Evidence map›Paper›PMID 41942507›Full record

ArticleScientific reports2026

AB jailbreaking - a novel hybrid framework for exploitation of adversarial vulnerabilities in LLMs.

Abrar Ahmad, Mehwish Naseer, Usman Qamar, Monther Alfuraidan

Abstract read
In one paragraph

Article in Scientific reports, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

4 authors.

Abrar Ahmad *Computer & Software Engineering Department, College of Electrical and Mechanical Engineering, National University of Sciences and Technology (NUST), Islamabad, 44080, Pakistan.
Mehwish Naseer *Computer & Software Engineering Department, College of Electrical and Mechanical Engineering, National University of Sciences and Technology (NUST), Islamabad, 44080, Pakistan.
Usman Qamar *Mathematics Department, College of Computing and Mathematics, King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia. usman.qamar@kfupm.edu.sa.
Monther Alfuraidan *Mathematics Department, College of Computing and Mathematics, King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia.

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

Large language models (LLMs) have advanced rapidly but remain vulnerable to adversarial “jailbreaking” attacks that elicit harmful or disallowed outputs. We propose AB-JB, a three-stage hybrid jailbreak framework that combines black-box semantic adversarial prompt variant generation with a compact, regularised embedding-level suffix optimiser that discretises to legal tokens. AB-JB first uses an attacker LLM to produce multiple semantically diverse adversarial variants for each harmful behaviour and a judge LLM to score and filter these variants into a high-quality candidate pool. It then performs suffix-only embedding optimization with ℓ2 regularization, per-iteration nearest-neighbour projection, and a strict iteration cap to obtain valid adversarial token suffixes under a bounded computational budget. We evaluate AB-JB on four adversarial benchmarks (AdvBench, HarmBench, JailbreakBench, Malicious-Instruct) against five popular 7B-parameter models (Llama2, Falcon, Vicuna, Mistral, MPT). Across these settings, AB-JB achieves an average of 93% dataset-level attack success rate (ASR-DS), while per-variant success (ASR-APV) averages 55.7%. On Malicious-Instruct we observe near-complete dataset success (99% ASR-DS), which we attribute to using a larger commercial model (Gemini 2.5 Flash) as the attacker when generating variants for this dataset. Compared with token-level gradient attacks, prompt-level search, and soft-prompt methods, our experiments indicate that AB-JB offers a practical compromise between attack success, cross-model performance across 7B-scale models, and compute efficiency, enabled by judge-guided variant selection and a 22-iteration suffix optimization cap. These results underline persistent alignment gaps and motivate adversarially informed defences. The present study is limited to 7B open-weight models and assumes white-box access for the suffix optimization stage.

Indexed as

Adversarial attacksBlack-box attacksHybrid attacksJailbreakingLLMsRed teamingSuffix optimizationWhite-box attacks

Identifiers

PMID41942507
PMCPMC13216313

What OpenQuestion holds

Textmetadata
LicenceCC BY
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.