Skip to content
Search
paperApril 2026Unreviewed

Jailbroken Frontier Models Retain Their Capabilities

Daniel Zhu, Zihan Wang, Jenny Bao, Jerry Wei

Abstract

As language model safeguards become more robust, attackers are pushed toward developing increasingly complex jailbreaks. Prior work has found that this complexity imposes a "jailbreak tax" that degrades the target model's task performance. We show that this tax scales inversely with model capability and that the most advanced jailbreaks effectively yield no reduction in model capabilities. Evaluating 28 jailbreaks on five benchmarks across Claude models ranging in capability from Haiku 4.5 to Op

Categories

Framework mappings

MITRE ATLAS
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{zhu2026jailbroken,
  title = {{Jailbroken Frontier Models Retain Their Capabilities}},
  author = {Daniel Zhu and Zihan Wang and Jenny Bao and Jerry Wei},
  year = {2026},
  month = apr,
  eprint = {2605.00267},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.00267}
}