{
  "id": 13494,
  "url": "https://arxiv.org/abs/2607.20581v1",
  "title": "Geometric Configurations of Perturbed Jailbreak Prompts",
  "summary": "Perturbation techniques that turn unsuccessful jailbreak prompts into successful ones are continuously evolving, constituting a major security threat to LLM safety. In this paper, we investigate the internal representations of such string-level perturbed jailbreak inputs in the small weight models of the Qwen-2.5-1.5B/-3B/-7B-Instruct and Llama-3.2-1B/-3B/-3.1-8B-Instruct families. We select two representation spaces: the last-layer-last-token embedding space and the top-50 next-token probabilit",
  "authors": "Lynn Delcon, Andres Algaba, Vincent Ginis",
  "category": "research",
  "topics": "safety-alignment,finance-investment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-22T11:52:43.000Z",
  "fetched_at": "2026-07-25T05:10:48.796Z",
  "source_slug": "x-arxiv-red-teaming-query",
  "source_name": "arXiv red teaming query",
  "source_homepage": "https://arxiv.org/a/redteam",
  "ethics_ai_record_url": "https://ethics.ai/record/13494",
  "original_url": "https://arxiv.org/abs/2607.20581v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}