arXiv

D-Judge: Disrupting Multi-Turn Jailbreaks using Semantics-Preserving Output Rewriting

Title: D-Judge: Disrupting Multi-Turn Jailbreaks using Semantics-Preserving Output Rewriting

Abstract:

Large language models (LLMs) face an escalating security risk from multi-turn jailbreak attacks, which leverage feedback from auxiliary judge models to iteratively hone prompts for malicious outcomes. Current defensive measures primarily focus on identifying or blocking unsafe content at specific turns or in the final output. However, these approaches leave the judge-driven refinement cycle operational, permitting attackers to glean valuable feedback from intermediate exchanges.

We present D-Judge, a novel defense mechanism that employs semantics-preserving output rewriting to intervene directly within this feedback loop. By modifying the victim LLM’s responses prior to evaluation by the attacker’s judge, D-Judge disrupts the alignment of the feedback signal while maintaining the original meaning. This misalignment obstructs the attacker’s ability to refine prompts effectively, as subsequent queries are optimized based on a distorted assessment of attack progress.

To enhance the efficacy of these rewrites, we developed a dataset comprising semantically equivalent response pairs that yield varying harmfulness scores from judges. This dataset was utilized for supervised fine-tuning and subsequent direct preference optimization. Evaluations on HarmBench demonstrate that D-Judge significantly lowers the success rate of advanced multi-turn jailbreaks without compromising performance on standard benign benchmarks.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...