{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:PJCI3UBBMYHAHBI5VFSJ2VVP7V","short_pith_number":"pith:PJCI3UBB","schema_version":"1.0","canonical_sha256":"7a448dd021660e03851da9649d56affd596a815ba2324c2ef31985144627caf2","source":{"kind":"arxiv","id":"2510.02999","version":5},"attestation_state":"computed","paper":{"title":"NonTextual Target Attack","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Di Wang, Hongsheng Hu, KeDong Xiu, Kui Ren, Tianhang Zheng, Wenjing Hu, Xiaojun Jia, Xinzhe Huang, Zhan Qin","submitted_at":"2025-10-03T13:38:56Z","abstract_excerpt":"Existing gradient-based jailbreak attacks on Large Language Models (LLMs) typically optimize adversarial suffixes to align the LLM output with predefined target responses. However, restricting the objective as inducing fixed targets inherently constrains the adversarial search space, limiting the overall attack efficacy. Furthermore, existing methods typically require numerous optimization iterations to fulfill the large gap between the fixed target and the original LLM output, resulting in low attack efficiency. To overcome these limitations, we propose NonTextual Target Attack (NTA), the fir"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2510.02999","kind":"arxiv","version":5},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-03T13:38:56Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"4437114b5056b56eb902eb6ba7fcf796f15c94b75354586ead893caeb204c309","abstract_canon_sha256":"915e0551d05bd58447b93ad8690201b87cb777c444179801f9bbee356cc28f00"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-09T00:19:36.156134Z","signature_b64":"i+KkvzPeQ5wVvj54r5oCPH/nw3143T9T+AbIZvdsZKD5ePEJUUydiQbA0Uil7ircLmUYGEy2NXIwfeesxAonBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7a448dd021660e03851da9649d56affd596a815ba2324c2ef31985144627caf2","last_reissued_at":"2026-07-09T00:19:36.155702Z","signature_status":"signed_v1","first_computed_at":"2026-07-09T00:19:36.155702Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"NonTextual Target Attack","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Di Wang, Hongsheng Hu, KeDong Xiu, Kui Ren, Tianhang Zheng, Wenjing Hu, Xiaojun Jia, Xinzhe Huang, Zhan Qin","submitted_at":"2025-10-03T13:38:56Z","abstract_excerpt":"Existing gradient-based jailbreak attacks on Large Language Models (LLMs) typically optimize adversarial suffixes to align the LLM output with predefined target responses. However, restricting the objective as inducing fixed targets inherently constrains the adversarial search space, limiting the overall attack efficacy. Furthermore, existing methods typically require numerous optimization iterations to fulfill the large gap between the fixed target and the original LLM output, resulting in low attack efficiency. To overcome these limitations, we propose NonTextual Target Attack (NTA), the fir"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.02999","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2510.02999/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2510.02999","created_at":"2026-07-09T00:19:36.155764+00:00"},{"alias_kind":"arxiv_version","alias_value":"2510.02999v5","created_at":"2026-07-09T00:19:36.155764+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.02999","created_at":"2026-07-09T00:19:36.155764+00:00"},{"alias_kind":"pith_short_12","alias_value":"PJCI3UBBMYHA","created_at":"2026-07-09T00:19:36.155764+00:00"},{"alias_kind":"pith_short_16","alias_value":"PJCI3UBBMYHAHBI5","created_at":"2026-07-09T00:19:36.155764+00:00"},{"alias_kind":"pith_short_8","alias_value":"PJCI3UBB","created_at":"2026-07-09T00:19:36.155764+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":3,"sample":[{"citing_arxiv_id":"2605.10764","citing_title":"Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization","ref_index":10,"is_internal_anchor":true},{"citing_arxiv_id":"2605.24817","citing_title":"RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry","ref_index":11,"is_internal_anchor":true},{"citing_arxiv_id":"2605.10764","citing_title":"Break the Brake, Not the Wheel: Untargeted Jailbreak via Entropy Maximization","ref_index":10,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V","json":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V.json","graph_json":"https://pith.science/api/pith-number/PJCI3UBBMYHAHBI5VFSJ2VVP7V/graph.json","events_json":"https://pith.science/api/pith-number/PJCI3UBBMYHAHBI5VFSJ2VVP7V/events.json","paper":"https://pith.science/paper/PJCI3UBB"},"agent_actions":{"view_html":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V","download_json":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V.json","view_paper":"https://pith.science/paper/PJCI3UBB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2510.02999&json=true","fetch_graph":"https://pith.science/api/pith-number/PJCI3UBBMYHAHBI5VFSJ2VVP7V/graph.json","fetch_events":"https://pith.science/api/pith-number/PJCI3UBBMYHAHBI5VFSJ2VVP7V/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V/action/storage_attestation","attest_author":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V/action/author_attestation","sign_citation":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V/action/citation_signature","submit_replication":"https://pith.science/pith/PJCI3UBBMYHAHBI5VFSJ2VVP7V/action/replication_record"}},"created_at":"2026-07-09T00:19:36.155764+00:00","updated_at":"2026-07-09T00:19:36.155764+00:00"}