{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:TP7XXTNH77RZRYWD3SC64FQVVM","short_pith_number":"pith:TP7XXTNH","schema_version":"1.0","canonical_sha256":"9bff7bcda7ffe398e2c3dc85ee1615ab1834bee9c089bdc3f9ba05e39d90783d","source":{"kind":"arxiv","id":"2502.18504","version":2},"attestation_state":"computed","paper":{"title":"TurboFuzzLLM: Turbocharging Mutation-based Fuzzing for Effectively Jailbreaking Large Language Models in Practice","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Aman Goel, Dmitriy Bespalov, Xian Carrie Wu, Yanjun Qi, Zhe Wang","submitted_at":"2025-02-21T21:10:12Z","abstract_excerpt":"Jailbreaking large-language models (LLMs) involves testing their robustness against adversarial prompts and evaluating their ability to withstand prompt attacks that could elicit unauthorized or malicious responses. In this paper, we present TurboFuzzLLM, a mutation-based fuzzing technique for efficiently finding a collection of effective jailbreaking templates that, when combined with harmful questions, can lead a target LLM to produce harmful responses through black-box access via user prompts. We describe the limitations of directly applying existing template-based attacking techniques in p"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.18504","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-02-21T21:10:12Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"93ea2743cec3ebf9b0142c18dc7612d44e774e43e10053e2b8e50878281e67c7","abstract_canon_sha256":"13b5488c0340e723ff8554be3bd1e02ff69b0c89d454984f1ffdefb0a405fff4"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:16:06.504009Z","signature_b64":"wzWK4bh2O8zb+OdyNsdCRmjBrgxo8iBSAnhPgTCzP3xRtPzaWh9h7MEe8qY774WrbyN5s4eBDiN2Uh7iWTdKBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9bff7bcda7ffe398e2c3dc85ee1615ab1834bee9c089bdc3f9ba05e39d90783d","last_reissued_at":"2026-07-05T11:16:06.503441Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:16:06.503441Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TurboFuzzLLM: Turbocharging Mutation-based Fuzzing for Effectively Jailbreaking Large Language Models in Practice","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Aman Goel, Dmitriy Bespalov, Xian Carrie Wu, Yanjun Qi, Zhe Wang","submitted_at":"2025-02-21T21:10:12Z","abstract_excerpt":"Jailbreaking large-language models (LLMs) involves testing their robustness against adversarial prompts and evaluating their ability to withstand prompt attacks that could elicit unauthorized or malicious responses. In this paper, we present TurboFuzzLLM, a mutation-based fuzzing technique for efficiently finding a collection of effective jailbreaking templates that, when combined with harmful questions, can lead a target LLM to produce harmful responses through black-box access via user prompts. We describe the limitations of directly applying existing template-based attacking techniques in p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.18504","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.18504/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.18504","created_at":"2026-07-05T11:16:06.503514+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.18504v2","created_at":"2026-07-05T11:16:06.503514+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.18504","created_at":"2026-07-05T11:16:06.503514+00:00"},{"alias_kind":"pith_short_12","alias_value":"TP7XXTNH77RZ","created_at":"2026-07-05T11:16:06.503514+00:00"},{"alias_kind":"pith_short_16","alias_value":"TP7XXTNH77RZRYWD","created_at":"2026-07-05T11:16:06.503514+00:00"},{"alias_kind":"pith_short_8","alias_value":"TP7XXTNH","created_at":"2026-07-05T11:16:06.503514+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2511.02356","citing_title":"ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12232","citing_title":"TEMPLATEFUZZ: Fine-Grained Chat Template Fuzzing for Jailbreaking and Red Teaming LLMs","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM","json":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM.json","graph_json":"https://pith.science/api/pith-number/TP7XXTNH77RZRYWD3SC64FQVVM/graph.json","events_json":"https://pith.science/api/pith-number/TP7XXTNH77RZRYWD3SC64FQVVM/events.json","paper":"https://pith.science/paper/TP7XXTNH"},"agent_actions":{"view_html":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM","download_json":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM.json","view_paper":"https://pith.science/paper/TP7XXTNH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.18504&json=true","fetch_graph":"https://pith.science/api/pith-number/TP7XXTNH77RZRYWD3SC64FQVVM/graph.json","fetch_events":"https://pith.science/api/pith-number/TP7XXTNH77RZRYWD3SC64FQVVM/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM/action/storage_attestation","attest_author":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM/action/author_attestation","sign_citation":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM/action/citation_signature","submit_replication":"https://pith.science/pith/TP7XXTNH77RZRYWD3SC64FQVVM/action/replication_record"}},"created_at":"2026-07-05T11:16:06.503514+00:00","updated_at":"2026-07-05T11:16:06.503514+00:00"}