{"id":"https://openalex.org/W4416234161","doi":"https://doi.org/10.48550/arxiv.2511.08597","title":"Self-HarmLLM: Can Large Language Model Harm Itself?","display_name":"Self-HarmLLM: Can Large Language Model Harm Itself?","publication_year":2025,"publication_date":"2025-10-31","ids":{"openalex":"https://openalex.org/W4416234161","doi":"https://doi.org/10.48550/arxiv.2511.08597"},"language":null,"primary_location":{"id":"pmh:oai:arXiv.org:2511.08597","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.08597","pdf_url":"https://arxiv.org/pdf/2511.08597","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2511.08597","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Kim, Heehwan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kim, Heehwan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034729174","display_name":"S. Park","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Park, Sungjune","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5120353273","display_name":"Daeseon Choi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Choi, Daeseon","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7717000246047974,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7717000246047974,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.033399999141693115,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.017100000753998756,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/harm","display_name":"Harm","score":0.638700008392334},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.6305000185966492},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.4814000129699707},{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.46239998936653137},{"id":"https://openalex.org/keywords/ambiguity","display_name":"Ambiguity","score":0.45399999618530273},{"id":"https://openalex.org/keywords/block","display_name":"Block (permutation group theory)","score":0.3522000014781952}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6550999879837036},{"id":"https://openalex.org/C2777363581","wikidata":"https://www.wikidata.org/wiki/Q15098235","display_name":"Harm","level":2,"score":0.638700008392334},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.6305000185966492},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.4814000129699707},{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.46239998936653137},{"id":"https://openalex.org/C2780522230","wikidata":"https://www.wikidata.org/wiki/Q1140419","display_name":"Ambiguity","level":2,"score":0.45399999618530273},{"id":"https://openalex.org/C2777210771","wikidata":"https://www.wikidata.org/wiki/Q4927124","display_name":"Block (permutation group theory)","level":2,"score":0.3522000014781952},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.351500004529953},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.34450000524520874},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.32010000944137573},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30959999561309814},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.302700012922287},{"id":"https://openalex.org/C3019060180","wikidata":"https://www.wikidata.org/wiki/Q184199","display_name":"Automated method","level":2,"score":0.27410000562667847},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2702000141143799},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.2694999873638153},{"id":"https://openalex.org/C2779791154","wikidata":"https://www.wikidata.org/wiki/Q258040","display_name":"Model transformation","level":3,"score":0.2556000053882599}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2511.08597","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.08597","pdf_url":"https://arxiv.org/pdf/2511.08597","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2511.08597","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2511.08597","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2511.08597","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.08597","pdf_url":"https://arxiv.org/pdf/2511.08597","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"Language":[1],"Models":[2],"(LLMs)":[3],"are":[4],"generally":[5],"equipped":[6],"with":[7,180],"guardrails":[8],"to":[9,127,134,145,152],"block":[10],"the":[11,26,30,52,64,106,140,158,173,228,238],"generation":[12],"of":[13,32,105,184,234,240],"harmful":[14,27,84],"responses.":[15],"However,":[16],"existing":[17],"defenses":[18],"always":[19],"assume":[20],"that":[21,172,188,215],"an":[22,74,181],"external":[23],"attacker":[24],"crafts":[25],"query,":[28],"and":[29,115,120,132,143,150,167,211,237],"possibility":[31],"a":[33,38,57,68,93,102,202,207,221,231,241],"model's":[34],"own":[35],"output":[36],"becoming":[37],"new":[39,69],"attack":[40,223],"vector":[41],"has":[42],"not":[43,87,193],"been":[44],"sufficiently":[45],"explored.":[46],"In":[47],"this":[48,97,199],"study,":[49],"we":[50,170],"propose":[51],"Self-HarmLLM":[53],"scenario,":[54],"which":[55],"uses":[56],"Mitigated":[58],"Harmful":[59],"Query":[60],"(MHQ)":[61],"generated":[62],"by":[63],"same":[65,107],"model":[66],"as":[67],"input.":[70],"An":[71],"MHQ":[72,98],"is":[73,80,86,99,192,201],"ambiguous":[75],"query":[76,209],"whose":[77],"original":[78],"intent":[79],"preserved":[81],"while":[82],"its":[83],"nature":[85],"directly":[88],"exposed.":[89],"We":[90,109],"verified":[91],"whether":[92],"jailbreak":[94,136,154,178],"occurs":[95],"when":[96],"re-entered":[100],"into":[101],"separate":[103],"session":[104],"model.":[108],"conducted":[110],"experiments":[111],"on":[112,206],"GPT-3.5-turbo,":[113],"LLaMA3-8B-instruct,":[114],"DeepSeek-R1-Distill-Qwen-7B":[116],"under":[117],"Base,":[118],"Zero-shot,":[119],"Few-shot":[121,159],"conditions.":[122],"The":[123],"results":[124,226],"showed":[125],"up":[126,133,144,151],"52%":[128],"transformation":[129,147],"success":[130,137,148,155],"rate":[131,138,149,156],"33%":[135],"in":[139,157],"Zero-shot":[141],"condition,":[142],"65%":[146],"41%":[153],"condition.":[160],"By":[161],"performing":[162],"both":[163],"prefix-based":[164],"automated":[165,174,189],"evaluation":[166,175,190,244],"human":[168],"evaluation,":[169],"found":[171],"consistently":[176],"overestimated":[177],"success,":[179],"average":[182],"difference":[183],"52%.":[185],"This":[186],"indicates":[187],"alone":[191],"accurate":[194],"for":[195,230],"determining":[196],"harmfulness.":[197],"While":[198],"study":[200,204],"toy-level":[203],"based":[205],"limited":[208],"set":[210],"evaluators,":[212],"it":[213],"proves":[214],"our":[216],"method":[217],"can":[218],"still":[219],"be":[220],"valid":[222],"scenario.":[224],"These":[225],"suggest":[227],"need":[229],"fundamental":[232],"reconsideration":[233],"guardrail":[235],"design":[236],"establishment":[239],"more":[242],"robust":[243],"methodology.":[245]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-14T00:00:00"}
