.science/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/P2T42GVWWJOHQJJAWSC3TWPDMC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2023:P2T42GVWWJOHQJJAWSC3TWPDMC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"5439c127d3c241f075a3a9d933a6d16876d187513c9bfe344027f677c6311ccf","cross_cats_sorted":["cs.AI","cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-05-23T09:33:38Z","title_canon_sha256":"67ebef0ec3638c8906e0b8c2aec6b55a6889eace3355560ae24ca2a601f93717"},"schema_version":"1.0","source":{"id":"2305.13860","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2305.13860","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"arxiv_version","alias_value":"2305.13860v2","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.13860","created_at":"2026-05-17T23:38:46Z"},{"alias_kind":"pith_short_12","alias_value":"P2T42GVWWJOH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"P2T42GVWWJOHQJJA","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"P2T42GVW","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:98a0c0d5f13fa9d8a6eaa238bd6c25abbcbdf3d68e080f98336e98162588c273","target":"graph","created_at":"2026-05-17T23:38:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"The prompts can consistently evade the restrictions in 40 use-case scenarios."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the chosen 3,120 questions and 40 use-case scenarios are representative of real jailbreak attempts and that the ten-pattern classification captures the space of effective prompts without major omissions."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Jailbreak prompts grouped into ten patterns and three categories successfully evade ChatGPT restrictions across 40 scenarios using 3,120 test questions."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios."}],"snapshot_sha256":"3bebcd9ce6dc1ad32d4e3f6661526df906304b9e15e6fd9ad2be998cb3666606"},"formal_canon":{"evidence_count":1,"snapshot_sha256":"6f9d3c20b5d9fa78bc1690980bc53422f4ac5d0dfc749c179ba6c51a0474e65f"},"paper":{"abstract_excerpt":"Large Language Models (LLMs), like ChatGPT, have demonstrated vast potential but also introduce challenges related to content constraints and potential misuse. Our study investigates three key research questions: (1) the number of different prompt types that can jailbreak LLMs, (2) the effectiveness of jailbreak prompts in circumventing LLM constraints, and (3) the resilience of ChatGPT against these jailbreak prompts. Initially, we develop a classification model to analyze the distribution of existing prompts, identifying ten distinct patterns and three categories of jailbreak prompts. Subseq","authors_text":"Gelei Deng, Kailong Wang, Lida Zhao, Tianwei Zhang, Yang Liu, Yaowen Zheng, Yi Liu, Ying Zhang, Yuekang Li, Zhengzi Xu","cross_cats":["cs.AI","cs.CL"],"headline":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-05-23T09:33:38Z","title":"Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study"},"references":{"count":26,"internal_anchors":0,"resolved_work":26,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Prompting large language model for machine translation: A case study,","work_id":"d5f3e1fc-3b4f-4bd2-8795-710d807a8a05","year":null},{"cited_arxiv_id":"","doi":"10.48550/arxiv.2301.07069","is_internal_anchor":false,"ref_index":2,"title":"Prompting large language model for machine translation: A case study,","work_id":"d5f3e1fc-3b4f-4bd2-8795-710d807a8a05","year":null},{"cited_arxiv_id":"","doi":"10.48550/arxiv.2303.11717","is_internal_anchor":false,"ref_index":3,"title":"A complete survey on generative ai (aigc): Is chatgpt from gpt-4 to gpt-5 all you need?","work_id":"8f840fe7-abbc-4ce1-98c3-c7ddfcbc7d49","year":2023},{"cited_arxiv_id":"","doi":"10.1007/s10462-022-10248-8","is_internal_anchor":false,"ref_index":4,"title":"Recent advances in deep learning based dialogue systems: a systematic survey,","work_id":"117d0a04-c628-40c0-93a6-8316c4be1f9e","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"“New chat,” https://chat .openai.com/, (Accessed on 02/02/2023)","work_id":"a8a006c8-5c95-4d3d-9ea9-b738970dfe34","year":2023}],"snapshot_sha256":"b4e1a01f45111fdf92863e0d704dea7dca2b3a673dd22ad8fb1c12bce655229f"},"source":{"id":"2305.13860","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-16T22:33:57.809333Z","id":"e422244e-6db7-43d5-8bfd-e75ac62a6de6","model_set":{"reader":"grok-4.3"},"one_line_summary":"Jailbreak prompts grouped into ten patterns and three categories successfully evade ChatGPT restrictions across 40 scenarios using 3,120 test questions.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Jailbreak prompts classified into ten patterns can consistently evade ChatGPT's content restrictions in 40 use-case scenarios.","strongest_claim":"The prompts can consistently evade the restrictions in 40 use-case scenarios.","weakest_assumption":"That the chosen 3,120 questions and 40 use-case scenarios are representative of real jailbreak attempts and that the ten-pattern classification captures the space of effective prompts without major omissions."}},"verdict_id":"e422244e-6db7-43d5-8bfd-e75ac62a6de6"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b21df61c14c8713929aaa5d3c25bd857360284f6fa2bfc3244cb30771fb3e424","target":"record","created_at":"2026-05-17T23:38:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"5439c127d3c241f075a3a9d933a6d16876d187513c9bfe344027f677c6311ccf","cross_cats_sorted":["cs.AI","cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-05-23T09:33:38Z","title_canon_sha256":"67ebef0ec3638c8906e0b8c2aec6b55a6889eace3355560ae24ca2a601f93717"},"schema_version":"1.0","source":{"id":"2305.13860","kind":"arxiv","version":2}},"canonical_sha256":"7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7ea7cd1ab6b25c782520b485b9d9e360b016990f4de50040de30ebdb337f5c9f","first_computed_at":"2026-05-17T23:38:46.358544Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:38:46.358544Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"wxvFGOYFKSBF8Wrfl3tcT37e8psrKmmfVH/ogPN1vKJ8Z2nRSxWrzvYYtpCSCDGsP3rEzwq92A7CEeVeDIpzAA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:38:46.358980Z","signed_message":"canonical_sha256_bytes"},"source_id":"2305.13860","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b21df61c14c8713929aaa5d3c25bd857360284f6fa2bfc3244cb30771fb3e424","sha256:98a0c0d5f13fa9d8a6eaa238bd6c25abbcbdf3d68e080f98336e98162588c273"],"state_sha256":"0b640e17def89ce5eeb3dab231a1ed8c089c98ca0d81c1b34052076f204f04b8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"bs3bPv5BH0T8KGfX+itIogV/DgMlx1e2d+kzlhFYdGf3t8MABWu1r4NEUAl5867u34HPPhi1Yginx7r52CC8Cg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T08:20:03.041072Z","bundle_sha256":"aa2230cd02d564955108529a83f233485b9a851369d76fd6d49f88c7d90d6add"}}