{"id":"https://openalex.org/W7160896374","doi":"https://doi.org/10.48550/arxiv.2605.08778","title":"Not All Turns Matter: Credit Assignment for Multi-Turn Jailbreaking","display_name":"Not All Turns Matter: Credit Assignment for Multi-Turn Jailbreaking","publication_year":2026,"publication_date":"2026-05-09","ids":{"openalex":"https://openalex.org/W7160896374","doi":"https://doi.org/10.48550/arxiv.2605.08778"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.08778","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.08778","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.08778","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5005381054","display_name":"Zhida He","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"He, Zhida","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135911249","display_name":"Xiaoyu Wen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wen, Xiaoyu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135973353","display_name":"Han Qi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qi, Han","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135973810","display_name":"Ziyuan Zhou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Ziyuan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136001192","display_name":"Peng Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yu, Peng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135913144","display_name":"Xingcheng Xu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xu, Xingcheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135920152","display_name":"Dongrui Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Dongrui","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135923049","display_name":"Xia Hu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hu, Xia","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135922679","display_name":"Chaochao Lu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lu, Chaochao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135960275","display_name":"Qiaosheng Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Qiaosheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":10,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7847999930381775,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7847999930381775,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.03909999877214432,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.01940000057220459,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/trace","display_name":"TRACE (psycholinguistics)","score":0.6646000146865845},{"id":"https://openalex.org/keywords/reuse","display_name":"Reuse","score":0.6413000226020813},{"id":"https://openalex.org/keywords/outcome","display_name":"Outcome (game theory)","score":0.5534999966621399},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.5019000172615051},{"id":"https://openalex.org/keywords/baseline","display_name":"Baseline (sea)","score":0.48089998960494995}],"concepts":[{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.6646000146865845},{"id":"https://openalex.org/C206588197","wikidata":"https://www.wikidata.org/wiki/Q846574","display_name":"Reuse","level":2,"score":0.6413000226020813},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6186000108718872},{"id":"https://openalex.org/C148220186","wikidata":"https://www.wikidata.org/wiki/Q7111912","display_name":"Outcome (game theory)","level":2,"score":0.5534999966621399},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.5019000172615051},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.48089998960494995},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3855000138282776},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.33880001306533813},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.3127000033855438},{"id":"https://openalex.org/C168031717","wikidata":"https://www.wikidata.org/wiki/Q1530280","display_name":"Balance (ability)","level":2,"score":0.30730000138282776},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3050000071525574}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.08778","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.08778","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.08778","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.08778","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7964228987693787,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Deploying":[0],"LLMs":[1],"in":[2,48,70,78,153,164],"multi-turn":[3,18,49,96,136],"dialogues":[4],"facilitates":[5],"jailbreak":[6,19],"attacks":[7],"that":[8,36,45,147],"distribute":[9],"harmful":[10],"intent":[11],"across":[12],"seemingly":[13],"benign":[14],"turns.":[15],"Recent":[16],"training-based":[17],"methods":[20],"learn":[21],"long-horizon":[22],"attack":[23,165],"strategies":[24],"from":[25],"interaction":[26],"feedback,":[27],"but":[28],"often":[29],"rely":[30],"on":[31,116,141],"coarse":[32,57],"trajectory-level":[33],"outcome":[34,58],"signals":[35],"broadcast":[37],"uniformly":[38],"to":[39,66],"every":[40],"turn.":[41],"However,":[42],"we":[43,84,129],"find":[44],"turn-level":[46,103],"contributions":[47,104],"jailbreaking":[50],"are":[51],"non-uniform,":[52],"phase-dependent,":[53],"and":[54,73,119,143,156],"target-specific.":[55],"Such":[56],"supervision":[59],"induces":[60],"a":[61,87,160],"credit":[62,89,133],"assignment":[63,90],"problem,":[64],"leading":[65],"over-rewarding":[67],"redundant":[68],"turns":[69,77],"successful":[71,99],"trajectories":[72],"under-crediting":[74],"useful":[75],"intermediate":[76],"failed":[79,110],"ones.":[80],"To":[81],"address":[82],"this,":[83],"propose":[85],"TRACE,":[86],"turn-aware":[88],"framework":[91],"for":[92,109,135,181],"reinforcement":[93],"learning":[94],"(RL)-based":[95],"jailbreaking.":[97],"For":[98],"trajectories,":[100],"TRACE":[101,112,148],"estimates":[102],"via":[105],"leave-one-turn-out":[106],"semantic":[107,120],"masking;":[108],"ones,":[111],"assigns":[113],"penalties":[114],"based":[115],"prompt":[117],"harmfulness":[118],"relevance,":[121],"with":[122],"an":[123],"additional":[124],"local":[125],"refusal-aware":[126],"penalty.":[127],"Furthermore,":[128],"reuse":[130],"the":[131,169,176],"attack-side":[132],"signal":[134],"defense":[137,182],"alignment.":[138,183],"Extensive":[139],"experiments":[140],"open-source":[142],"closed-source":[144],"targets":[145],"show":[146],"achieves":[149],"strong":[150],"overall":[151],"performance":[152],"effectiveness,":[154],"transferability,":[155],"efficiency,":[157],"yielding":[158],"about":[159],"25%":[161],"relative":[162],"improvement":[163],"success":[166],"rate":[167],"over":[168],"strongest":[170],"RL":[171],"baseline":[172],"while":[173],"also":[174],"improving":[175],"safety-utility":[177],"balance":[178],"when":[179],"reused":[180]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-13T00:00:00"}
