{"url":"/task/llm-jailbreak","name":"LLM Jailbreak","slug":"llm-jailbreak","description_markdown":null,"categories":[{"name":"Adversarial","url":"/area/adversarial"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":24,"papers_with_code":11,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":3,"subtasks":0,"parent_tasks":0},"benchmarks":[],"datasets":[{"url":"/dataset/salad-bench","name":"SALAD-Bench","full_name":"A Hierarchical and Comprehensive Safety Benchmark for Large Language Models","num_papers_in_archive":18},{"url":"/dataset/clear-bias","name":"CLEAR-Bias","full_name":"Corpus for Linguistic Evaluation of Adversarial Robustness against Bias","num_papers_in_archive":2},{"url":"/dataset/sudo-dataset","name":"SUDO Dataset","full_name":"","num_papers_in_archive":1}],"subtasks":[],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":11,"of":11,"tagged_in_all":24,"items":[{"url":"/paper/automatic-prompt-optimization-with-gradient","title":"Automatic Prompt Optimization with \"Gradient Descent\" and Beam Search","date":"2023-05-04","arxiv_id":"2305.03495","repositories_listed":6,"syntology":{"n":9,"n_ran":5,"n_unverified":4,"n_pointer_only":0}},{"url":"/paper/derail-yourself-multi-turn-llm-jailbreak","title":"Derail Yourself: Multi-turn LLM Jailbreak Attack through Self-discovered Clues","date":"2024-10-14","arxiv_id":"2410.10700","repositories_listed":2,"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":3}},{"url":"/paper/pandaguard-systematic-evaluation-of-llm","title":"PandaGuard: Systematic Evaluation of LLM Safety against Jailbreaking Attacks","date":"2025-05-20","arxiv_id":"2505.13862","repositories_listed":1,"syntology":null},{"url":"/paper/graph-of-attacks-with-pruning-optimizing","title":"Graph of Attacks with Pruning: Optimizing Stealthy Jailbreak Prompt Generation for Enhanced LLM Content Moderation","date":"2025-01-28","arxiv_id":"2501.18638","repositories_listed":1,"syntology":null},{"url":"/paper/cysecbench-generative-ai-based-cybersecurity","title":"CySecBench: Generative AI-based CyberSecurity-focused Prompt Dataset for Benchmarking Large Language Models","date":"2025-01-02","arxiv_id":"2501.01335","repositories_listed":1,"syntology":null},{"url":"/paper/sata-a-paradigm-for-llm-jailbreak-via-simple","title":"SATA: A Paradigm for LLM Jailbreak via Simple Assistive Task Linkage","date":"2024-12-19","arxiv_id":"2412.15289","repositories_listed":1,"syntology":null},{"url":"/paper/smiles-prompting-a-novel-approach-to-llm","title":"SMILES-Prompting: A Novel Approach to LLM Jailbreak Attacks in Chemical Synthesis","date":"2024-10-21","arxiv_id":"2410.15641","repositories_listed":1,"syntology":null},{"url":"/paper/cognitive-overload-attack-prompt-injection","title":"Cognitive Overload Attack:Prompt Injection for Long Context","date":"2024-10-15","arxiv_id":"2410.11272","repositories_listed":1,"syntology":null},{"url":"/paper/jailbreakzoo-survey-landscapes-and-horizons","title":"JailbreakZoo: Survey, Landscapes, and Horizons in Jailbreaking Large Language and Vision-Language Models","date":"2024-06-26","arxiv_id":"2407.01599","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-llm-jailbreak-via-adaptive-dense-to","title":"Efficient LLM Jailbreak via Adaptive Dense-to-sparse Constrained Optimization","date":"2024-05-15","arxiv_id":"2405.09113","repositories_listed":1,"syntology":null},{"url":"/paper/jailbreakv-28k-a-benchmark-for-assessing-the","title":"JailBreakV: A Benchmark for Assessing the Robustness of MultiModal Large Language Models against Jailbreak Attacks","date":"2024-04-03","arxiv_id":"2404.03027","repositories_listed":1,"syntology":null}],"syntology_records":2,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-25T09:33:49+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}