{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:VPMIRXT4LOF3ZCVVIXHAOXMDSZ","short_pith_number":"pith:VPMIRXT4","schema_version":"1.0","canonical_sha256":"abd888de7c5b8bbc8ab545ce075d8396450a152e53a2008141577c8e9cbda431","source":{"kind":"arxiv","id":"2404.02637","version":2},"attestation_state":"computed","paper":{"title":"Vocabulary Attack to Hijack Large Language Model Applications","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.DC"],"primary_cat":"cs.CR","authors_text":"Christoph P. Neumann, Patrick Levi","submitted_at":"2024-04-03T10:54:07Z","abstract_excerpt":"The fast advancements in Large Language Models (LLMs) are driving an increasing number of applications. Together with the growing number of users, we also see an increasing number of attackers who try to outsmart these systems. They want the model to reveal confidential information, specific false information, or offensive behavior. To this end, they manipulate their instructions for the LLM by inserting separators or rephrasing them systematically until they reach their goal. Our approach is different. It inserts words from the model vocabulary. We find these words using an optimization proce"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2404.02637","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-04-03T10:54:07Z","cross_cats_sorted":["cs.AI","cs.DC"],"title_canon_sha256":"db9daf6836f5997bb8cb0483c97de0ddd3ee104e4620939995f31dd9d7fb727a","abstract_canon_sha256":"5260a67ea650468369302cc78a090414ca5d3e8ae7a43ff25183ecfa3047ea2f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:25:02.339095Z","signature_b64":"kiUK7iWegMAa/EFQmpdn5HfqiZekgeLnB3tfsLD1aDm/pXP7hjKTlUarSCfXcsg2Dg6BmOCbM3NwCK3W4Nr+AA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"abd888de7c5b8bbc8ab545ce075d8396450a152e53a2008141577c8e9cbda431","last_reissued_at":"2026-07-05T08:25:02.338574Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:25:02.338574Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Vocabulary Attack to Hijack Large Language Model Applications","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.DC"],"primary_cat":"cs.CR","authors_text":"Christoph P. Neumann, Patrick Levi","submitted_at":"2024-04-03T10:54:07Z","abstract_excerpt":"The fast advancements in Large Language Models (LLMs) are driving an increasing number of applications. Together with the growing number of users, we also see an increasing number of attackers who try to outsmart these systems. They want the model to reveal confidential information, specific false information, or offensive behavior. To this end, they manipulate their instructions for the LLM by inserting separators or rephrasing them systematically until they reach their goal. Our approach is different. It inserts words from the model vocabulary. We find these words using an optimization proce"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2404.02637","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2404.02637/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2404.02637","created_at":"2026-07-05T08:25:02.338650+00:00"},{"alias_kind":"arxiv_version","alias_value":"2404.02637v2","created_at":"2026-07-05T08:25:02.338650+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2404.02637","created_at":"2026-07-05T08:25:02.338650+00:00"},{"alias_kind":"pith_short_12","alias_value":"VPMIRXT4LOF3","created_at":"2026-07-05T08:25:02.338650+00:00"},{"alias_kind":"pith_short_16","alias_value":"VPMIRXT4LOF3ZCVV","created_at":"2026-07-05T08:25:02.338650+00:00"},{"alias_kind":"pith_short_8","alias_value":"VPMIRXT4","created_at":"2026-07-05T08:25:02.338650+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2510.09093","citing_title":"Exploiting Web Search Tools of AI Agents for Data Exfiltration","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11575","citing_title":"MIXAR: Scaling Autoregressive Pixel-based Language Models to Multiple Languages and Scripts","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ","json":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ.json","graph_json":"https://pith.science/api/pith-number/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/graph.json","events_json":"https://pith.science/api/pith-number/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/events.json","paper":"https://pith.science/paper/VPMIRXT4"},"agent_actions":{"view_html":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ","download_json":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ.json","view_paper":"https://pith.science/paper/VPMIRXT4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2404.02637&json=true","fetch_graph":"https://pith.science/api/pith-number/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/graph.json","fetch_events":"https://pith.science/api/pith-number/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/action/storage_attestation","attest_author":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/action/author_attestation","sign_citation":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/action/citation_signature","submit_replication":"https://pith.science/pith/VPMIRXT4LOF3ZCVVIXHAOXMDSZ/action/replication_record"}},"created_at":"2026-07-05T08:25:02.338650+00:00","updated_at":"2026-07-05T08:25:02.338650+00:00"}