{"id":"https://openalex.org/W7160647729","doi":"https://doi.org/10.48550/arxiv.2605.05630","title":"One Turn Too Late: Response-Aware Defense Against Hidden Malicious Intent in Multi-Turn Dialogue","display_name":"One Turn Too Late: Response-Aware Defense Against Hidden Malicious Intent in Multi-Turn Dialogue","publication_year":2026,"publication_date":"2026-05-07","ids":{"openalex":"https://openalex.org/W7160647729","doi":"https://doi.org/10.48550/arxiv.2605.05630"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.05630","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.05630","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.05630","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5024324156","display_name":"Xinjie Shen","orcid":"https://orcid.org/0009-0004-9176-5400"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shen, Xinjie","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135728619","display_name":"Rongzhe Wei","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wei, Rongzhe","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102687891","display_name":"Peizhi Niu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Niu, Peizhi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135669077","display_name":"Haoyu Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Haoyu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135686487","display_name":"Ruihan Wu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wu, Ruihan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135639750","display_name":"Eli Chien","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chien, Eli","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135677941","display_name":"Bo Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Bo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135703703","display_name":"Pin-Yu Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Pin-Yu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135679460","display_name":"Pan Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Pan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.590399980545044,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.590399980545044,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.07900000363588333,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.041999999433755875,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.6194000244140625},{"id":"https://openalex.org/keywords/point","display_name":"Point (geometry)","score":0.4399999976158142},{"id":"https://openalex.org/keywords/intervention","display_name":"Intervention (counseling)","score":0.362199991941452},{"id":"https://openalex.org/keywords/exploratory-analysis","display_name":"Exploratory analysis","score":0.36010000109672546},{"id":"https://openalex.org/keywords/closure","display_name":"Closure (psychology)","score":0.35910001397132874},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.2946000099182129}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7365999817848206},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6920999884605408},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.6194000244140625},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.46459999680519104},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.4399999976158142},{"id":"https://openalex.org/C2780665704","wikidata":"https://www.wikidata.org/wiki/Q959298","display_name":"Intervention (counseling)","level":2,"score":0.362199991941452},{"id":"https://openalex.org/C3018260909","wikidata":"https://www.wikidata.org/wiki/Q1322871","display_name":"Exploratory analysis","level":2,"score":0.36010000109672546},{"id":"https://openalex.org/C146834321","wikidata":"https://www.wikidata.org/wiki/Q2979672","display_name":"Closure (psychology)","level":2,"score":0.35910001397132874},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.2946000099182129},{"id":"https://openalex.org/C2992444157","wikidata":"https://www.wikidata.org/wiki/Q775079","display_name":"Single point","level":3,"score":0.2937999963760376},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.28439998626708984},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.28139999508857727},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.27950000762939453},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2709999978542328},{"id":"https://openalex.org/C85973986","wikidata":"https://www.wikidata.org/wiki/Q1091731","display_name":"Exploratory research","level":2,"score":0.2644999921321869},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2522999942302704}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.05630","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.05630","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.05630","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.05630","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7657269835472107,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Hidden":[0],"malicious":[1],"intent":[2,32],"in":[3,22,55,153],"multi-turn":[4],"dialogue":[5],"poses":[6],"a":[7,19,23,144],"growing":[8],"threat":[9],"to":[10,50,85],"deployed":[11],"large":[12],"language":[13],"models":[14,44],"(LLMs).":[15],"Rather":[16],"than":[17],"exposing":[18],"harmful":[20,87],"objective":[21,90],"single":[24],"prompt,":[25],"increasingly":[26],"capable":[27],"attackers":[28],"can":[29],"distribute":[30],"their":[31],"across":[33,164],"multiple":[34],"benign-looking":[35],"turns.":[36,137],"Recent":[37],"studies":[38],"show":[39,139],"that":[40,95,140],"even":[41],"modern":[42],"commercial":[43],"with":[45],"advanced":[46],"guardrails":[47],"remain":[48],"vulnerable":[49],"such":[51],"attacks":[52],"despite":[53],"advances":[54],"safety":[56],"alignment":[57],"and":[58,113,131,168],"external":[59],"guardrails.":[60],"In":[61],"this":[62,66],"work,":[63],"we":[64,115],"address":[65],"challenge":[67],"by":[68],"detecting":[69],"the":[70,76,81,97,117,134],"earliest":[71,135],"turn":[72],"at":[73,175],"which":[74,122,148],"delivering":[75],"candidate":[77],"response":[78],"would":[79],"make":[80],"accumulated":[82],"interaction":[83],"sufficient":[84],"enable":[86,143],"action.":[88],"This":[89],"requires":[91],"precise":[92],"turn-level":[93,145],"intervention":[94],"identifies":[96],"harm-enabling":[98,136],"closure":[99],"point":[100],"while":[101,156],"avoiding":[102],"premature":[103],"refusal":[104],"of":[105,133],"benign":[106,128],"exploratory":[107],"conversations.":[108],"To":[109],"further":[110,162],"support":[111],"training":[112],"evaluation,":[114],"construct":[116],"Multi-Turn":[118],"Intent":[119],"Dataset":[120],"(MTID),":[121],"contains":[123],"branching":[124],"attack":[125],"rollouts,":[126],"matched":[127],"hard":[129],"negatives,":[130],"annotations":[132],"We":[138],"MTID":[141],"helps":[142],"monitor":[146],"TurnGate,":[147],"substantially":[149],"outperforms":[150],"existing":[151],"baselines":[152],"harmful-intent":[154],"detection":[155],"maintaining":[157],"low":[158],"over-refusal":[159],"rates.":[160],"TurnGate":[161],"generalizes":[163],"domains,":[165],"attacker":[166],"pipelines,":[167],"target":[169],"models.":[170],"Our":[171],"code":[172],"is":[173],"available":[174],"https://github.com/Graph-COM/TurnGate.":[176]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-09T00:00:00"}
