{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:QOO2U2KAVXWL3ZNCRG3OJQVSZV","short_pith_number":"pith:QOO2U2KA","schema_version":"1.0","canonical_sha256":"839daa6940adecbde5a289b6e4c2b2cd4de91249926ee5bf862cda6c65530f22","source":{"kind":"arxiv","id":"2505.17598","version":1},"attestation_state":"computed","paper":{"title":"One Model Transfer to All: On Robust Jailbreak Prompts Generation against LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Daojing He, Linbao Li, Yannan Liu, Yu Li","submitted_at":"2025-05-23T08:02:38Z","abstract_excerpt":"Safety alignment in large language models (LLMs) is increasingly compromised by jailbreak attacks, which can manipulate these models to generate harmful or unintended content. Investigating these attacks is crucial for uncovering model vulnerabilities. However, many existing jailbreak strategies fail to keep pace with the rapid development of defense mechanisms, such as defensive suffixes, rendering them ineffective against defended models. To tackle this issue, we introduce a novel attack method called ArrAttack, specifically designed to target defended LLMs. ArrAttack automatically generates"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.17598","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-05-23T08:02:38Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"02eb21a9ff6f974ff1176f5f321473944fccb1c3294462ee4ef0846f23542673","abstract_canon_sha256":"ee489f9d240413a69fc139cc04a251e1247854347641a5e71efe41eb3e62cd2b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:08:28.769200Z","signature_b64":"vOv1jAryUS7o2m9EipwoE84GXx9vjRX7KfIrXboeJCwwZzquachjc5i8HYlHpYJ77qdKpPnoZs2NBvVozxQFBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"839daa6940adecbde5a289b6e4c2b2cd4de91249926ee5bf862cda6c65530f22","last_reissued_at":"2026-07-05T11:08:28.768701Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:08:28.768701Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"One Model Transfer to All: On Robust Jailbreak Prompts Generation against LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Daojing He, Linbao Li, Yannan Liu, Yu Li","submitted_at":"2025-05-23T08:02:38Z","abstract_excerpt":"Safety alignment in large language models (LLMs) is increasingly compromised by jailbreak attacks, which can manipulate these models to generate harmful or unintended content. Investigating these attacks is crucial for uncovering model vulnerabilities. However, many existing jailbreak strategies fail to keep pace with the rapid development of defense mechanisms, such as defensive suffixes, rendering them ineffective against defended models. To tackle this issue, we introduce a novel attack method called ArrAttack, specifically designed to target defended LLMs. ArrAttack automatically generates"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.17598","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.17598/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.17598","created_at":"2026-07-05T11:08:28.768761+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.17598v1","created_at":"2026-07-05T11:08:28.768761+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.17598","created_at":"2026-07-05T11:08:28.768761+00:00"},{"alias_kind":"pith_short_12","alias_value":"QOO2U2KAVXWL","created_at":"2026-07-05T11:08:28.768761+00:00"},{"alias_kind":"pith_short_16","alias_value":"QOO2U2KAVXWL3ZNC","created_at":"2026-07-05T11:08:28.768761+00:00"},{"alias_kind":"pith_short_8","alias_value":"QOO2U2KA","created_at":"2026-07-05T11:08:28.768761+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.03647","citing_title":"Black-box, Adaptive, Efficient, Transferable, Harmful, Applicable... Attacks Are All You Need to Break LLMs","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2604.10326","citing_title":"Jailbreaking the Matrix: Nullspace Steering for Controlled Model Subversion","ref_index":20,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV","json":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV.json","graph_json":"https://pith.science/api/pith-number/QOO2U2KAVXWL3ZNCRG3OJQVSZV/graph.json","events_json":"https://pith.science/api/pith-number/QOO2U2KAVXWL3ZNCRG3OJQVSZV/events.json","paper":"https://pith.science/paper/QOO2U2KA"},"agent_actions":{"view_html":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV","download_json":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV.json","view_paper":"https://pith.science/paper/QOO2U2KA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.17598&json=true","fetch_graph":"https://pith.science/api/pith-number/QOO2U2KAVXWL3ZNCRG3OJQVSZV/graph.json","fetch_events":"https://pith.science/api/pith-number/QOO2U2KAVXWL3ZNCRG3OJQVSZV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV/action/storage_attestation","attest_author":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV/action/author_attestation","sign_citation":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV/action/citation_signature","submit_replication":"https://pith.science/pith/QOO2U2KAVXWL3ZNCRG3OJQVSZV/action/replication_record"}},"created_at":"2026-07-05T11:08:28.768761+00:00","updated_at":"2026-07-05T11:08:28.768761+00:00"}