{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T13:12:15Z","timestamp":1783775535933,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":32,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819228546","type":"print"},{"value":"9789819228522","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,12]],"date-time":"2026-07-12T00:00:00Z","timestamp":1783814400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,12]],"date-time":"2026-07-12T00:00:00Z","timestamp":1783814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-2852-2_46","type":"book-chapter","created":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T12:30:23Z","timestamp":1783773023000},"page":"617-631","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Evolva: A Multi-turn Contextual Attack for\u00a0Long-Reasoning LLMs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-3213-4205","authenticated-orcid":false,"given":"Wenbiao","family":"Du","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-5729-7753","authenticated-orcid":false,"given":"Xiuqi","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1909-1643","authenticated-orcid":false,"given":"Zeyang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boya","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3087-9701","authenticated-orcid":false,"given":"Jingfeng","family":"Xue","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,12]]},"reference":[{"key":"46_CR1","doi-asserted-by":"crossref","unstructured":"Anil, C., et al.: Many-shot jailbreaking. Anthropic (2024)","DOI":"10.52202\/079017-4121"},{"key":"46_CR2","unstructured":"Anwar, U., et al.: Foundational challenges in assuring alignment and safety of large language models, arXiv preprint arXiv:2404.09932 (2024)"},{"key":"46_CR3","unstructured":"Bai, Y., et\u00a0al.: Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv preprint arXiv:2204.05862 (2022)"},{"key":"46_CR4","unstructured":"Chao, P., Robey, A., Dobriban, E., Hassani, H., Pappas, G.J., Wong, E.: Jailbreaking black box large language models in twenty queries, arXiv preprint arXiv:2310.08419 (2023)"},{"key":"46_CR5","unstructured":"Cui, T., et al.: Risk taxonomy, mitigation, and assessment benchmarks of large language model systems. arXiv preprint arXiv:2401.05778 (2024)"},{"key":"46_CR6","unstructured":"Deng, G., et al.: Jailbreaker: automated jailbreak across multiple large language model chatbots. arXiv preprint arXiv:2307.08715 (2023)"},{"key":"46_CR7","doi-asserted-by":"crossref","unstructured":"Ding, P., et al.: A wolf in sheep\u2019s clothing: generalized nested jailbreak prompts can fool large language models easily, arXiv preprint arXiv:2311.08268 (2023)","DOI":"10.18653\/v1\/2024.naacl-long.118"},{"key":"46_CR8","unstructured":"Dong, H., et al.: RAFT: reward ranked finetuning for generative foundation model alignment. arXiv preprint arXiv:2304.06767 (2023)"},{"key":"46_CR9","unstructured":"Guo, X., Yu, F., Zhang, H., Qin, L., Hu, B.: Cold-attack: jailbreaking LLMs with stealthiness and controllability, arXiv preprint arXiv:2402.08679 (2024)"},{"key":"46_CR10","unstructured":"Huang, Y., Gupta, S., Xia, M., Li, K., Chen, D.: Catastrophic jailbreak of open-source LLMs via exploiting generation, arXiv preprint arXiv:2310.06987 (2023)"},{"key":"46_CR11","unstructured":"Huang, Y., et al.: ObscurePrompt: jailbreaking large language models via obscure input. arXiv preprint arXiv:2406.13662 (2024)"},{"key":"46_CR12","unstructured":"Ji, J., et al.: Aligner: achieving efficient alignment through weak-to-strong correction, arXiv preprint arXiv:2402.02416 (2024)"},{"key":"46_CR13","unstructured":"Kirchner, J.H., Chen, Y., Edwards, H., Leike, J., McAleese, N., Burda, Y.: Prover-verifier games improve legibility of LLM outputs. arXiv preprint arXiv:2407.13692 (2024)"},{"key":"46_CR14","doi-asserted-by":"crossref","unstructured":"Li, H., et al.: Multi-step jailbreaking privacy attacks on chatGPT, arXiv preprint arXiv:2304.05197 (2023)","DOI":"10.18653\/v1\/2023.findings-emnlp.272"},{"key":"46_CR15","unstructured":"Li, X., Zhou, Z., Zhu, J., Yao, J., Liu, T., Han, B.: DeepInception: hypnotize large language model to be jailbreaker. arXiv preprint arXiv:2311.03191 (2023)"},{"key":"46_CR16","unstructured":"Liu, X., Xu, N., Chen, M., Xiao, C.: AutoDAN: generating stealthy jailbreak prompts on aligned large language models, arXiv preprint arXiv:2310.04451 (2023)"},{"key":"46_CR17","doi-asserted-by":"crossref","unstructured":"Ouyang, L., et al.: Training language models to follow instructions with human feedback. In: Advances in Neural Information Processing Systems, vol. 35, pp. 27730\u201327744 (2022)","DOI":"10.52202\/068431-2011"},{"key":"46_CR18","unstructured":"Qi, X., et al.: Safety alignment should be made more than just a few tokens deep, arXiv preprint arXiv:2406.05946 (2024)"},{"key":"46_CR19","doi-asserted-by":"crossref","unstructured":"Shen, X., Chen, Z., Backes, M., Shen, Y., Zhang, Y.: \u201cDo anything now\u201d: Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv preprint arXiv:2308.03825 (2023)","DOI":"10.1145\/3658644.3670388"},{"key":"46_CR20","doi-asserted-by":"crossref","unstructured":"Wei, A., Haghtalab, N., Steinhardt, J.: Jailbroken: how does LLM safety training fail? Adv. Neural. Inf. Process. Syst. 36 (2024)","DOI":"10.52202\/075280-3508"},{"key":"46_CR21","unstructured":"Wu, J., et al.: Recursively summarizing books with human feedback, arXiv preprint arXiv:2109.10862 (2021)"},{"key":"46_CR22","unstructured":"Xiong, J., et al.: A comprehensive survey on large language model alignment, arXiv preprint arXiv:2309.15025 (2023)"},{"key":"46_CR23","unstructured":"Yang, X., Tang, X., Hu, S., Han, J.: Chain of attack: a semantic-driven contextual multi-turn attacker for LLM, arXiv preprint arXiv:2405.05610 (2024)"},{"key":"46_CR24","unstructured":"Yong, Z.X., Menghini, C., Bach, S.H.: Low-resource languages jailbreak GPT-4, arXiv preprint arXiv:2310.02446 (2023)"},{"key":"46_CR25","unstructured":"Yu, J., Lin, X., Xing, X.: GPTFUZZER: red teaming large language models with auto-generated jailbreak prompts, arXiv preprint arXiv:2309.10253 (2023)"},{"key":"46_CR26","unstructured":"Yuan, Y., et al.: GPT-4 is too smart to be safe: stealthy chat with LLMs via cipher, arXiv preprint arXiv:2308.06463 (2023)"},{"key":"46_CR27","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Lin, H., Zhang, J., Yang, D., Jia, R., Shi, W.: How Johnny can persuade LLMs to jailbreak them: rethinking persuasion to challenge AI safety by humanizing LLMs, arXiv preprint arXiv:2401.06373 (2024)","DOI":"10.18653\/v1\/2024.acl-long.773"},{"key":"46_CR28","unstructured":"Zhang, M., Pan, X., Yang, M.: JADE: a linguistics-based safety evaluation platform for large language models, arXiv preprint arXiv:2311.00286 (2023)"},{"key":"46_CR29","doi-asserted-by":"crossref","unstructured":"Zheng, L., et al.: Judging LLM-as-a-judge with MT-bench and chatbot arena. In: Advances in Neural Information Processing Systems, vol.\u00a036, pp. 46595\u201346623 (2023)","DOI":"10.52202\/075280-2020"},{"key":"46_CR30","unstructured":"Zhou, Z., Xiang, J., Chen, H., Liu, Q., Li, Z., Su, S.: Speak out of turn: safety vulnerability of large language models in multi-turn dialogue, arXiv preprint arXiv:2402.17262 (2024)"},{"key":"46_CR31","unstructured":"Zhu, S., et al.: AutoDAN: automatic and interpretable adversarial attacks on large language models, arXiv preprint arXiv:2310.15140 (2023)"},{"key":"46_CR32","unstructured":"Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J.Z., Fredrikson, M.: Universal and transferable adversarial attacks on aligned language models, arXiv preprint arXiv:2307.15043 (2023)"}],"container-title":["Lecture Notes in Computer Science","Knowledge Science, Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-2852-2_46","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T12:30:25Z","timestamp":1783773025000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-2852-2_46"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,12]]},"ISBN":["9789819228546","9789819228522"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-2852-2_46","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,12]]},"assertion":[{"value":"12 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"KSEM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Knowledge Science, Engineering and Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ksem2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ksem2026.rosc.org.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}