Detecting Jailbreak Attempts in Clinical Training LLMs Through Automated Linguistic Feature Extraction

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Nguyen, Tri, Le, Huy Hoang Bao, Pentapalli, Lohith Srikanth, Turner, Laurah, Cohen, Kelly
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910021971869696
author Nguyen, Tri
Le, Huy Hoang Bao
Pentapalli, Lohith Srikanth
Turner, Laurah
Cohen, Kelly
author_facet Nguyen, Tri
Le, Huy Hoang Bao
Pentapalli, Lohith Srikanth
Turner, Laurah
Cohen, Kelly
contents Detecting jailbreak attempts in clinical training large language models (LLMs) requires accurate modeling of linguistic deviations that signal unsafe or off-task user behavior. Prior work on the 2-Sigma clinical simulation platform showed that manually annotated linguistic features could support jailbreak detection. However, reliance on manual annotation limited both scalability and expressiveness. In this study, we extend this framework by using experts' annotations of four core linguistic features (Professionalism, Medical Relevance, Ethical Behavior, and Contextual Distraction) and training multiple general-domain and medical-domain BERT-based LLM models to predict these features directly from text. The most reliable feature regressor for each dimension was selected and used as the feature extractor in a second layer of classifiers. We evaluate a suite of predictive models, including tree-based, linear, probabilistic, and ensemble methods, to determine jailbreak likelihood from the extracted features. Across cross-validation and held-out evaluations, the system achieves strong overall performance, indicating that LLM-derived linguistic features provide an effective basis for automated jailbreak detection. Error analysis further highlights key limitations in current annotations and feature representations, pointing toward future improvements such as richer annotation schemes, finer-grained feature extraction, and methods that capture the evolving risk of jailbreak behavior over the course of a dialogue. This work demonstrates a scalable and interpretable approach for detecting jailbreak behavior in safety-critical clinical dialogue systems.
format Preprint
id arxiv_https___arxiv_org_abs_2602_13321
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Detecting Jailbreak Attempts in Clinical Training LLMs Through Automated Linguistic Feature Extraction
Nguyen, Tri
Le, Huy Hoang Bao
Pentapalli, Lohith Srikanth
Turner, Laurah
Cohen, Kelly
Artificial Intelligence
Machine Learning
Detecting jailbreak attempts in clinical training large language models (LLMs) requires accurate modeling of linguistic deviations that signal unsafe or off-task user behavior. Prior work on the 2-Sigma clinical simulation platform showed that manually annotated linguistic features could support jailbreak detection. However, reliance on manual annotation limited both scalability and expressiveness. In this study, we extend this framework by using experts' annotations of four core linguistic features (Professionalism, Medical Relevance, Ethical Behavior, and Contextual Distraction) and training multiple general-domain and medical-domain BERT-based LLM models to predict these features directly from text. The most reliable feature regressor for each dimension was selected and used as the feature extractor in a second layer of classifiers. We evaluate a suite of predictive models, including tree-based, linear, probabilistic, and ensemble methods, to determine jailbreak likelihood from the extracted features. Across cross-validation and held-out evaluations, the system achieves strong overall performance, indicating that LLM-derived linguistic features provide an effective basis for automated jailbreak detection. Error analysis further highlights key limitations in current annotations and feature representations, pointing toward future improvements such as richer annotation schemes, finer-grained feature extraction, and methods that capture the evolving risk of jailbreak behavior over the course of a dialogue. This work demonstrates a scalable and interpretable approach for detecting jailbreak behavior in safety-critical clinical dialogue systems.
title Detecting Jailbreak Attempts in Clinical Training LLMs Through Automated Linguistic Feature Extraction
topic Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2602.13321