{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:QPUQBPMVDU763T7TO7UNBFJT2W","short_pith_number":"pith:QPUQBPMV","schema_version":"1.0","canonical_sha256":"83e900bd951d3fedcff377e8d09533d59018943f51359c186a25703fa79c1bca","source":{"kind":"arxiv","id":"2501.16497","version":1},"attestation_state":"computed","paper":{"title":"Smoothed Embeddings for Robust Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ashley Lewis, Jing Liu, Kieran Parsons, Md Rafi Ur Rashid, Ryo Hase, Toshiaki Koike-Akino, Ye Wang","submitted_at":"2025-01-27T20:57:26Z","abstract_excerpt":"Improving the safety and reliability of large language models (LLMs) is a crucial aspect of realizing trustworthy AI systems. Although alignment methods aim to suppress harmful content generation, LLMs are often still vulnerable to jailbreaking attacks that employ adversarial inputs that subvert alignment and induce harmful outputs. We propose the Randomized Embedding Smoothing and Token Aggregation (RESTA) defense, which adds random noise to the embedding vectors and performs aggregation during the generation of each output token, with the aim of better preserving semantic information. Our ex"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2501.16497","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2025-01-27T20:57:26Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CR","stat.ML"],"title_canon_sha256":"78ee3f57af9d380da50c92c2346e3660b526c2cdacee607c5ed8ac4079b0f355","abstract_canon_sha256":"cc3778de410e4dbad55cf8b45ad613d3745efbe76c7a0151814b8231d7427563"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:06:14.143906Z","signature_b64":"RAJpIM8Th1pTKd53eCzdTAuffei4mLk13T8fhb9s3R59J8VUQWcMD8/vAMKeFhIPe0rRMepflcl2NFLkTS12Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"83e900bd951d3fedcff377e8d09533d59018943f51359c186a25703fa79c1bca","last_reissued_at":"2026-07-05T10:06:14.143330Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:06:14.143330Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Smoothed Embeddings for Robust Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ashley Lewis, Jing Liu, Kieran Parsons, Md Rafi Ur Rashid, Ryo Hase, Toshiaki Koike-Akino, Ye Wang","submitted_at":"2025-01-27T20:57:26Z","abstract_excerpt":"Improving the safety and reliability of large language models (LLMs) is a crucial aspect of realizing trustworthy AI systems. Although alignment methods aim to suppress harmful content generation, LLMs are often still vulnerable to jailbreaking attacks that employ adversarial inputs that subvert alignment and induce harmful outputs. We propose the Randomized Embedding Smoothing and Token Aggregation (RESTA) defense, which adds random noise to the embedding vectors and performs aggregation during the generation of each output token, with the aim of better preserving semantic information. Our ex"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2501.16497","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2501.16497/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2501.16497","created_at":"2026-07-05T10:06:14.143399+00:00"},{"alias_kind":"arxiv_version","alias_value":"2501.16497v1","created_at":"2026-07-05T10:06:14.143399+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2501.16497","created_at":"2026-07-05T10:06:14.143399+00:00"},{"alias_kind":"pith_short_12","alias_value":"QPUQBPMVDU76","created_at":"2026-07-05T10:06:14.143399+00:00"},{"alias_kind":"pith_short_16","alias_value":"QPUQBPMVDU763T7T","created_at":"2026-07-05T10:06:14.143399+00:00"},{"alias_kind":"pith_short_8","alias_value":"QPUQBPMV","created_at":"2026-07-05T10:06:14.143399+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.04717","citing_title":"Auditing CoT Answer-Hijack Patches: Source-Control Certificates with Type-I Guarantees","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10611","citing_title":"Re-Triggering Safeguards within LLMs for Jailbreak Detection","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2604.18756","citing_title":"Towards Understanding the Robustness of Sparse Autoencoders","ref_index":28,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W","json":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W.json","graph_json":"https://pith.science/api/pith-number/QPUQBPMVDU763T7TO7UNBFJT2W/graph.json","events_json":"https://pith.science/api/pith-number/QPUQBPMVDU763T7TO7UNBFJT2W/events.json","paper":"https://pith.science/paper/QPUQBPMV"},"agent_actions":{"view_html":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W","download_json":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W.json","view_paper":"https://pith.science/paper/QPUQBPMV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2501.16497&json=true","fetch_graph":"https://pith.science/api/pith-number/QPUQBPMVDU763T7TO7UNBFJT2W/graph.json","fetch_events":"https://pith.science/api/pith-number/QPUQBPMVDU763T7TO7UNBFJT2W/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W/action/storage_attestation","attest_author":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W/action/author_attestation","sign_citation":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W/action/citation_signature","submit_replication":"https://pith.science/pith/QPUQBPMVDU763T7TO7UNBFJT2W/action/replication_record"}},"created_at":"2026-07-05T10:06:14.143399+00:00","updated_at":"2026-07-05T10:06:14.143399+00:00"}