SearcharxivSearch

arXiv subjects

Luping Ma

Publications and source records attributed to Luping Ma.

2 recordsLinked to original sources

Prefill-level Jailbreak: A Black-Box Risk Analysis of Large Language Models

Large Language Models face security threats from jailbreak attacks. Existing research has predominantly focused on prompt-level attacks while largely ignoring the underexplored attack surface of user-controlled response prefilling. This functionality allows an attacker to dictate the beginning of a model's output, thereby shifting the attack paradigm from persuasion to direct state manipulation.In this paper, we present a systematic black-box security analysis of prefill-level jailbreak attacks. We categorize these new attacks and evaluate their effectiveness across fourteen language models. Our experiments show that prefill-level attacks achieve high success rates, with adaptive methods exceeding 99% on several models. Token-level probability analysis reveals that these attacks work through initial-state manipulation by changing the first-token probability from refusal to compliance.Furthermore, we show that prefill-level jailbreak can act as effective enhancers, increasing the success of existing prompt-level attacks by 10 to 15 percentage points. Our evaluation of several defense strategies indicates that conventional content filters offer limited protection. We find that a detection method focusing on the manipulative relationship between the prompt and the prefill is more effective. Our findings reveal a gap in current LLM safety alignment and highlight the need to address the prefill attack surface in future safety training.

cs.CR

Minors of a Class of Riordan Arrays Related to Weighted Partial Motzkin Paths

A partial Motzkin path is a path from $(0, 0)$ to $(n, k)$ in the $XOY$-plane that does not go below the $X$-axis and consists of up steps $U=(1, 1)$, down steps $D=(1, -1)$ and horizontal steps $H=(1, 0)$. A weighted partial Motzkin path is a partial Motzkin path with the weight assignment that all up steps and down steps are weighted by 1, the horizontal steps are endowed with a weight $x$ if they are lying on $X$-axis, and endowed with a weight $y$ if they are not lying on $X$-axis. Denote by $M_{n,k}(x, y)$ to be the weight function of all weighted partial Motzkin paths from $(0, 0)$ to $(n, k)$, and $\mathcal{M}=(M_{n,k}(x,y))_{n\geq k\geq 0}$ to be the infinite lower triangular matrices. In this paper, we consider the sums of minors of second order of the matrix $\mathcal{M}$, and obtain a lot of interesting determinant identities related to $\mathcal{M}$, which are proved by bijections using weighted partial Motzkin paths. When the weight parameters $(x, y)$ are specialized, several new identities are obtained related to some classical sequences involving Catalan numbers. Besides, in the alternating cases we also give some new explicit formulas for Catalan numbers.

math.CO