SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks
Large Language Models (LLMs) are increasingly deployed in interactive settings, where user intent commonly unfolds through multi-turn dialogue. Multi-turn jailbreaks exploit this pattern by advancing a harmful intent across turns, so that no single message exposes the full objective. However, existing work treats these attacks as a loose collection of prompt patterns and does not analyze how the adversary organizes and advances harmful intent across an interaction. We develop a four-part, intent
Record details
Published: 2 August 2026
Source: arXiv red teaming query
Category: Research
Topics: Safety & alignment
Retrieved: 4 August 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Decoy Images Amplify Caption-Mediated Defenses Against Encoded Jailbreaks
arXiv red teaming query · 2 August 2026
Mind the Gap: Zero-Query Jailbreaks via Filter-Generator Discrepancy in Text-to-Image Systems
arXiv red teaming query · 2 August 2026
UDT: Reconciling U-Nets and Diffusion Transformers with Data-Adaptive Token Reduction
arXiv cs.LG · 2 August 2026
xMICD: Explainable Representation of Multiple ICD Codes
arXiv cs.LG · 2 August 2026
The Boy Who Cried Wolf: Adversarial Misclassification of Safe Inputs as Unsafe in Multimodal Guardrails
arXiv red teaming query · 2 August 2026
Moving the Safety Barrier: Dynamic Routing Adaptive Alignment Against White-Box Attacks
arXiv red teaming query · 2 August 2026
How to cite this record
ethics.ai (2 August 2026), “SoK: Intent-Oriented Systematization of Multi-Turn LLM Jailbreaks,” evidence record 16169, https://ethics.ai/record/16169 (originally published by arXiv red teaming query).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.