{"id":"https://openalex.org/W7161970319","doi":"https://doi.org/10.48550/arxiv.2605.21362","title":"LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models","display_name":"LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models","publication_year":2026,"publication_date":"2026-05-20","ids":{"openalex":"https://openalex.org/W7161970319","doi":"https://doi.org/10.48550/arxiv.2605.21362"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.21362","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21362","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.21362","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5011490332","display_name":"Abdullah Al Nomaan Nafi","orcid":"https://orcid.org/0000-0002-9032-7175"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Nafi, Abdullah Al Nomaan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026365218","display_name":"Fnu Suya","orcid":"https://orcid.org/0000-0002-3334-6257"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Suya, Fnu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136615052","display_name":"Swarup Bhunia","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bhunia, Swarup","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5136720918","display_name":"Prabuddha Chakraborty","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chakraborty, Prabuddha","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7795000076293945,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7795000076293945,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.046799998730421066,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.037300001829862595,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6046000123023987},{"id":"https://openalex.org/keywords/tree","display_name":"Tree (set theory)","score":0.5339000225067139},{"id":"https://openalex.org/keywords/function","display_name":"Function (biology)","score":0.48019999265670776},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.4203999936580658},{"id":"https://openalex.org/keywords/harm","display_name":"Harm","score":0.4147000014781952},{"id":"https://openalex.org/keywords/composition","display_name":"Composition (language)","score":0.39309999346733093},{"id":"https://openalex.org/keywords/genetic-algorithm","display_name":"Genetic algorithm","score":0.34369999170303345},{"id":"https://openalex.org/keywords/base","display_name":"Base (topology)","score":0.3416999876499176}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7462000250816345},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6046000123023987},{"id":"https://openalex.org/C113174947","wikidata":"https://www.wikidata.org/wiki/Q2859736","display_name":"Tree (set theory)","level":2,"score":0.5339000225067139},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4959000051021576},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.48019999265670776},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.4203999936580658},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.41990000009536743},{"id":"https://openalex.org/C2777363581","wikidata":"https://www.wikidata.org/wiki/Q15098235","display_name":"Harm","level":2,"score":0.4147000014781952},{"id":"https://openalex.org/C40231798","wikidata":"https://www.wikidata.org/wiki/Q1333743","display_name":"Composition (language)","level":2,"score":0.39309999346733093},{"id":"https://openalex.org/C8880873","wikidata":"https://www.wikidata.org/wiki/Q187787","display_name":"Genetic algorithm","level":2,"score":0.34369999170303345},{"id":"https://openalex.org/C42058472","wikidata":"https://www.wikidata.org/wiki/Q810214","display_name":"Base (topology)","level":2,"score":0.3416999876499176},{"id":"https://openalex.org/C176066374","wikidata":"https://www.wikidata.org/wiki/Q629118","display_name":"Fitness function","level":3,"score":0.33469998836517334},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3257000148296356},{"id":"https://openalex.org/C501734568","wikidata":"https://www.wikidata.org/wiki/Q42918","display_name":"Mutation","level":3,"score":0.31049999594688416},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.30230000615119934},{"id":"https://openalex.org/C68784500","wikidata":"https://www.wikidata.org/wiki/Q1570691","display_name":"Adaptive behavior","level":2,"score":0.2793000042438507},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.27140000462532043},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.2703000009059906},{"id":"https://openalex.org/C2775955345","wikidata":"https://www.wikidata.org/wiki/Q7449071","display_name":"Semantic mapping","level":2,"score":0.2648000121116638},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2567000091075897},{"id":"https://openalex.org/C2775945657","wikidata":"https://www.wikidata.org/wiki/Q381442","display_name":"Structuring","level":2,"score":0.25589999556541443}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.21362","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21362","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.21362","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21362","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.5696010589599609}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Jailbreak":[0],"attacks":[1,89],"expose":[2],"a":[3,32,80,103,115,119,124,136,244],"persistent":[4],"gap":[5],"between":[6],"the":[7,55,129,201],"intended":[8],"safety":[9],"behavior":[10,18],"of":[11,172],"aligned":[12],"large":[13],"language":[14],"models":[15,61],"and":[16,50,62,94,111,123,135,177,189,227],"their":[17],"under":[19,174,179,223],"adversarial":[20],"prompting.":[21],"Existing":[22],"automated":[23],"methods":[24],"are":[25,184],"increasingly":[26],"effective":[27],"but":[28],"each":[29,99],"commits":[30],"to":[31],"single":[33,52,120],"attack":[34,169],"family":[35,53],"(e.g.,":[36],"one":[37,40,43,47],"refinement":[38],"loop,":[39],"tree":[41],"search,":[42],"mutation":[44],"space,":[45],"or":[46],"strategy":[48],"library)":[49],"no":[51],"dominates:":[54],"best-performing":[56],"method":[57],"shifts":[58],"across":[59,154,239],"target":[60,100,133,163,217],"harm":[63],"categories,":[64,156],"suggesting":[65],"complementary":[66],"strengths":[67],"that":[68,83,236],"per-prompt":[69],"composition":[70,116,238],"could":[71],"exploit.":[72],"We":[73],"introduce":[74],"LASH":[75,106,159,165,205,219],"(LLM":[76],"Adaptive":[77],"Semantic":[78],"Hybridization),":[79],"black-box":[81,132,248],"framework":[82],"treats":[84],"outputs":[85],"from":[86],"multiple":[87],"base":[88],"as":[90],"reusable":[91],"seed":[92,104,109],"prompts":[93,153],"adaptively":[95],"composes":[96],"them":[97],"for":[98,187,196,247],"request.":[101,204],"Given":[102],"pool,":[105],"searches":[107],"over":[108],"subsets":[110],"softmax-normalized":[112],"mixture":[113],"weights;":[114],"module":[117],"synthesizes":[118],"candidate":[121],"prompt,":[122],"derivative-free":[125],"genetic":[126],"optimizer":[127],"updates":[128],"weights":[130],"using":[131],"feedback":[134],"two-stage":[137,180],"fitness":[138],"function":[139],"combining":[140],"keyword-based":[141,175],"refusal":[142],"detection":[143],"with":[144,213],"LLM-judge":[145],"scoring.":[146],"On":[147],"JailbreakBench,":[148],"which":[149],"contains":[150],"100":[151],"harmful":[152,203],"10":[155],"we":[157],"evaluate":[158],"on":[160,210],"six":[161],"common":[162],"models.":[164],"achieves":[166],"an":[167,193],"average":[168],"success":[170],"rate":[171],"84.5%":[173],"evaluation":[176],"74.5%":[178],"evaluation,":[181],"where":[182],"responses":[183],"first":[185],"filtered":[186],"refusals":[188],"then":[190],"scored":[191],"by":[192],"LLM":[194],"judge":[195],"whether":[197],"they":[198],"substantively":[199],"fulfill":[200],"original":[202],"outperforms":[206],"five":[207],"state-of-the-art":[208],"baselines":[209],"both":[211],"metrics":[212],"only":[214],"30":[215],"mean":[216],"queries.":[218],"also":[220],"remains":[221],"competitive":[222],"three":[224],"defense":[225],"mechanisms":[226],"induces":[228],"more":[229],"success-like":[230],"internal":[231],"representations.":[232],"These":[233],"results":[234],"suggest":[235],"adaptive":[237],"heterogeneous":[240],"jailbreak":[241],"strategies":[242],"is":[243],"promising":[245],"direction":[246],"red-teaming.":[249]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-22T00:00:00"}
