TombRaider: Entering the Vault of History to Jailbreak Large Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Ding, Junchen, Zhang, Jiahao, Liu, Yi, Ding, Ziqi, Deng, Gelei, Li, Yuekang
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916912584196096
author Ding, Junchen
Zhang, Jiahao
Liu, Yi
Ding, Ziqi
Deng, Gelei
Li, Yuekang
author_facet Ding, Junchen
Zhang, Jiahao
Liu, Yi
Ding, Ziqi
Deng, Gelei
Li, Yuekang
contents Warning: This paper contains content that may involve potentially harmful behaviours, discussed strictly for research purposes. Jailbreak attacks can hinder the safety of Large Language Model (LLM) applications, especially chatbots. Studying jailbreak techniques is an important AI red teaming task for improving the safety of these applications. In this paper, we introduce TombRaider, a novel jailbreak technique that exploits the ability to store, retrieve, and use historical knowledge of LLMs. TombRaider employs two agents, the inspector agent to extract relevant historical information and the attacker agent to generate adversarial prompts, enabling effective bypassing of safety filters. We intensively evaluated TombRaider on six popular models. Experimental results showed that TombRaider could outperform state-of-the-art jailbreak techniques, achieving nearly 100% attack success rates (ASRs) on bare models and maintaining over 55.4% ASR against defence mechanisms. Our findings highlight critical vulnerabilities in existing LLM safeguards, underscoring the need for more robust safety defences.
format Preprint
id arxiv_https___arxiv_org_abs_2501_18628
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle TombRaider: Entering the Vault of History to Jailbreak Large Language Models
Ding, Junchen
Zhang, Jiahao
Liu, Yi
Ding, Ziqi
Deng, Gelei
Li, Yuekang
Cryptography and Security
Artificial Intelligence
Computation and Language
Computers and Society
Warning: This paper contains content that may involve potentially harmful behaviours, discussed strictly for research purposes. Jailbreak attacks can hinder the safety of Large Language Model (LLM) applications, especially chatbots. Studying jailbreak techniques is an important AI red teaming task for improving the safety of these applications. In this paper, we introduce TombRaider, a novel jailbreak technique that exploits the ability to store, retrieve, and use historical knowledge of LLMs. TombRaider employs two agents, the inspector agent to extract relevant historical information and the attacker agent to generate adversarial prompts, enabling effective bypassing of safety filters. We intensively evaluated TombRaider on six popular models. Experimental results showed that TombRaider could outperform state-of-the-art jailbreak techniques, achieving nearly 100% attack success rates (ASRs) on bare models and maintaining over 55.4% ASR against defence mechanisms. Our findings highlight critical vulnerabilities in existing LLM safeguards, underscoring the need for more robust safety defences.
title TombRaider: Entering the Vault of History to Jailbreak Large Language Models
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Computers and Society
url https://arxiv.org/abs/2501.18628