August 2026Unreviewed
SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks
Siyuan Li, Aodu Wulianghai, Zehao Liu, Xi Lin, Qinghua Mao, Haoyu Li, Xiang Chen, Siyuan Liang, Jun Wu, Jianhua Li, Dacheng Tao
Abstract
Large Language Models (LLMs) are increasingly deployed in interactive settings, where user intent commonly unfolds through multi-turn dialogue. Multi-turn jailbreaks exploit this pattern by advancing a harmful intent across turns, so that no single message exposes the full objective. However, existing work treats these attacks as a loose collection of prompt patterns and does not analyze how the adversary organizes and advances harmful intent across an interaction. We develop a four-part, intent
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{li2026sok,
title = {{SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks}},
author = {Siyuan Li and Aodu Wulianghai and Zehao Liu and Xi Lin and Qinghua Mao and Haoyu Li and Xiang Chen and Siyuan Liang and Jun Wu and Jianhua Li and Dacheng Tao},
year = {2026},
month = aug,
eprint = {2608.01117},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.01117}
}