AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

The Fragility of Jailbreak Robustness Across Operational States

arXiv · AI, language, vision and robotics · article · Aug 31, 2026 · UTC

Existing jailbreak evaluations typically characterize robustness using a single attack success rate (ASR) measured in a default configuration (the vanilla state). However, user-LLM interactions can induce diverse operational states beyond the vanilla state. In this work, we find that jailbreak robustness is highly fragile to operational-state variation: even when the attack remains fixed, changing only an ordinary system prompt not designed to affect safety can dramatically alter attack success rates. We systematically investigate this phenomenon across seven aligned models and three represent

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T07:01:58.596Z. This is not the publication date.