Prepending single letters to key words makes BPE and WordPiece text classifiers misclassify malicious prompts as benign, while the tested Unigram-based models resist the trick.
Tricking llms into disobedience: Formalizing, analyzing, and detecting jailbreaks, 2024
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.LG 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
TokenBreak: Bypassing Text Classification Models Through Token Manipulation
Prepending single letters to key words makes BPE and WordPiece text classifiers misclassify malicious prompts as benign, while the tested Unigram-based models resist the trick.