Papers
arxiv:2605.21674

Adversarial Reframing: A Framework for Targeted Generation in Language Models

Published on May 20
Authors:
,
,

Abstract

A reasoning-driven framework coordinates multiple LLMs to iteratively discover textual jailbreak prompts by formulating prompt discovery as a nonconvex optimization problem, achieving higher attack success rates with lower computational cost while revealing previously undetected vulnerabilities in aligned LLMs.

Large Language Models (LLMs) are widely deployed in diverse real-world settings, yet remain vulnerable to jailbreaking, where prompt-based attacks bypass safety filters. We present THREAT (Targeted Harmful generation via Reframing and Exploitation of Adversarial Tactics), a reasoning-driven framework that coordinates multiple LLMs in an iterative search loop to find textual jailbreak prompts. We formulate prompt discovery as a nonconvex optimization problem and provide an efficient solution that lowers runtime and improves attack effectiveness. Across diverse datasets and model architectures, THREAT delivers higher attack success rates with lower computational cost than prior methods. The crafted prompts were flagged as harmful in fewer than 1% of cases, compared with about 50% refusals for the corresponding unmodified prompts. These findings reveal previously undetected vulnerabilities in aligned LLMs and position THREAT as a practical tool for proactively strengthening the safety of foundation models.

Community

Sign up or log in to comment

Get this paper in your agent:

hf papers read 2605.21674
Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash

Models citing this paper 0

No model linking this paper

Cite arxiv.org/abs/2605.21674 in a model README.md to link it from this page.

Datasets citing this paper 0

No dataset linking this paper

Cite arxiv.org/abs/2605.21674 in a dataset README.md to link it from this page.

Spaces citing this paper 0

No Space linking this paper

Cite arxiv.org/abs/2605.21674 in a Space README.md to link it from this page.

Collections including this paper 1