April 2026Unreviewed
Jailbroken Frontier Models Retain Their Capabilities
Daniel Zhu, Zihan Wang, Jenny Bao, Jerry Wei
Abstract
As language model safeguards become more robust, attackers are pushed toward developing increasingly complex jailbreaks. Prior work has found that this complexity imposes a "jailbreak tax" that degrades the target model's task performance. We show that this tax scales inversely with model capability and that the most advanced jailbreaks effectively yield no reduction in model capabilities. Evaluating 28 jailbreaks on five benchmarks across Claude models ranging in capability from Haiku 4.5 to Op
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{zhu2026jailbroken,
title = {{Jailbroken Frontier Models Retain Their Capabilities}},
author = {Daniel Zhu and Zihan Wang and Jenny Bao and Jerry Wei},
year = {2026},
month = apr,
eprint = {2605.00267},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.00267}
}