Researchers have developed a novel jailbreaking technique for aligned large language models that leverages fanfiction subgenres. This method uses passages from twelve different Archive of Our Own (AO3) subgenres to embed harmful behaviors, bypassing traditional defenses. The attack significantly increases the attack success rate (ASR) from 0.278 to 0.731 on eight LLMs, demonstrating that the effectiveness stems from the writing style rather than prompt structure. Proposed defenses were found to be ineffective, suggesting a shift towards register-based attacks. AI
IMPACT This research highlights a new vulnerability in LLM safety training, potentially requiring novel defense mechanisms beyond simple prompt filtering.
RANK_REASON The cluster contains a research paper detailing a new method for jailbreaking LLMs.
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →