Pith. sign in

REVIEW 5 cited by

Jailbreaking Large Language Models with Symbolic Mathematics

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2409.11445 v2 pith:ZRC2VN4L submitted 2024-09-17 cs.CR cs.AIcs.CLcs.LG

classification cs.CRcs.AIcs.CLcs.LG
keywords safetylanguagellmsmechanismsacrossattackeffortsencoded
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Recent advancements in AI safety have led to increased efforts in training and red-teaming large language models (LLMs) to mitigate unsafe content generation. However, these safety mechanisms may not be comprehensive, leaving potential vulnerabilities unexplored. This paper introduces MathPrompt, a novel jailbreaking technique that exploits LLMs' advanced capabilities in symbolic mathematics to bypass their safety mechanisms. By encoding harmful natural language prompts into mathematical problems, we demonstrate a critical vulnerability in current AI safety measures. Our experiments across 13 state-of-the-art LLMs reveal an average attack success rate of 73.6\%, highlighting the inability of existing safety training mechanisms to generalize to mathematically encoded inputs. Analysis of embedding vectors shows a substantial semantic shift between original and encoded prompts, helping explain the attack's success. This work emphasizes the importance of a holistic approach to AI safety, calling for expanded red-teaming efforts to develop robust safeguards across all potential input types and their associated risks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Whose Refusal Is It? The Unmeasured Contribution of Black-Box Multimodal Guardrails

    cs.CR 2026-08 conditional novelty 7.0 of 10

    The reported benefit of a multimodal guardrail is a sum of guard blocks and the target model's own refusals, and evaluation protocol alone can move the guardrail's measured share from 0% to 99%.

  2. Decoy Images Amplify Caption-Mediated Defenses Against Encoded Jailbreaks

    cs.CR 2026-08 conditional novelty 7.0 of 10

    Pairing a decoy image with an encoded jailbreak prompt can sharply amplify the safety effect of an image-aware defense (ECSO), at the cost of more benign refusals unless gated by a detector.

  3. Should LLM Safety Be More Than Refusing Harmful Instructions?

    cs.CL 2025-06 conditional novelty 5.0 of 10

    LLMs that can decrypt common ciphers show safety failures split across two dimensions, refusing too much or generating unsafe output, and current defenses fix one side while breaking the other.

  4. Don't Command, Cultivate: An Exploratory Study of System-2 Alignment

    cs.CL 2024-11 conditional novelty 5.0 of 10

    Encouraging LLMs to analyze user requests step-by-step (System-2 Alignment) modestly improves safety on open-source models, but with trade-offs and limited evidence.

  5. Defense Against the Dark Prompts: Mitigating Best-of-N Jailbreaking with Prompt Evaluation

    cs.CR 2025-02 conditional novelty 4.0 of 10

    An iterative LLM-based prompt evaluator blocked 100% of the Best-of-N jailbreaking paper's released successful prompts and 99.8% of a fresh replication, with false-positive rates near zero.

Pith tools