Papers › How Many Iterations to Jailbreak? Dynamic Budget Allocation for Multi-Turn LLM Evaluation

How Many Iterations to Jailbreak? Dynamic Budget Allocation for Multi-Turn LLM Evaluation

7 May 2026arXiv:2605.06605added by Syntology

Shai Feldman, Yaniv Romano

Title, abstract, authors and date from arXiv's metadata (CC0); this paper is not in the Papers with Code archive (frozen 2025-07-28).

Evaluating and predicting the performance of large language models (LLMs) in multi-turn conversational settings is critical yet computationally expensive; key events -- e.g., jailbreaks or successful task completion by an agent -- often emerge only after repeated interactions. These events might be rare, and under any feasible computational budget, remain unobserved. Recent conformal survival frameworks construct reliable lower predictive bounds (LPBs) on the number of iterations to trigger the event of interest, but rely on static budget allocation that is inefficient in multi-turn setups. To address this, we introduce \emph{Dynamic Allocation via PRojected Optimization} (DAPRO), the first theoretically valid dynamic budget allocation framework for bounding the time-to-event in multi-turn LLM interactions. We prove that DAPRO satisfies the budget constraint and provides distribution-free, finite-sample coverage guarantees without requiring the conditional independence between censoring and event times assumed by prior conformal survival approaches. A key theoretical contribution is a novel coverage bound that scales with the square root of the mean censoring weight rather than the worst-case weight, yielding provably tighter guarantees than prior work. Furthermore, DAPRO can be employed to obtain unbiased, low-variance estimates of population-level evaluation metrics, such as the jailbreak rate, under limited computing resources. Comprehensive experiments across agentic task success, adversarial jailbreaks, toxic content generation, and RAG hallucinations using LLMs such as Llama 3.1 and Qwen 2.5 demonstrate that DAPRO consistently achieves coverage closer to the nominal level with lower variance than static baselines, while satisfying the budget constraint.

PaperPDFCode Syntology ran

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

For agents, Syntology's MCP tool lists every function and class Syntology harvested from this paper and whether it ran (how to connect): get_harvested_code_for_paper(arxiv_id="2605.06605")

Code

Syntology Ran 12 of 14 code samples harvested from 1 repository linked to this paper; 2 have no recorded run. Of those that ran: 7 ran · our draft was wrong; 4 ran · fixture could not drive it; 1 ran with no contract checked.

By repository: found in paper text by Syntology: 14 samples from 1 repository, 12 ran. The run record, sample by sample. “Ran” means executed on a synthesized input, not that the code is correct or reproduces the paper.

Shai128/dapro found in paper text by Syntology report

Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

14 samples harvested; 12 ran; 0 honoured the contract we drafted; 2 have no recorded run. Read from Syntology's graph 2026-09-24; that is when this build read the record, not when the samples ran.

7ran · our draft was wrong
4ran · fixture could not drive it
1ran
2unverified

Licence: 14 of the 14 samples are pointer only, meaning Syntology does not serve that copy's text. This page shows no code text for any sample; each one links to its file in the repository.

Harvested from Shai128/dapro. “Ran” means the sample executed on a synthesized input. It does not mean the output is correct, and nothing here reproduces the paper's results. “Honoured” and “violated” refer to a contract Syntology drafted from the code itself; “our draft was wrong” and “fixture could not drive it” are failures of Syntology's instrument, not of the code.

Each sample ends with its code_sha256, Syntology's identity for that exact code. An agent fetches the stored sample with Syntology's MCP tool get_code(code_sha256="…") (how to connect); click an identity to copy that call.

Repository labels, per sample. official repository: The archive marks this repository official for the paper. named in the paper: The archive records that the paper mentions this repository; it is not marked official. community (archive-listed): In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper. found in paper text by Syntology: Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted. community: Not in the archive's code links for this paper; a community repository Syntology harvested. Samples from a repository marked official are listed first. Licence labels name the repository's licence as recorded at harvest. “Pointer only” means Syntology does not serve that copy's text, for one of four reasons: no licence file was found; the licence was not identified; the licence is recorded as permissive but that copy's record is not marked cleared; or the licence is outside the permissive list Syntology serves text under (MIT, Apache-2.0, BSD and similar). Some licences outside that list permit redistribution, such as WTFPL, and GPL-3.0 under its conditions; they are simply not on the list. Hover a licence label for the reason. File links open the file on GitHub at the default branch, which may have changed since the harvest.

BudgetAllocationResult Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran no licence file found · pointer only · 9fe42bc9bbd6f856 · report
adaptive_budget_allocation Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · 46a47aafa6d6130f · report
compute_quantile_survival_time Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · fixture could not drive it no licence file found · pointer only · 20a07c4782cd6861 · report
construct_final_result Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · 744f6727bede6352 · report
estimate_tail_decay_rate Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · fixture could not drive it no licence file found · pointer only · 0c1406020867a865 · report
get_prior Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · fixture could not drive it no licence file found · pointer only · b7d2b20ec98a2f23 · report
mask_and_renormalize_probs Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · fixture could not drive it fingerprinted no licence file found · pointer only · 623cc5943fe4b193 · report
project_to_test_beta Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · cb15c9e40a0bd276 · report
project_to_test_ir Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · 77a681ea83d8dfc1 · report
project_to_test_platt Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · 63d156d7f8a64d80 · report
solve_exact_fast Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · f52a63991e332957 · report
split_to_two_sets Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology ran · our draft was wrong no licence file found · pointer only · 5e6790f0532f98c7 · report
BudgetAllocator Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology unverified no licence file found · pointer only · aeac11fe2200522b · report
DAPRO Shai128/dapro/src/safety_evaluation/budget_allocators/DAPRO.py found in paper text by Syntology unverified no licence file found · pointer only · f424380029fda4d0 · report

Results from the paper

The Papers with Code archive ends with its 2025-07-28 snapshot. This paper's arXiv identifier, 2605.06605, was issued in May 2026, after that date, so the archive has no leaderboard rows for it.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections