{"id":"https://openalex.org/W7140182980","doi":"https://doi.org/10.1109/lsp.2026.3677330","title":"GRA: Graph-Based Role-Playing Attack for Single-Turn Jailbreak","display_name":"GRA: Graph-Based Role-Playing Attack for Single-Turn Jailbreak","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7140182980","doi":"https://doi.org/10.1109/lsp.2026.3677330"},"language":null,"primary_location":{"id":"doi:10.1109/lsp.2026.3677330","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lsp.2026.3677330","pdf_url":null,"source":{"id":"https://openalex.org/S120629676","display_name":"IEEE Signal Processing Letters","issn_l":"1070-9908","issn":["1070-9908","1558-2361"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Signal Processing Letters","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Anda Liu","orcid":"https://orcid.org/0009-0009-0447-7635"},"institutions":[{"id":"https://openalex.org/I52158045","display_name":"China Agricultural University","ror":"https://ror.org/04v3ywz14","country_code":"CN","type":"education","lineage":["https://openalex.org/I52158045"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Anda Liu","raw_affiliation_strings":["College of Information and Electrical Engineering, China Agricultural University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0009-0447-7635","affiliations":[{"raw_affiliation_string":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China","institution_ids":["https://openalex.org/I52158045"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Zhengxian Wu","orcid":"https://orcid.org/0000-0001-7957-0441"},"institutions":[{"id":"https://openalex.org/I52158045","display_name":"China Agricultural University","ror":"https://ror.org/04v3ywz14","country_code":"CN","type":"education","lineage":["https://openalex.org/I52158045"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhengxian Wu","raw_affiliation_strings":["College of Information and Electrical Engineering, China Agricultural University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-7957-0441","affiliations":[{"raw_affiliation_string":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China","institution_ids":["https://openalex.org/I52158045"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Juan Wen","orcid":"https://orcid.org/0000-0002-4199-2988"},"institutions":[{"id":"https://openalex.org/I52158045","display_name":"China Agricultural University","ror":"https://ror.org/04v3ywz14","country_code":"CN","type":"education","lineage":["https://openalex.org/I52158045"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Juan Wen","raw_affiliation_strings":["College of Information and Electrical Engineering, China Agricultural University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-4199-2988","affiliations":[{"raw_affiliation_string":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China","institution_ids":["https://openalex.org/I52158045"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Wanli Peng","orcid":null},"institutions":[{"id":"https://openalex.org/I52158045","display_name":"China Agricultural University","ror":"https://ror.org/04v3ywz14","country_code":"CN","type":"education","lineage":["https://openalex.org/I52158045"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wanli Peng","raw_affiliation_strings":["College of Information and Electrical Engineering, China Agricultural University, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China","institution_ids":["https://openalex.org/I52158045"]}]},{"author_position":"last","author":{"id":null,"display_name":"Changtong Dou","orcid":"https://orcid.org/0009-0007-6288-6117"},"institutions":[{"id":"https://openalex.org/I52158045","display_name":"China Agricultural University","ror":"https://ror.org/04v3ywz14","country_code":"CN","type":"education","lineage":["https://openalex.org/I52158045"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Changtong Dou","raw_affiliation_strings":["College of Information and Electrical Engineering, China Agricultural University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0007-6288-6117","affiliations":[{"raw_affiliation_string":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China","institution_ids":["https://openalex.org/I52158045"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.40434182,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"33","issue":null,"first_page":"1536","last_page":"1540"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.14509999752044678,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.14509999752044678,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.08269999921321869,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11147","display_name":"Misinformation and Its Impacts","score":0.07959999889135361,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.715499997138977},{"id":"https://openalex.org/keywords/deception","display_name":"Deception","score":0.7063999772071838},{"id":"https://openalex.org/keywords/persuasion","display_name":"Persuasion","score":0.5720000267028809},{"id":"https://openalex.org/keywords/mechanism","display_name":"Mechanism (biology)","score":0.3824000060558319},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.37400001287460327},{"id":"https://openalex.org/keywords/task-analysis","display_name":"Task analysis","score":0.352400004863739},{"id":"https://openalex.org/keywords/electronic-mail","display_name":"Electronic mail","score":0.3224000036716461},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.30809998512268066}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7918000221252441},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.715499997138977},{"id":"https://openalex.org/C2779267917","wikidata":"https://www.wikidata.org/wiki/Q170028","display_name":"Deception","level":2,"score":0.7063999772071838},{"id":"https://openalex.org/C2781310500","wikidata":"https://www.wikidata.org/wiki/Q1231428","display_name":"Persuasion","level":2,"score":0.5720000267028809},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5654000043869019},{"id":"https://openalex.org/C89611455","wikidata":"https://www.wikidata.org/wiki/Q6804646","display_name":"Mechanism (biology)","level":2,"score":0.3824000060558319},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.37400001287460327},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3716999888420105},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.352400004863739},{"id":"https://openalex.org/C3020028006","wikidata":"https://www.wikidata.org/wiki/Q9158","display_name":"Electronic mail","level":2,"score":0.3224000036716461},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.30809998512268066},{"id":"https://openalex.org/C2780861071","wikidata":"https://www.wikidata.org/wiki/Q1062934","display_name":"Character (mathematics)","level":2,"score":0.2987000048160553},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.28299999237060547},{"id":"https://openalex.org/C169900460","wikidata":"https://www.wikidata.org/wiki/Q2200417","display_name":"Cognition","level":2,"score":0.27630001306533813},{"id":"https://openalex.org/C4727928","wikidata":"https://www.wikidata.org/wiki/Q17164759","display_name":"Social network (sociolinguistics)","level":3,"score":0.26930001378059387},{"id":"https://openalex.org/C2778717966","wikidata":"https://www.wikidata.org/wiki/Q4189076","display_name":"Protection mechanism","level":3,"score":0.26179999113082886},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.26170000433921814},{"id":"https://openalex.org/C161407221","wikidata":"https://www.wikidata.org/wiki/Q4382939","display_name":"Cognitive model","level":3,"score":0.25529998540878296},{"id":"https://openalex.org/C114713312","wikidata":"https://www.wikidata.org/wiki/Q7551269","display_name":"Social network analysis","level":3,"score":0.25119999051094055},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.25060001015663147}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/lsp.2026.3677330","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lsp.2026.3677330","pdf_url":null,"source":{"id":"https://openalex.org/S120629676","display_name":"IEEE Signal Processing Letters","issn_l":"1070-9908","issn":["1070-9908","1558-2361"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Signal Processing Letters","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.75776207447052,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G3352639443","display_name":null,"funder_award_id":"62402117","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G679331998","display_name":null,"funder_award_id":"62272463","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"Language":[1],"Models":[2],"(LLMs)":[3],"have":[4,48],"achieved":[5,53],"impressive":[6],"capabilities":[7],"in":[8,56,115],"diverse":[9],"applications":[10],"but":[11],"remain":[12],"vulnerable":[13],"to":[14],"jailbreak":[15],"attacks":[16,22],"despite":[17],"advanced":[18,173],"safety":[19],"alignments.":[20],"Existing":[21],"primarily":[23],"fall":[24],"into":[25],"optimization-based":[26],"methods,":[27,34],"which":[28,35,101,111,129],"require":[29],"white-box":[30],"access,":[31],"and":[32,52,149,163],"prompt-based":[33],"rely":[36],"on":[37,143],"surface-level":[38],"deception":[39],"strategies":[40],"like":[41],"persuasion":[42],"or":[43],"obfuscation.":[44],"While":[45],"these":[46,70],"approaches":[47],"exposed":[49],"significant":[50],"vulnerabilities":[51],"notable":[54],"success":[55],"earlier":[57],"model":[58,114],"generations,":[59],"they":[60],"are":[61],"increasingly":[62],"mitigated":[63],"by":[64,91],"robust":[65],"alignment":[66],"techniques.":[67],"To":[68],"overcome":[69],"challenges,":[71],"we":[72],"propose":[73],"GRA,":[74],"a":[75,86,116,164],"graph-based":[76],"role-playing":[77],"attack":[78],"framework":[79],"for":[80],"single-turn":[81],"black-box":[82],"jailbreaking.":[83],"GRA":[84,153],"introduces":[85],"mechanism":[87],"of":[88,161,167],"cognitive":[89],"inertia":[90],"synergizing":[92],"three":[93],"components:":[94],"(1)":[95],"<italic":[96,106,123],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[97,107,124],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Domain-Aligned":[98],"Character":[99],"Matching</i>,":[100],"dynamically":[102],"selects":[103],"adversarial":[104],"personas;(2)":[105],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Graph-based":[108],"Attention":[109],"Redirection</i>,":[110],"anchors":[112],"the":[113,171],"benign":[117],"social":[118],"network":[119],"analysis":[120],"task;":[121],"and(3)":[122],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Structured":[125],"Malicious":[126],"Content":[127],"Encoding</i>,":[128],"injects":[130],"malicious":[131],"goals":[132],"as":[133],"isomorphic":[134],"structural":[135],"instructions,":[136],"effectively":[137],"bypassing":[138],"content-based":[139],"filters.":[140],"Extensive":[141],"evaluations":[142],"eight":[144],"state-of-the-art":[145],"models":[146],"(including":[147],"GPT-5":[148],"Claude-4)":[150],"demonstrate":[151],"that":[152],"achieves":[154],"an":[155],"average":[156],"Attack":[157],"Success":[158],"Rate":[159],"(ASR)":[160],"85.38%":[162],"StrongREJECT":[165],"Score":[166],"0.690,":[168],"significantly":[169],"outperforming":[170],"most":[172],"attacks.":[174]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-25T00:00:00"}
