arXiv

Black-box, Adaptive, Efficient, Transferable, Harmful, Applicable... Attacks Are All You Need to Break LLMs

Title: Breaking LLMs: The Necessity of Black-Box, Adaptive, Efficient, and Transferable Attacks

Abstract:

Establishing accurate metrics for adversarial robustness has long remained a significant hurdle in the field. When attack methodologies are poorly designed, they can artificially inflate estimates of robustness, thereby compromising the reliability of risk assessments for deployment and comparisons among defensive strategies. While standardized tools like AutoAttack have largely addressed this issue for image classifiers—establishing a trustworthy baseline for systematic defense evaluation—no equivalent standard currently exists for Large Language Model (LLM) jailbreak testing. Designing such an attack for LLMs is notably more complex. To be effective, a robust attack must simultaneously satisfy several critical criteria: it must operate in a black-box setting, remain applicable to diverse defense pipelines, and maintain high efficiency. Currently, no existing method meets all these requirements collectively.

We present Indirect Harm Optimization (IHO), a novel attacker based on a masked diffusion language model. This approach is trained through iterative preference optimization against a harmfulness judge and requires only black-box access to the target model. The versatility of IHO allows it to function as a potent adaptive attack tailored to specific behaviors without modification, or as an efficient, amortized policy capable of transferring to unseen target models and held-out behaviors without the need for fine-tuning.

In evaluations involving layered defenses—such as models trained with Circuit Breaker techniques augmented by auxiliary detectors—IHO significantly outperforms current state-of-the-art methods in terms of attack success rates. This superiority is achieved without any adaptation specific to the defenses employed. These findings position IHO as a crucial practical advancement toward the standardized jailbreak evaluation protocols that have previously enhanced reliability in other domains. The associated code and models are publicly accessible via GitHub and Hugging Face.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...