{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:Z7WJ3OD226FX4J25N5SJ3P7FVI","short_pith_number":"pith:Z7WJ3OD2","schema_version":"1.0","canonical_sha256":"cfec9db87ad78b7e275d6f649dbfe5aa273a1c43d99b5cd47724a65b880b155d","source":{"kind":"arxiv","id":"2303.04381","version":1},"attestation_state":"computed","paper":{"title":"Automatically Auditing Large Language Models via Discrete Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Aditi Raghunathan, Anca Dragan, Erik Jones, Jacob Steinhardt","submitted_at":"2023-03-08T05:09:59Z","abstract_excerpt":"Auditing large language models for unexpected behaviors is critical to preempt catastrophic deployments, yet remains challenging. In this work, we cast auditing as an optimization problem, where we automatically search for input-output pairs that match a desired target behavior. For example, we might aim to find a non-toxic input that starts with \"Barack Obama\" that a model maps to a toxic output. This optimization problem is difficult to solve as the set of feasible points is sparse, the space is discrete, and the language models we audit are non-linear and high-dimensional. To combat these c"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2303.04381","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-03-08T05:09:59Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"1366cb4cddba8f5294c0198730ae3d2be38a54957072469866d4c39ad089401c","abstract_canon_sha256":"b8796d98b0b16773da5627b8f8526926cc0d13582e3aeae4de300c642780d60c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:49:20.745824Z","signature_b64":"S7UNOGkTTwQkDg4HJtXlFsi58MV5otXi4Plp1fedaGp5OS+FW0W05cfQ6JJbyx0WZxiftlgmzgmkhbMBYTrsBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cfec9db87ad78b7e275d6f649dbfe5aa273a1c43d99b5cd47724a65b880b155d","last_reissued_at":"2026-07-05T05:49:20.745347Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:49:20.745347Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Automatically Auditing Large Language Models via Discrete Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Aditi Raghunathan, Anca Dragan, Erik Jones, Jacob Steinhardt","submitted_at":"2023-03-08T05:09:59Z","abstract_excerpt":"Auditing large language models for unexpected behaviors is critical to preempt catastrophic deployments, yet remains challenging. In this work, we cast auditing as an optimization problem, where we automatically search for input-output pairs that match a desired target behavior. For example, we might aim to find a non-toxic input that starts with \"Barack Obama\" that a model maps to a toxic output. This optimization problem is difficult to solve as the set of feasible points is sparse, the space is discrete, and the language models we audit are non-linear and high-dimensional. To combat these c"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2303.04381","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2303.04381/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2303.04381","created_at":"2026-07-05T05:49:20.745409+00:00"},{"alias_kind":"arxiv_version","alias_value":"2303.04381v1","created_at":"2026-07-05T05:49:20.745409+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2303.04381","created_at":"2026-07-05T05:49:20.745409+00:00"},{"alias_kind":"pith_short_12","alias_value":"Z7WJ3OD226FX","created_at":"2026-07-05T05:49:20.745409+00:00"},{"alias_kind":"pith_short_16","alias_value":"Z7WJ3OD226FX4J25","created_at":"2026-07-05T05:49:20.745409+00:00"},{"alias_kind":"pith_short_8","alias_value":"Z7WJ3OD2","created_at":"2026-07-05T05:49:20.745409+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2307.15043","citing_title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2508.20325","citing_title":"GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2310.06987","citing_title":"Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2307.02483","citing_title":"Jailbroken: How Does LLM Safety Training Fail?","ref_index":29,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI","json":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI.json","graph_json":"https://pith.science/api/pith-number/Z7WJ3OD226FX4J25N5SJ3P7FVI/graph.json","events_json":"https://pith.science/api/pith-number/Z7WJ3OD226FX4J25N5SJ3P7FVI/events.json","paper":"https://pith.science/paper/Z7WJ3OD2"},"agent_actions":{"view_html":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI","download_json":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI.json","view_paper":"https://pith.science/paper/Z7WJ3OD2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2303.04381&json=true","fetch_graph":"https://pith.science/api/pith-number/Z7WJ3OD226FX4J25N5SJ3P7FVI/graph.json","fetch_events":"https://pith.science/api/pith-number/Z7WJ3OD226FX4J25N5SJ3P7FVI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI/action/storage_attestation","attest_author":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI/action/author_attestation","sign_citation":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI/action/citation_signature","submit_replication":"https://pith.science/pith/Z7WJ3OD226FX4J25N5SJ3P7FVI/action/replication_record"}},"created_at":"2026-07-05T05:49:20.745409+00:00","updated_at":"2026-07-05T05:49:20.745409+00:00"}