{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:S4V5RCC6YQMYUX76BZ3BD4ZXZD","short_pith_number":"pith:S4V5RCC6","schema_version":"1.0","canonical_sha256":"972bd8885ec4198a5ffe0e7611f337c8c667ca2011be7ad818065b39dea8a944","source":{"kind":"arxiv","id":"2402.16006","version":2},"attestation_state":"computed","paper":{"title":"ASETF: A Novel Method for Jailbreak Attack on LLMs through Translate Suffix Embeddings","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Hao Li, Hao Wang, Lei Sha, Minlie Huang","submitted_at":"2024-02-25T06:46:27Z","abstract_excerpt":"The safety defense methods of Large language models(LLMs) stays limited because the dangerous prompts are manually curated to just few known attack types, which fails to keep pace with emerging varieties. Recent studies found that attaching suffixes to harmful instructions can hack the defense of LLMs and lead to dangerous outputs. However, similar to traditional text adversarial attacks, this approach, while effective, is limited by the challenge of the discrete tokens. This gradient based discrete optimization attack requires over 100,000 LLM calls, and due to the unreadable of adversarial s"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.16006","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2024-02-25T06:46:27Z","cross_cats_sorted":[],"title_canon_sha256":"22523a29a9d486a856bdc572591aa5639c93719ce40dfa1264c91eb62567c0ef","abstract_canon_sha256":"dcf54c2b1bcfca59c1af36735fbf83fba9cdc89840d6985268b99a1ccce538b6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:27:04.648819Z","signature_b64":"b2mjRk/8VZQy3SN5MhuTEe2yM67a6dpg1riug9e/RAQCD7Be8suHc8lsDglSCvFzgRaZCFIyd5jzYGS/BBc3Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"972bd8885ec4198a5ffe0e7611f337c8c667ca2011be7ad818065b39dea8a944","last_reissued_at":"2026-07-05T08:27:04.648342Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:27:04.648342Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ASETF: A Novel Method for Jailbreak Attack on LLMs through Translate Suffix Embeddings","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Hao Li, Hao Wang, Lei Sha, Minlie Huang","submitted_at":"2024-02-25T06:46:27Z","abstract_excerpt":"The safety defense methods of Large language models(LLMs) stays limited because the dangerous prompts are manually curated to just few known attack types, which fails to keep pace with emerging varieties. Recent studies found that attaching suffixes to harmful instructions can hack the defense of LLMs and lead to dangerous outputs. However, similar to traditional text adversarial attacks, this approach, while effective, is limited by the challenge of the discrete tokens. This gradient based discrete optimization attack requires over 100,000 LLM calls, and due to the unreadable of adversarial s"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.16006","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.16006/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.16006","created_at":"2026-07-05T08:27:04.648398+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.16006v2","created_at":"2026-07-05T08:27:04.648398+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.16006","created_at":"2026-07-05T08:27:04.648398+00:00"},{"alias_kind":"pith_short_12","alias_value":"S4V5RCC6YQMY","created_at":"2026-07-05T08:27:04.648398+00:00"},{"alias_kind":"pith_short_16","alias_value":"S4V5RCC6YQMYUX76","created_at":"2026-07-05T08:27:04.648398+00:00"},{"alias_kind":"pith_short_8","alias_value":"S4V5RCC6","created_at":"2026-07-05T08:27:04.648398+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2407.04295","citing_title":"Jailbreak Attacks and Defenses Against Large Language Models: A Survey","ref_index":93,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12813","citing_title":"REALISTA: Realistic Latent Adversarial Attacks that Elicit LLM Hallucinations","ref_index":184,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD","json":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD.json","graph_json":"https://pith.science/api/pith-number/S4V5RCC6YQMYUX76BZ3BD4ZXZD/graph.json","events_json":"https://pith.science/api/pith-number/S4V5RCC6YQMYUX76BZ3BD4ZXZD/events.json","paper":"https://pith.science/paper/S4V5RCC6"},"agent_actions":{"view_html":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD","download_json":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD.json","view_paper":"https://pith.science/paper/S4V5RCC6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.16006&json=true","fetch_graph":"https://pith.science/api/pith-number/S4V5RCC6YQMYUX76BZ3BD4ZXZD/graph.json","fetch_events":"https://pith.science/api/pith-number/S4V5RCC6YQMYUX76BZ3BD4ZXZD/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD/action/timestamp_anchor","attest_storage":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD/action/storage_attestation","attest_author":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD/action/author_attestation","sign_citation":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD/action/citation_signature","submit_replication":"https://pith.science/pith/S4V5RCC6YQMYUX76BZ3BD4ZXZD/action/replication_record"}},"created_at":"2026-07-05T08:27:04.648398+00:00","updated_at":"2026-07-05T08:27:04.648398+00:00"}