As large language models (LLMs) grow more capable, concerns about their safe deployment have also grown. Although alignment mechanisms have been introduced to deter misuse, they remain vulnerable to carefully designed adversarial prompts. In this work, we present a scalable attack strategy: intent-hiding adversarial prompting, which conceals malicious intent through the composition of skills. We develop a game-theoretic framework to model the interaction between such attacks and defense systems that apply both prompt and response filtering. Our analysis identifies equilibrium points and reveals structural advantages for the attacker. To counter these threats, we propose and analyze a defense mechanism tailored to intent-hiding attacks. Empirically, we validate the attack's effectiveness on multiple real-world LLMs across a range of malicious behaviors, demonstrating clear advantages over existing adversarial prompting techniques.
Building similarity graph...
Analyzing shared references across papers
Loading...
Xinbo Wu
Tongji University
Abhishek K. Umrawal
University of Maryland, Baltimore
Lav R. Varshney
University of Illinois Urbana-Champaign
Building similarity graph...
Analyzing shared references across papers
Loading...
Wu et al. (Tue,) studied this question.
synapsesocial.com/papers/68d6e16f8b2b6861e4c3ffe3 — DOI: https://doi.org/10.48550/arxiv.2505.20841
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: