May 2026Unreviewed
Persona Attack: Incremental Memory Injection Jailbreak Attack against Large Language Models
Junyoung Park, Seongyong Ju, Sunghwan Park, Jaewoo Lee
Abstract
As Large Language Models evolve for user convenience, vulnerability to jailbreak attacks continues to be reported despite ongoing efforts in safety training. Traditional jailbreak techniques typically focus on a single prompt injection, neglecting the models' ability to remember the flow of conversation and the user's instructions. In this paper, we propose Persona Attack, a memory injection based jailbreak method that manipulates the model's context window through a step by step approach. Exper
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{park2026persona,
title = {{Persona Attack: Incremental Memory Injection Jailbreak Attack against Large Language Models}},
author = {Junyoung Park and Seongyong Ju and Sunghwan Park and Jaewoo Lee},
year = {2026},
month = may,
eprint = {2606.00150},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.00150}
}