about
PsychoPass: Geometric Profiling of Multi-Turn Adversarial LLM Conversations (arxiv.org)
3 points by Anon84 103 days ago | hide | past | pdf | discuss on HN

In plain words: It tracks how a conversation's meaning drifts through a space of word meanings to flag jailbreak attacks before any harmful text appears. Once the easy clue of conversation length is removed, the shape alone still catches attacks early, beating the usual check-each-message guardrails.

Abstract

Multi-turn jailbreak attacks on large language models (LLMs) reveal a mismatch in current guardrails: they operate on individual turns, while attacks unfold as trajectories across conversations. We propose a shift from content to dynamics, modeling conversations as paths in representation space and asking whether adversarial intent is encoded early in their geometry. We introduce PsychoPass, a framework that extracts geometric features from conversation trajectories in embedding space to predict a potential attack before harmful content is produced. These features achieve near-perfect performance in naïve classifiers, which is largely explained by the inclusion of number of turns as a feature. After removing this confound, a smaller but consistent geometric signal remains, with classification performance that does not depend meaningfully on encoder choice. Crucially, this signal appears early in the conversation: attack outcomes remain above chance from short prefixes alone, more reliably than baseline guardrails. A supporting theoretical analysis explains these findings via a decomposition of length and shape, a detection bound based on prefix length, and encoder invariance. Together, these results show that adversarial conversations leave an early, representation-robust geometric fingerprint suitable for online monitoring.

Muberra Ozmen, Subhabrata Majumdar
arXiv:2606.03136 · cs.CR, cs.CL · submitted Jun 2, 2026
abstract · pdf · html

add comment on HN