Evolving Skill-Structured Attack Memory Enhances LLM Jailbreaking
Junke Zhang, Jianwei Wang, Sishuo Chen, Yizhang He, Qingshuai Feng, Zhengyi Yang
cs.CR
Submitted: 2026-08-15
Updated: 2026-08-18
Comments: Under review
License: http://creativecommons.org/licenses/by/4.0/
The gist: Jailbreak attacks on large language models (LLMs) aim to induce LLMs to produce content that they are expected to refuse.
Terminology
Abstract
Jailbreak attacks on large language models (LLMs) aim to induce LLMs to produce content that they are expected to refuse. Automated black-box jailbreak generation is especially important for safety evaluation, where the attacker observes only model outputs and needs to automatically search for effective adversarial prompts. Existing black-box jailbreak methods either depend on sample-wise heuristic search or leverage attack experience through accumulating strategy pools or method libraries, lacking a systematic organization and management of attack experience. To mitigate these drawbacks, we propose MemoAttack, a memory-driven black-box jailbreak framework with comprehensive attack memory modeling, evolution, and selection. Specifically, MemoAttack comprises three key designs: (1) Skill-Structured Memory Modeling, which abstracts accumulated attack experience into reusable skill-structured attack memory whose units pair attack skills with templates, evidence, and lifecycle state; (2) Lifecycle-Driven Memory Evolution, which evolves the memory through evidence-based probation, promotion, retirement, reactivation, elimination, and storage cleanup; and (3) Explore-Exploit Balanced Memory Selection, which balances reliable memory reuse with uncertainty-driven exploration via contextual Thompson Sampling. Experiments on AdvBench demonstrate that MemoAttack achieves an average attack success rate of 98.00%, outperforming the strongest baseline by 16.67 percentage points, while reducing request count by 45.9%. Moreover, MemoAttack continuously improves as memory accumulates over more samples.
Sources
- Detecting Language Model Attacks with Perplexity
- MetaCipher: A Time-Persistent and Universal Multi-Agent Framework for Cipher-Based Jailbreak Attacks for LLMs
- Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs
- Zer0-Jack: A Memory-efficient Gradient-based Jailbreaking Method for Black-box Multi-modal Large Language Models
- Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned
- AutoRISE: Agent-Driven Strategy Evolution for Red-Teaming Large Language Models
- COLD-Attack: Jailbreaking LLMs with Stealthiness and Controllability
- Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
- GUARD: Role-playing to Generate Natural-language Jailbreakings to Test Guideline Adherence of Large Language Models
- STAR-Teaming: A Strategy-Response Multiplex Network Approach to Automated LLM Red Teaming
- JailPO: A Novel Black-box Jailbreak Framework via Preference Optimization against Aligned LLMs
- DeepInception: Hypnotize Large Language Model to Be Jailbreaker
- PathSeeker: Exploring LLM Security Vulnerabilities with a Reinforcement Learning-Based Jailbreak Approach
- Large Language Model Guided Tree-of-Thought
- ER-MIA: Black-Box Adversarial Memory Injection Attacks on Long-Term Memory-Augmented Large Language Models
- Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks
- EvoJail: Evolutionary Diverse Jailbreak Prompt Generation for Large Language Models
- BlackDAN: A Black-Box Multi-Objective Approach for Effective and Contextual Jailbreaking of Large Language Models
- Distract Large Language Models for Automatic Jailbreak Attack
- Low-Resource Languages Jailbreak GPT-4
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs