Beyond Fixed and Dynamic Prompts: Embedded Jailbreak Templates for Advancing LLM Security

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Kim, Hajun, Na, Hyunsik, Choi, Daeseon
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908661877571584
author Kim, Hajun
Na, Hyunsik
Choi, Daeseon
author_facet Kim, Hajun
Na, Hyunsik
Choi, Daeseon
contents As the use of large language models (LLMs) continues to expand, ensuring their safety and robustness has become a critical challenge. In particular, jailbreak attacks that bypass built-in safety mechanisms are increasingly recognized as a tangible threat across industries, driving the need for diverse templates to support red-teaming efforts and strengthen defensive techniques. However, current approaches predominantly rely on two limited strategies: (i) substituting harmful queries into fixed templates, and (ii) having the LLM generate entire templates, which often compromises intent clarity and reproductibility. To address this gap, this paper introduces the Embedded Jailbreak Template, which preserves the structure of existing templates while naturally embedding harmful queries within their context. We further propose a progressive prompt-engineering methodology to ensure template quality and consistency, alongside standardized protocols for generation and evaluation. Together, these contributions provide a benchmark that more accurately reflects real-world usage scenarios and harmful intent, facilitating its application in red-teaming and policy regression testing.
format Preprint
id arxiv_https___arxiv_org_abs_2511_14140
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond Fixed and Dynamic Prompts: Embedded Jailbreak Templates for Advancing LLM Security
Kim, Hajun
Na, Hyunsik
Choi, Daeseon
Cryptography and Security
As the use of large language models (LLMs) continues to expand, ensuring their safety and robustness has become a critical challenge. In particular, jailbreak attacks that bypass built-in safety mechanisms are increasingly recognized as a tangible threat across industries, driving the need for diverse templates to support red-teaming efforts and strengthen defensive techniques. However, current approaches predominantly rely on two limited strategies: (i) substituting harmful queries into fixed templates, and (ii) having the LLM generate entire templates, which often compromises intent clarity and reproductibility. To address this gap, this paper introduces the Embedded Jailbreak Template, which preserves the structure of existing templates while naturally embedding harmful queries within their context. We further propose a progressive prompt-engineering methodology to ensure template quality and consistency, alongside standardized protocols for generation and evaluation. Together, these contributions provide a benchmark that more accurately reflects real-world usage scenarios and harmful intent, facilitating its application in red-teaming and policy regression testing.
title Beyond Fixed and Dynamic Prompts: Embedded Jailbreak Templates for Advancing LLM Security
topic Cryptography and Security
url https://arxiv.org/abs/2511.14140