{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:55:08Z","timestamp":1782316508154,"version":"3.54.5"},"publisher-location":"Cham","reference-count":49,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032297549","type":"print"},{"value":"9783032297556","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T00:00:00Z","timestamp":1782345600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T00:00:00Z","timestamp":1782345600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-29755-6_3","type":"book-chapter","created":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:40:59Z","timestamp":1782315659000},"page":"33-48","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["The Cost of\u00a0Thinking: Increased Jailbreak Risk in\u00a0Large Language Models in\u00a0Education"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-0203-2558","authenticated-orcid":false,"given":"Fan","family":"Yang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2460-7758","authenticated-orcid":false,"given":"Ke","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-5823-1965","authenticated-orcid":false,"given":"Wenzhou","family":"Dou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1052-984X","authenticated-orcid":false,"given":"Yifan","family":"Shuai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0491-307X","authenticated-orcid":false,"given":"Zitao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5605-7397","authenticated-orcid":false,"given":"Weiqi","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,25]]},"reference":[{"key":"3_CR1","unstructured":"Arrieta, A., Ugarte, M., Valle, P., Parejo, J.A., Segura, S.: Early external safety testing of openai\u2019s o3-mini: insights from the pre-deployment evaluation. arXiv preprint arXiv:2501.17749 (2025)"},{"key":"3_CR2","unstructured":"Arrieta, A., Ugarte, M., Valle, P., Parejo, J.A., Segura, S.: o3-mini vs DeepSeek-R1: which one is safer? arXiv preprint arXiv:2501.18438 (2025)"},{"key":"3_CR3","unstructured":"Bondarenko, A., Volk, D., Volkov, D., Ladish, J.: Demonstrating specification gaming in reasoning models. arXiv preprint arXiv:2502.13295 (2025)"},{"key":"3_CR4","doi-asserted-by":"publisher","unstructured":"Brender, J., El-Hamamsy, L., Mondada, F., Bumbacher, E.: Who\u2019s helping who? when students use chatgpt to engage in practice lab sessions. In: Olney, A.M., Chounta, IA., Liu, Z., Santos, O.C., Bittencourt, I.I. (eds.) AIED 2024. vol. 14829, pp. 235\u2013249. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-64302-6_17","DOI":"10.1007\/978-3-031-64302-6_17"},{"key":"3_CR5","doi-asserted-by":"publisher","first-page":"55005","DOI":"10.52202\/079017-1745","volume":"37","author":"P Chao","year":"2024","unstructured":"Chao, P., et al.: JailbreakBench: an open robustness benchmark for jailbreaking large language models. Adv. Neural. Inf. Process. Syst. 37, 55005\u201355029 (2024)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Chao, P., Robey, A., Dobriban, E., Hassani, H., Pappas, G.J., Wong, E.: Jailbreaking black box large language models in twenty queries. In: IEEE Conference on Secure and Trustworthy Machine Learning, pp. 23\u201342. IEEE (2025)","DOI":"10.1109\/SaTML64287.2025.00010"},{"key":"3_CR7","unstructured":"Chen, Z., Liu, T., Tian, M., Luo, W., Liu, Z., et\u00a0al.: Advancing mathematical reasoning in language models: the impact of problem-solving data, data synthesis methods, and training stages. In: The Thirteenth International Conference on Learning Representations (2025)"},{"key":"3_CR8","unstructured":"Chi, J., et al.: Llama guard 3 vision: Safeguarding human-AI image understanding conversations. arXiv preprint arXiv:2411.10414 (2024)"},{"key":"3_CR9","doi-asserted-by":"crossref","unstructured":"Dan, Y., et al.: EduChat: a large-scale language model-based chatbot system for intelligent education. In: Proceedings of the China Conference on Knowledge Graph and Semantic Computing (2024)","DOI":"10.1007\/978-981-96-1809-5_22"},{"key":"3_CR10","doi-asserted-by":"publisher","unstructured":"Deng, N., Liu, E.J., Zhai, X.: Understanding university students\u2019 use of generative AI: the roles of demographics and personality traits. In: Cristea, A.I., Walker, E., Lu, Y., Santos, O.C., Isotani, S. (eds.) AIED 2025. LNCS, vol. 15877, pp. 281\u2013293. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-98414-3_20","DOI":"10.1007\/978-3-031-98414-3_20"},{"key":"3_CR11","unstructured":"Fang, J., et al.: Safemlrm: demystifying safety in multi-modal large reasoning models. arXiv preprint arXiv:2504.08813 (2025)"},{"key":"3_CR12","doi-asserted-by":"publisher","unstructured":"Ghimire, A., Edwards, J.: Coding with AI: How are tools like chatGPT being used by students in foundational programming courses. In: Olney, A.M., Chounta, IA., Liu, Z., Santos, O.C., Bittencourt, I.I. (eds.) AIED 2024. LNCS, vol. 14830, pp. 259\u2013267. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-64299-9_20","DOI":"10.1007\/978-3-031-64299-9_20"},{"key":"3_CR13","unstructured":"Grattafiori, A., et al.: The llama 3 herd of models. arXiv preprint arXiv:2407.21783 (2024)"},{"issue":"8081","key":"3_CR14","doi-asserted-by":"publisher","first-page":"633","DOI":"10.1038\/s41586-025-09422-z","volume":"645","author":"D Guo","year":"2025","unstructured":"Guo, D., et al.: DeepSeek-R1 incentivizes reasoning in LLMs through reinforcement learning. Nature 645(8081), 633\u2013638 (2025)","journal-title":"Nature"},{"key":"3_CR15","doi-asserted-by":"publisher","unstructured":"Gupta, A., Reddig, J., Calo, T., Weitekamp, D., MacLellan, C.J.: Beyond final answers: Evaluating large language models for math tutoring. In: Cristea, A.I., Walker, E., Lu, Y., Santos, O.C., Isotani, S. (eds.) AIED 2025. LNCS, vol. 15877, pp. 323\u2013337. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-98414-3_23","DOI":"10.1007\/978-3-031-98414-3_23"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Han, S., et al.: WILDGUARD: open one-stop moderation tools for safety risks, jailbreaks, and refusals of LLMs. In: Proceedings of the 38th International Conference on Neural Information Processing Systems, pp. 8093\u20138131 (2024)","DOI":"10.52202\/079017-0261"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Harvey, E., Koenecke, A., Kizilcec, R.F.: \u201cdon\u2019t forget the teachers\u201d: towards an educator-centered understanding of harms from large language models in education. In: Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pp. 1\u201319 (2025)","DOI":"10.1145\/3706598.3713210"},{"key":"3_CR18","unstructured":"Inan, H., et al.: Llama guard: LLM-based input-output safeguard for human-AI conversations. arXiv preprint arXiv:2312.06674 (2023)"},{"key":"3_CR19","unstructured":"Jain, N., et al.: Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614 (2023)"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Jiang, F., et al.: Artprompt: ascii art-based jailbreak attacks against aligned LLMs. In: Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics, pp. 15157\u201315173 (2024)","DOI":"10.18653\/v1\/2024.acl-long.809"},{"key":"3_CR21","unstructured":"Jiang, Y., Li, M., Backes, M., Zhang, Y.: Adjacent words, divergent intents: jailbreaking large language models via task concurrency. In: The Thirty-Ninth Annual Conference on Neural Information Processing Systems (2025)"},{"key":"3_CR22","unstructured":"Li, X., Zhou, Z., Zhu, J., Yao, J., Liu, T., Han, B.: Deepinception: Hypnotize large language model to be jailbreaker. arXiv preprint arXiv:2311.03191 (2023)"},{"key":"3_CR23","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1109\/TASLPRO.2025.3642728","volume":"34","author":"X Li","year":"2025","unstructured":"Li, X., Zhou, Z., Liu, Z., Wu, Y., Luo, W.: A synergistic multi-agent framework for camouflage attack on large language models. IEEE Trans. Audio Speech Lang. Process. 34, 299\u2013310 (2025)","journal-title":"IEEE Trans. Audio Speech Lang. Process."},{"key":"3_CR24","unstructured":"Liao, Z., Sun, H.: AmpleGCG: learning a universal and transferable generative model of adversarial suffixes for jailbreaking both open and closed LLMs. In: Proceedings of the First Conference on Language Modeling (2024)"},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"Liu, S., Chen, J., Ruan, S., Su, H., Yin, Z.: Exploring the robustness of decision-level through adversarial attacks on LLM-based embodied models. In: Proceedings of the 32nd ACM International Conference on Multimedia, pp. 8120\u20138128 (2024)","DOI":"10.1145\/3664647.3680616"},{"key":"3_CR26","unstructured":"Liu, X., et al.: AutoDAN-Turbo: a lifelong agent for strategy self-exploration to jailbreak LLMs. In: The Thirteenth International Conference on Learning Representations (2025)"},{"key":"3_CR27","unstructured":"Liu, X., Xu, N., Chen, M., Xiao, C.: AutoDAN: generating stealthy jailbreak prompts on aligned large language models. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"3_CR28","unstructured":"Liu, Y., Jia, Y., Geng, R., Jia, J., Gong, N.Z.: Formalizing and benchmarking prompt injection attacks and defenses. In: 33rd USENIX Security Symposium. pp. 1831\u20131847 (2024)"},{"key":"3_CR29","unstructured":"Mazeika, M., et al.: HarmBench: a standardized evaluation framework for automated red teaming and robust refusal. In: Proceedings of Machine Learning Research, vol. 235, pp. 35181\u201335224 (2024)"},{"key":"3_CR30","doi-asserted-by":"publisher","first-page":"61065","DOI":"10.52202\/079017-1952","volume":"37","author":"A Mehrotra","year":"2024","unstructured":"Mehrotra, A., et al.: Tree of attacks: jailbreaking black-box LLMs automatically. Adv. Neural. Inf. Process. Syst. 37, 61065\u201361105 (2024)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"3_CR31","doi-asserted-by":"publisher","unstructured":"Nguyen, M.H., P\u0103durean, V.A., Gotovos, A., Tschiatschek, S., Singla, A.: Synthesizing high-quality programming tasks with LLM-based expert and student agents. In: Cristea, A.I., Walker, E., Lu, Y., Santos, O.C., Isotani, S. (eds.) AIED 2025. LNCS, vol. 15877, pp. 77\u201391. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-98414-3_6","DOI":"10.1007\/978-3-031-98414-3_6"},{"key":"3_CR32","unstructured":"OpenAI: GPT-5.1: Large language model (2025). https:\/\/openai.com. Accessed 26 Nov 2025"},{"key":"3_CR33","unstructured":"Qi, X., et al.: Fine-tuning aligned language models compromises safety, even when users do not intend to! In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"3_CR34","doi-asserted-by":"crossref","unstructured":"Rath, P., Shrawgi, H., Agrawal, P., Dandapat, S.: LLM safety for children. In: Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies, pp. 809\u2013821 (2025)","DOI":"10.18653\/v1\/2025.naacl-industry.62"},{"key":"3_CR35","doi-asserted-by":"publisher","unstructured":"Scarlatos, A., Liu, N., Lee, J., Baraniuk, R., Lan, A.: Training llm-based tutors to improve student learning outcomes in dialogues. In: Cristea, A.I., Walker, E., Lu, Y., Santos, O.C., Isotani, S. (eds.) AIED 2025. LNCS, vol. 15877, pp. 251\u2013266. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-98414-3_18","DOI":"10.1007\/978-3-031-98414-3_18"},{"key":"3_CR36","doi-asserted-by":"publisher","unstructured":"Scarlatos, A., Smith, D., Woodhead, S., Lan, A.: Improving the validity of automatically generated feedback via reinforcement learning. In: In: Olney, A.M., Chounta, IA., Liu, Z., Santos, O.C., Bittencourt, I.I. (eds.) AIED 2024. vol. 14829, pp. 280\u2013294. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-64302-6_20","DOI":"10.1007\/978-3-031-64302-6_20"},{"key":"3_CR37","doi-asserted-by":"publisher","unstructured":"Schmucker, R., Xia, M., Azaria, A., Mitchell, T.: Ruffle&riley: Insights from designing and evaluating a large language model-based conversational tutoring system. In: Olney, A.M., Chounta, IA., Liu, Z., Santos, O.C., Bittencourt, I.I. (eds.) AIED 2024. LNCS, vol. 14829, pp. 75\u201390. Springer, Cham (2024).https:\/\/doi.org\/10.1007\/978-3-031-64302-6_6","DOI":"10.1007\/978-3-031-64302-6_6"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Shi, J., et al.: Optimization-based prompt injection attack to LLM-as-a-judge. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 660\u2013674 (2024)","DOI":"10.1145\/3658644.3690291"},{"key":"3_CR39","unstructured":"Wang, C., et\u00a0al.: Safety in large reasoning models: a survey. In: Findings of the Association for Computational Linguistics: EMNLP, pp. 3468\u20133482. Association for Computational Linguistics (2025)"},{"key":"3_CR40","unstructured":"Wei, Z., Wang, Y., Li, A., Mo, Y., Wang, Y.: Jailbreak and guard aligned language models with only few in-context demonstrations. arXiv preprint arXiv:2310.06387 (2023)"},{"key":"3_CR41","unstructured":"White, J., et al.: A prompt pattern catalog to enhance prompt engineering with chatgpt. arXiv preprint arXiv:2302.11382 (2023)"},{"key":"3_CR42","unstructured":"Xu, H., et al.: Probabilistic categorical adversarial attack and adversarial training. In: International Conference on Machine Learning, pp. 38428\u201338442. PMLR (2023)"},{"key":"3_CR43","unstructured":"Yang, A., et\u00a0al.: Qwen3 technical report. arXiv preprint arXiv:2505.09388 (2025)"},{"key":"3_CR44","doi-asserted-by":"crossref","unstructured":"Yi, J., et al.: Benchmarking and defending against indirect prompt injection attacks on large language models. In: Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1, pp. 1809\u20131820 (2025)","DOI":"10.1145\/3690624.3709179"},{"key":"3_CR45","unstructured":"Zeng, W., et al.: Shieldgemma: generative AI content moderation based on gemma. arXiv preprint arXiv:2407.21772 (2024)"},{"key":"3_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Wei, Z.: Boosting jailbreak attack with momentum. In: IEEE International Conference on Acoustics, Speech and Signal Processing, pp. 1\u20135. IEEE (2025)","DOI":"10.1109\/ICASSP49660.2025.10888812"},{"key":"3_CR47","doi-asserted-by":"crossref","unstructured":"Zhou, K., et al.: The hidden risks of large reasoning models: a safety assessment of r1. In: International Conference on Machine Learning 2025 Workshop on Reliable and Responsible Foundation Models (2025)","DOI":"10.18653\/v1\/2025.ijcnlp-long.173"},{"key":"3_CR48","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Lu, L., Sun, H., Zhou, P., Sun, L.: Virtual context: enhancing jailbreak attacks with special token injection. arXiv preprint arXiv:2406.19845 (2024)","DOI":"10.18653\/v1\/2024.findings-emnlp.692"},{"key":"3_CR49","unstructured":"Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J.Z., Fredrikson, M.: Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043 (2023)"}],"container-title":["Lecture Notes in Computer Science","Artificial Intelligence in Education"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-29755-6_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:42:10Z","timestamp":1782315730000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-29755-6_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,25]]},"ISBN":["9783032297549","9783032297556"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-29755-6_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,25]]},"assertion":[{"value":"25 June 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AIED","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Artificial Intelligence in Education","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Seoul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"aied2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.aied-conference.org\/2026","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}