January 2025Unreviewed
Graph of Attacks with Pruning: Optimizing Stealthy Jailbreak Prompt Generation for Enhanced LLM Content Moderation
Daniel Schwartz, Dmitriy Bespalov, Zhe Wang, Ninad Kulkarni, Yanjun Qi
Conference on Empirical Methods in Natural Language Processing
Abstract
As large language models (LLMs) become increasingly prevalent, ensuring their robustness against adversarial misuse is crucial. This paper introduces the GAP (Graph of Attacks with Pruning) framework, an advanced approach for generating stealthy jailbreak prompts to evaluate and enhance LLM safeguards. GAP addresses limitations in existing tree-based LLM jailbreak methods by implementing an interconnected graph structure that enables knowledge sharing across attack paths. Our experimental evalua
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@inproceedings{schwartz2025graph,
title = {{Graph of Attacks with Pruning: Optimizing Stealthy Jailbreak Prompt Generation for Enhanced LLM Content Moderation}},
author = {Daniel Schwartz and Dmitriy Bespalov and Zhe Wang and Ninad Kulkarni and Yanjun Qi},
year = {2025},
month = jan,
booktitle = {Conference on Empirical Methods in Natural Language Processing},
eprint = {2501.18638},
archivePrefix = {arXiv},
doi = {10.48550/arXiv.2501.18638},
url = {https://www.semanticscholar.org/paper/79f7e65410d089da1f7a66569a19d5ff27b80f5d}
}