Bait-and-Recover: Poisoning Internal Refusal Signals to Defend LLMs against White-Box Editing Jailbreaks
cs.CR, cs.AI, cs.CL
Submitted: 2026-09-05
Updated: 2026-09-05
Comments: 13 pages, 3 figures. Code: https://github.com/SparkShieldLab/bait-and-recover
Code: https://github.com/SparkShieldLab/bait-and-recover
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs