
























Abstract:Large Language Models (LLMs) have seen widespread adoption across multiple domains, creating an urgent need for robust safety alignment mechanisms. However, robustness remains challenging due to jailbreak attacks that bypass alignment via adversarial prompts. In this work, we focus on the prevalent Greedy Coordinate Gradient (GCG) attack and identify a previously underexplored attack axis in jailbreak attacks typically framed as suffix-based: the placement of adversarial tokens within the prompt. Using GCG as a case study, we show that both optimizing attacks to generate prefixes instead of suffixes and varying adversarial token position during evaluation substantially influence attack success rates. Our findings highlight a critical blind spot in current safety evaluations and underline the need to account for the position of adversarial tokens in the adversarial robustness evaluation of LLMs.
| Comments: | 12 pages, 10 figures, presented at the "I Can't Believe It's Not Better" workshop at ICLR 2026 |
| Subjects: | Machine Learning (cs.LG) |
| Cite as: | arXiv:2602.03265 [cs.LG] |
| (or arXiv:2602.03265v2 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2602.03265 arXiv-issued DOI via DataCite |
From: Hicham Eddoubi [view email]
[v1]
Tue, 3 Feb 2026 08:53:35 UTC (2,185 KB)
[v2]
Thu, 30 Apr 2026 22:29:40 UTC (2,185 KB)
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。