{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/code/check-for-attack-success","entry":"check_for_attack_success","source":"Syntology graph, per-sample; not an archive number","read_at":"2026-09-24T18:15:14+00:00","claim":"Names are grouped by exact entry-name string. Same-named routines are NOT asserted to be equivalent; 'ran' means executed on a synthesized fixture, not correctness. n_samples_ran = sum of by_status over every status except 'unverified' (ran_draft_wrong and ran_fixture are failures of Syntology's instrument, not of the code); n_papers_ran = papers with at least one such sample.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"},"n_papers":6,"n_papers_ran":5,"units":"n_samples, n_samples_ran, n_samples_fingerprinted and by_status count distinct code bodies (code_sha256); n_places and n_places_pointer_only count places, one per (paper, code body) pair, which is also the unit of the samples list","n_samples":5,"n_samples_ran":4,"n_samples_fingerprinted":0,"n_places":6,"n_places_pointer_only":2,"by_status":{"ran_honours":0,"ran_violates":0,"ran_draft_wrong":2,"ran_fixture":0,"ran":2,"unverified":1},"syntology":{"atlas_url":null,"mcp":null,"mcp_per_sample":{"tool":"get_code","arguments_in":"samples[].mcp_get_code"},"developers":"https://syntology.ai/developers"},"samples":[{"arxiv_id":"2603.03081","paper":"/paper/arxiv-2603-03081","title":"TAO-Attack: Toward Advanced Optimization-Based Jailbreak Attacks for Large Language Models","date":null,"month_inferred_from_arxiv_id":"2026-03","title_source":"syntology","repo":"ZevineXu/TAO-Attack","path":"attack.py","file_url":"https://github.com/ZevineXu/TAO-Attack/blob/HEAD/attack.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"2b431b29ac3d458c","mcp_get_code":{"code_sha256":"2b431b29ac3d458c"}},{"arxiv_id":"2406.01288","paper":"/paper/improved-few-shot-jailbreaking-can-circumvent","title":"Improved Few-Shot Jailbreaking Can Circumvent Aligned Language Models and Their Defenses","date":"2024-06-03","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"sail-sg/I-FSJ","path":"exps/rs.py","file_url":"https://github.com/sail-sg/I-FSJ/blob/HEAD/exps/rs.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"a2058f7fc99001a7","mcp_get_code":{"code_sha256":"a2058f7fc99001a7"}},{"arxiv_id":"2405.21018","paper":"/paper/improved-techniques-for-optimization-based","title":"Improved Techniques for Optimization-Based Jailbreaking on Large Language Models","date":"2024-05-31","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"jiaxiaojunQAQ/I-GCG","path":"attack_llm_core_best_update_our_target.py","file_url":"https://github.com/jiaxiaojunQAQ/I-GCG/blob/HEAD/attack_llm_core_best_update_our_target.py","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"3e43a8aedf0a2745","mcp_get_code":{"code_sha256":"3e43a8aedf0a2745"}},{"arxiv_id":"2405.01229","paper":"/paper/boosting-jailbreak-attack-with-momentum","title":"Boosting Jailbreak Attack with Momentum","date":"2024-05-02","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"weizeming/momentum-attack-llm","path":"gcg.py","file_url":"https://github.com/weizeming/momentum-attack-llm/blob/HEAD/gcg.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"3f2d43822911360c","mcp_get_code":{"code_sha256":"3f2d43822911360c"}},{"arxiv_id":"2403.04957","paper":"/paper/automatic-and-universal-prompt-injection","title":"Automatic and Universal Prompt Injection Attacks against Large Language Models","date":"2024-03-07","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"sheltonliu-n/universal-prompt-injection","path":"universal_prompt_injection.py","file_url":"https://github.com/sheltonliu-n/universal-prompt-injection/blob/HEAD/universal_prompt_injection.py","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"7a1925d40005947b","mcp_get_code":{"code_sha256":"7a1925d40005947b"}},{"arxiv_id":"2310.04451","paper":"/paper/autodan-generating-stealthy-jailbreak-prompts","title":"AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","date":"2023-10-03","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"SheltonLiu-N/AutoDAN","path":"autodan_ga_eval.py","file_url":"https://github.com/SheltonLiu-N/AutoDAN/blob/HEAD/autodan_ga_eval.py","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"7a1925d40005947b","mcp_get_code":{"code_sha256":"7a1925d40005947b"}}]}