{"id":"https://openalex.org/W4409657133","doi":"https://doi.org/10.1145/3696410.3714654","title":"Dual Intention Escape: Penetrating and Toxic Jailbreak Attack against Large Language Models","display_name":"Dual Intention Escape: Penetrating and Toxic Jailbreak Attack against Large Language Models","publication_year":2025,"publication_date":"2025-04-22","ids":{"openalex":"https://openalex.org/W4409657133","doi":"https://doi.org/10.1145/3696410.3714654"},"language":"en","primary_location":{"id":"doi:10.1145/3696410.3714654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714654","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714654","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5106668812","display_name":"Yanni Xue","orcid":null},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yanni Xue","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0002-8015-0430","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031116553","display_name":"Jiakai Wang","orcid":"https://orcid.org/0000-0001-5884-3412"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jiakai Wang","raw_affiliation_strings":["Zhongguancun Laboratory, Beijing, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-5884-3412","affiliations":[{"raw_affiliation_string":"Zhongguancun Laboratory, Beijing, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103163232","display_name":"Zixin Yin","orcid":"https://orcid.org/0000-0002-2129-9182"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zixin Yin","raw_affiliation_strings":["Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-2129-9182","affiliations":[{"raw_affiliation_string":"Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030290826","display_name":"Yuqing Ma","orcid":"https://orcid.org/0000-0003-1936-9396"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuqing Ma","raw_affiliation_strings":["Institute of Artificial Intelligence, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0003-1936-9396","affiliations":[{"raw_affiliation_string":"Institute of Artificial Intelligence, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044945190","display_name":"Haotong Qin","orcid":"https://orcid.org/0000-0001-7391-7539"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Haotong Qin","raw_affiliation_strings":["ETH Zurich, Zurich, Switzerland"],"raw_orcid":"https://orcid.org/0000-0001-7391-7539","affiliations":[{"raw_affiliation_string":"ETH Zurich, Zurich, Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039889916","display_name":"Renshuai Tao","orcid":"https://orcid.org/0000-0001-5695-2009"},"institutions":[{"id":"https://openalex.org/I21193070","display_name":"Beijing Jiaotong University","ror":"https://ror.org/01yj56c84","country_code":"CN","type":"education","lineage":["https://openalex.org/I21193070"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Renshuai Tao","raw_affiliation_strings":["Institute of Information Science, Beijing Jiaotong University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-5695-2009","affiliations":[{"raw_affiliation_string":"Institute of Information Science, Beijing Jiaotong University, Beijing, China","institution_ids":["https://openalex.org/I21193070"]}]},{"author_position":"last","author":{"id":null,"display_name":"Xianglong Liu","orcid":"https://orcid.org/0000-0002-7618-3275"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xianglong Liu","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China, Zhongguancun Laboratory, Beijing, China, and Institute of Data Space, Hefei Comprehensive National Science Center, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0002-7618-3275","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China, Zhongguancun Laboratory, Beijing, China, and Institute of Data Space, Hefei Comprehensive National Science Center, Hefei, China","institution_ids":["https://openalex.org/I82880672"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5106668812"],"corresponding_institution_ids":["https://openalex.org/I82880672"],"apc_list":null,"apc_paid":null,"fwci":4.2811,"has_fulltext":true,"cited_by_count":2,"citation_normalized_percentile":{"value":0.93559821,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"863","last_page":"871"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.9739999771118164,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9265999794006348,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/dual","display_name":"Dual (grammatical number)","score":0.6503221988677979},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5978280305862427},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5030352473258972},{"id":"https://openalex.org/keywords/astrobiology","display_name":"Astrobiology","score":0.3493584394454956},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.3324083983898163},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.11403694748878479}],"concepts":[{"id":"https://openalex.org/C2780980858","wikidata":"https://www.wikidata.org/wiki/Q110022","display_name":"Dual (grammatical number)","level":2,"score":0.6503221988677979},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5978280305862427},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5030352473258972},{"id":"https://openalex.org/C87355193","wikidata":"https://www.wikidata.org/wiki/Q411","display_name":"Astrobiology","level":1,"score":0.3493584394454956},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3324083983898163},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.11403694748878479},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C124952713","wikidata":"https://www.wikidata.org/wiki/Q8242","display_name":"Literature","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3696410.3714654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714654","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3696410.3714654","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714654","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714654","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.7799999713897705,"display_name":"Gender equality","id":"https://metadata.un.org/sdg/5"}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4409657133.pdf","grobid_xml":"https://content.openalex.org/works/W4409657133.grobid-xml"},"referenced_works_count":12,"referenced_works":["https://openalex.org/W2990138404","https://openalex.org/W3048972258","https://openalex.org/W3173777717","https://openalex.org/W4366588626","https://openalex.org/W4385571034","https://openalex.org/W4389617257","https://openalex.org/W4400315206","https://openalex.org/W4402683786","https://openalex.org/W6600018615","https://openalex.org/W6600042794","https://openalex.org/W6603527449","https://openalex.org/W6608160362"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W2952265190"],"abstract_inverted_index":{"Recently,":[0],"the":[1,32,38,41,71,74,107,112,119,128,138,145,152,163,171,183,192],"jailbreak":[2,86],"attack,":[3],"which":[4],"generates":[5],"adversarial":[6],"prompts":[7,51,95],"to":[8,18,27,30,57,89,96,99,151,182,189,200],"bypass":[9],"safety":[10],"measures":[11],"and":[12,64,93,132,155,222],"mislead":[13],"large":[14],"language":[15],"models":[16],"(LLMs)":[17],"output":[19,100,193],"harmful":[20,67,101,120,153,190],"answers,":[21],"has":[22],"attracted":[23],"extensive":[24,210],"interest":[25],"due":[26],"its":[28],"potential":[29],"reveal":[31],"vulnerabilities":[33],"of":[34,40,76,186,195],"LLMs.":[35],"However,":[36],"ignoring":[37],"exploitation":[39],"characteristics":[42],"in":[43,73,175],"intention":[44,83,121,126,134,140,154],"understanding,":[45],"existing":[46],"studies":[47],"could":[48,218],"only":[49],"generate":[50,90],"with":[52],"weak":[53],"attacking":[54],"ability,":[55],"failing":[56],"evade":[58],"defenses":[59],"(e.g.,":[60],"sensitive":[61],"word":[62],"detect)":[63],"causing":[65],"malice(e.g.,":[66],"outputs).":[68],"Motivated":[69],"by":[70,106,127],"mechanism":[72,174],"psychology":[75],"human":[77],"misjudgment,":[78],"we":[79,110,161],"propose":[80,162],"a":[81,123,176],"dual":[82],"escape":[84],"(DIE)":[85],"attack":[87],"framework":[88],"more":[91,202,206],"stealthy":[92],"toxic":[94],"deceive":[97],"LLMs":[98,146,196],"content.":[102],"For":[103,159],"stealthiness,":[104],"inspired":[105],"anchoring":[108],"effect,":[109],"designed":[111],"Intention-anchored":[113],"Malicious":[114,165],"Concealment(IMC)":[115],"module":[116,168],"that":[117,216],"hides":[118],"behind":[122],"generated":[124],"anchor":[125,139],"recursive":[129],"decomposition":[130],"block":[131],"contrary":[133],"nesting":[135],"block.":[136],"Since":[137],"will":[141,197],"be":[142,198],"received":[143],"first,":[144],"might":[147],"pay":[148],"less":[149],"attention":[150],"enter":[156],"response":[157],"status.":[158],"toxicity,":[160],"Intention-reinforced":[164],"Inducement":[166],"(IMI)":[167],"based":[169],"on":[170],"availability":[172],"bias":[173],"progressive":[177],"malicious":[178],"prompting":[179],"approach.":[180],"Due":[181],"ongoing":[184],"emergence":[185],"statements":[187],"correlated":[188],"intentions,":[191,204],"content":[194],"closer":[199],"these":[201],"accessible":[203],"i.e.,":[205],"toxic.":[207],"We":[208],"conducted":[209],"experiments":[211],"under":[212],"black-box":[213],"settings,":[214],"supporting":[215],"DIE":[217],"achieve":[219],"100%":[220],"ASR-R":[221],"92.9%":[223],"ASR-G":[224],"against":[225],"GPT3.5-turbo.":[226]},"counts_by_year":[{"year":2026,"cited_by_count":2}],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2025-10-10T00:00:00"}
