{"id":"https://openalex.org/W7160632034","doi":"https://doi.org/10.48550/arxiv.2605.06605","title":"How Many Iterations to Jailbreak? Dynamic Budget Allocation for Multi-Turn LLM Evaluation","display_name":"How Many Iterations to Jailbreak? Dynamic Budget Allocation for Multi-Turn LLM Evaluation","publication_year":2026,"publication_date":"2026-05-07","ids":{"openalex":"https://openalex.org/W7160632034","doi":"https://doi.org/10.48550/arxiv.2605.06605"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.06605","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.06605","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.06605","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5135678010","display_name":"Shai Feldman","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Feldman, Shai","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135678063","display_name":"Yaniv Romano","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Romano, Yaniv","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.42149999737739563,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.42149999737739563,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.14329999685287476,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12488","display_name":"Mental Health via Writing","score":0.04690000042319298,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bounding-overwatch","display_name":"Bounding overwatch","score":0.7419000267982483},{"id":"https://openalex.org/keywords/censoring","display_name":"Censoring (clinical trials)","score":0.6990000009536743},{"id":"https://openalex.org/keywords/budget-constraint","display_name":"Budget constraint","score":0.5468999743461609},{"id":"https://openalex.org/keywords/conditional-independence","display_name":"Conditional independence","score":0.47049999237060547},{"id":"https://openalex.org/keywords/event","display_name":"Event (particle physics)","score":0.46970000863075256},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.42399999499320984},{"id":"https://openalex.org/keywords/variance","display_name":"Variance (accounting)","score":0.4009000062942505},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.39640000462532043},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.38679999113082886}],"concepts":[{"id":"https://openalex.org/C63584917","wikidata":"https://www.wikidata.org/wiki/Q333286","display_name":"Bounding overwatch","level":2,"score":0.7419000267982483},{"id":"https://openalex.org/C137668524","wikidata":"https://www.wikidata.org/wiki/Q189813","display_name":"Censoring (clinical trials)","level":2,"score":0.6990000009536743},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6809999942779541},{"id":"https://openalex.org/C8505890","wikidata":"https://www.wikidata.org/wiki/Q605095","display_name":"Budget constraint","level":2,"score":0.5468999743461609},{"id":"https://openalex.org/C79772020","wikidata":"https://www.wikidata.org/wiki/Q5159264","display_name":"Conditional independence","level":2,"score":0.47049999237060547},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.46970000863075256},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.4528000056743622},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.42399999499320984},{"id":"https://openalex.org/C196083921","wikidata":"https://www.wikidata.org/wiki/Q7915758","display_name":"Variance (accounting)","level":2,"score":0.4009000062942505},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.39640000462532043},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.38679999113082886},{"id":"https://openalex.org/C2776036281","wikidata":"https://www.wikidata.org/wiki/Q48769818","display_name":"Constraint (computer-aided design)","level":2,"score":0.3813000023365021},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.37700000405311584},{"id":"https://openalex.org/C77553402","wikidata":"https://www.wikidata.org/wiki/Q13222579","display_name":"Upper and lower bounds","level":2,"score":0.36809998750686646},{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.3337000012397766},{"id":"https://openalex.org/C774472","wikidata":"https://www.wikidata.org/wiki/Q6760393","display_name":"Margin (machine learning)","level":2,"score":0.31380000710487366},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.3133000135421753},{"id":"https://openalex.org/C175291020","wikidata":"https://www.wikidata.org/wiki/Q1156822","display_name":"Offset (computer science)","level":2,"score":0.302700012922287},{"id":"https://openalex.org/C52740198","wikidata":"https://www.wikidata.org/wiki/Q1539564","display_name":"Importance sampling","level":3,"score":0.2799000144004822},{"id":"https://openalex.org/C2776502983","wikidata":"https://www.wikidata.org/wiki/Q690182","display_name":"Contrast (vision)","level":2,"score":0.27869999408721924},{"id":"https://openalex.org/C179799912","wikidata":"https://www.wikidata.org/wiki/Q205084","display_name":"Computational complexity theory","level":2,"score":0.273499995470047},{"id":"https://openalex.org/C55282118","wikidata":"https://www.wikidata.org/wiki/Q252683","display_name":"Snapshot (computer storage)","level":2,"score":0.267300009727478},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.2587999999523163},{"id":"https://openalex.org/C29202148","wikidata":"https://www.wikidata.org/wiki/Q287260","display_name":"Resource allocation","level":2,"score":0.25529998540878296},{"id":"https://openalex.org/C35651441","wikidata":"https://www.wikidata.org/wiki/Q625303","display_name":"Independence (probability theory)","level":2,"score":0.25279998779296875}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.06605","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.06605","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.06605","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.06605","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"sustainable_development_goals":[{"score":0.44290825724601746,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Evaluating":[0],"and":[1,43,119,132,207,216],"predicting":[2],"the":[3,62,68,95,105,116,127,153,157,163,189,227,238],"performance":[4],"of":[5,64,70,156,183],"large":[6],"language":[7],"models":[8],"(LLMs)":[9],"in":[10,81,107],"multi-turn":[11,82,108],"conversational":[12],"settings":[13],"is":[14,79,145],"critical":[15],"yet":[16],"computationally":[17],"expensive;":[18],"key":[19,142],"events":[20,39],"--":[21,31],"e.g.,":[22],"jailbreaks":[23],"or":[24],"successful":[25],"task":[26,200],"completion":[27],"by":[28,136],"an":[29],"agent":[30],"often":[32],"emerge":[33],"only":[34],"after":[35],"repeated":[36],"interactions.":[37,110],"These":[38],"might":[40],"be":[41,176],"rare,":[42],"under":[44,192],"any":[45],"feasible":[46],"computational":[47],"budget,":[48],"remain":[49],"unobserved.":[50],"Recent":[51],"conformal":[52,138],"survival":[53,139],"frameworks":[54],"construct":[55],"reliable":[56],"lower":[57,231],"predictive":[58],"bounds":[59],"(LPBs)":[60],"on":[61,74],"number":[63],"iterations":[65],"to":[66,178,226],"trigger":[67],"event":[69,133],"interest,":[71],"but":[72],"rely":[73],"static":[75,234],"budget":[76,100,117,239],"allocation":[77,101],"that":[78,113,150,220],"inefficient":[80],"setups.":[83],"To":[84],"address":[85],"this,":[86],"we":[87],"introduce":[88],"\\emph{Dynamic":[89],"Allocation":[90],"via":[91],"PRojected":[92],"Optimization}":[93],"(DAPRO),":[94],"first":[96],"theoretically":[97],"valid":[98],"dynamic":[99],"framework":[102],"for":[103],"bounding":[104],"time-to-event":[106],"LLM":[109],"We":[111],"prove":[112],"DAPRO":[114,174,221],"satisfies":[115],"constraint":[118],"provides":[120],"distribution-free,":[121],"finite-sample":[122],"coverage":[123,148,224],"guarantees":[124,169],"without":[125],"requiring":[126],"conditional":[128],"independence":[129],"between":[130],"censoring":[131,159],"times":[134],"assumed":[135],"prior":[137,171],"approaches.":[140],"A":[141],"theoretical":[143],"contribution":[144],"a":[146],"novel":[147],"bound":[149],"scales":[151],"with":[152,230],"square":[154],"root":[155],"mean":[158],"weight":[160],"rather":[161],"than":[162,170,233],"worst-case":[164],"weight,":[165],"yielding":[166],"provably":[167],"tighter":[168],"work.":[172],"Furthermore,":[173],"can":[175],"employed":[177],"obtain":[179],"unbiased,":[180],"low-variance":[181],"estimates":[182],"population-level":[184],"evaluation":[185],"metrics,":[186],"such":[187,212],"as":[188,213],"jailbreak":[190],"rate,":[191],"limited":[193],"computing":[194],"resources.":[195],"Comprehensive":[196],"experiments":[197],"across":[198],"agentic":[199],"success,":[201],"adversarial":[202],"jailbreaks,":[203],"toxic":[204],"content":[205],"generation,":[206],"RAG":[208],"hallucinations":[209],"using":[210],"LLMs":[211],"Llama":[214],"3.1":[215],"Qwen":[217],"2.5":[218],"demonstrate":[219],"consistently":[222],"achieves":[223],"closer":[225],"nominal":[228],"level":[229],"variance":[232],"baselines,":[235],"while":[236],"satisfying":[237],"constraint.":[240]},"counts_by_year":[],"updated_date":"2026-07-01T06:00:48.157686","created_date":"2026-05-09T00:00:00"}
