{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/code/attacker","entry":"Attacker","source":"Syntology graph, per-sample; not an archive number","read_at":"2026-09-24T18:15:14+00:00","claim":"Names are grouped by exact entry-name string. Same-named routines are NOT asserted to be equivalent; 'ran' means executed on a synthesized fixture, not correctness. n_samples_ran = sum of by_status over every status except 'unverified' (ran_draft_wrong and ran_fixture are failures of Syntology's instrument, not of the code); n_papers_ran = papers with at least one such sample.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"},"n_papers":8,"n_papers_ran":3,"units":"n_samples, n_samples_ran, n_samples_fingerprinted and by_status count distinct code bodies (code_sha256); n_places and n_places_pointer_only count places, one per (paper, code body) pair, which is also the unit of the samples list","n_samples":8,"n_samples_ran":3,"n_samples_fingerprinted":0,"n_places":8,"n_places_pointer_only":4,"by_status":{"ran_honours":0,"ran_violates":0,"ran_draft_wrong":0,"ran_fixture":0,"ran":3,"unverified":5},"syntology":{"atlas_url":null,"mcp":null,"mcp_per_sample":{"tool":"get_code","arguments_in":"samples[].mcp_get_code"},"developers":"https://syntology.ai/developers"},"samples":[{"arxiv_id":"2608.09542","paper":"/paper/arxiv-2608-09542","title":"Dual-Adversarial Safety Alignment: Cultivating Intrinsic Threat Comprehension in LRMs","date":null,"month_inferred_from_arxiv_id":"2026-08","title_source":"syntology","repo":"renmiamu/AdvSafe","path":"src/agent/attacker.py","file_url":"https://github.com/renmiamu/AdvSafe/blob/HEAD/src/agent/attacker.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"528b86b6bc65a5ae","mcp_get_code":{"code_sha256":"528b86b6bc65a5ae"}},{"arxiv_id":"2605.26595","paper":"/paper/arxiv-2605-26595","title":"CORDYCEPS: Covert Control Attacks on LLMs via Data Poisoning","date":null,"month_inferred_from_arxiv_id":"2026-05","title_source":"syntology","repo":"Sadcardation/cordyceps","path":"Open-Prompt-Injection/OpenPromptInjection/attackers/SleeperAttacker.py","file_url":"https://github.com/Sadcardation/cordyceps/blob/HEAD/Open-Prompt-Injection/OpenPromptInjection/attackers/SleeperAttacker.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"1ab09600faafb4d4","mcp_get_code":{"code_sha256":"1ab09600faafb4d4"}},{"arxiv_id":"2605.00974","paper":"/paper/arxiv-2605-00974","title":"SRTJ: Self-Evolving Rule-Driven Training-Free LLM Jailbreaking","date":null,"month_inferred_from_arxiv_id":"2026-05","title_source":"syntology","repo":"TheSolkatt/SRTJ","path":"src/attacker.py","file_url":"https://github.com/TheSolkatt/SRTJ/blob/HEAD/src/attacker.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"b6a850495a7e70fb","mcp_get_code":{"code_sha256":"b6a850495a7e70fb"}},{"arxiv_id":"2410.02195","paper":"/paper/backtime-backdoor-attacks-on-multivariate","title":"BACKTIME: Backdoor Attacks on Multivariate Time Series Forecasting","date":"2024-10-03","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"xiaolin-cs/backtime","path":"attack.py","file_url":"https://github.com/xiaolin-cs/backtime/blob/HEAD/attack.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"a0458a9d0f3f116c","mcp_get_code":{"code_sha256":"a0458a9d0f3f116c"}},{"arxiv_id":"2409.05021","paper":"/paper/vision-fused-attack-advancing-aggressive-and","title":"Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation","date":"2024-09-08","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"Levelower/VFA","path":"attack.py","file_url":"https://github.com/Levelower/VFA/blob/HEAD/attack.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"b13d2218dfb23d83","mcp_get_code":{"code_sha256":"b13d2218dfb23d83"}},{"arxiv_id":"2111.09277","paper":"/paper/smoothmix-training-confidence-calibrated","title":"SmoothMix: Training Confidence-calibrated Smoothed Classifiers for Certified Robustness","date":"2021-11-17","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"jh-jeong/smoothmix","path":"code/train_consistency.py","file_url":"https://github.com/jh-jeong/smoothmix/blob/HEAD/code/train_consistency.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"dff4428e257e2940","mcp_get_code":{"code_sha256":"dff4428e257e2940"}},{"arxiv_id":"2106.05087","paper":"/paper/who-is-the-strongest-enemy-towards-optimal","title":"Who Is the Strongest Enemy? Towards Optimal and Efficient Evasion Attacks in Deep RL","date":"2021-06-09","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"umd-huang-lab/paad_adv_rl","path":"code_atari/paad_rl/attacker/attacker.py","file_url":"https://github.com/umd-huang-lab/paad_adv_rl/blob/HEAD/code_atari/paad_rl/attacker/attacker.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"942887ec27de2b72","mcp_get_code":{"code_sha256":"942887ec27de2b72"}},{"arxiv_id":"2102.05096","paper":"/paper/adversarially-robust-classifier-with","title":"Towards Bridging the gap between Empirical and Certified Robustness against Adversarial Examples","date":"2021-02-09","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"Hadisalman/smoothing-adversarial","path":"code/train_pgd.py","file_url":"https://github.com/Hadisalman/smoothing-adversarial/blob/HEAD/code/train_pgd.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"156c1e3dc785672c","mcp_get_code":{"code_sha256":"156c1e3dc785672c"}}]}