In plain words: They gathered 17 known tricks for coaxing chatbots into forbidden answers, sorted them into categories, and tested them on safety-tuned models with and without added defenses. Simple hand-crafted tricks fooled models most often, but ordinary safety filters blocked them easily, cutting their real-world value.
Abstract · JailbreakRadar: Comprehensive Assessment of Jailbreak Attacks Against LLMs
Jailbreak attacks aim to bypass the LLMs' safeguards. While researchers have proposed different jailbreak attacks in depth, they have done so in isolation -- either with unaligned settings or comparing a limited range of methods. To fill this gap, we present a large-scale evaluation of various jailbreak attacks. We collect 17 representative jailbreak attacks, summarize their features, and establish a novel jailbreak attack taxonomy. Then we conduct comprehensive measurement and ablation studies across nine aligned LLMs on 160 forbidden questions from 16 violation categories. Also, we test jailbreak attacks under eight advanced defenses. Based on our taxonomy and experiments, we identify some important patterns, such as heuristic-based attacks could achieve high attack success rates but are easy to mitigate by defenses, causing low practicality. Our study offers valuable insights for future research on jailbreak attacks and defenses. We hope our work could help the community avoid incremental work and serve as an effective benchmark tool for practitioners.
Junjie Chu, Yugeng Liu, Ziqing Yang, Xinyue Shen, Michael Backes, Yang Zhang
arXiv:2402.05668 · cs.CR, cs.AI, cs.CL, cs.LG · submitted Feb 8, 2024 · updated May 26, 2025
abstract · pdf · html · Correct typos and update new experiment results. Accepted in ACL 2025. 25 pages, 12 figures