{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T13:15:02Z","timestamp":1783602902165,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":26,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819533428","type":"print"},{"value":"9789819533435","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,11,23]],"date-time":"2025-11-23T00:00:00Z","timestamp":1763856000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,23]],"date-time":"2025-11-23T00:00:00Z","timestamp":1763856000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3343-5_32","type":"book-chapter","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T06:30:54Z","timestamp":1763793054000},"page":"414-426","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Reward-Guided Many-Shot Jailbreaking"],"prefix":"10.1007","author":[{"given":"Yongkang","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaotian","family":"Zou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianwen","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hu","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaohui","family":"Kuang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,23]]},"reference":[{"key":"32_CR1","unstructured":"Anil, C., et\u00a0al.: Many-shot jailbreaking. In: The Thirty-eighth Annual Conference on Neural Information Processing Systems (2024)"},{"key":"32_CR2","doi-asserted-by":"crossref","unstructured":"Chao, P., et\u00a0al.: Jailbreakbench: an open robustness benchmark for jailbreaking large language models. arXiv preprint arXiv:2404.01318 (2024)","DOI":"10.52202\/079017-1745"},{"key":"32_CR3","unstructured":"Del\u00e9tang, G., et\u00a0al.: Language modeling is compression. arXiv preprint arXiv:2309.10668 (2023)"},{"key":"32_CR4","unstructured":"Dubey, A., et\u00a0al.: The llama 3 herd of models. arXiv preprint arXiv:2407.21783 (2024)"},{"key":"32_CR5","unstructured":"Fort, S.: Scaling laws for adversarial attacks on language model activations. arXiv preprint arXiv:2312.02780 (2023)"},{"key":"32_CR6","unstructured":"Grigsby, J., Fan, L., Zhu, Y.: Amago: scalable in-context reinforcement learning for adaptive agents. arXiv preprint arXiv:2310.09971 (2023)"},{"key":"32_CR7","doi-asserted-by":"crossref","unstructured":"Krishnamurthy, A., Harris, K., Foster, D.J., Zhang, C., Slivkins, A.: Can large language models explore in-context? arXiv preprint arXiv:2403.15371 (2024)","DOI":"10.52202\/079017-3818"},{"key":"32_CR8","unstructured":"Laskin, M., et\u00a0al.: In-context reinforcement learning with algorithm distillation. arXiv preprint arXiv:2210.14215 (2022)"},{"key":"32_CR9","doi-asserted-by":"crossref","unstructured":"Lee, J., et al.: Supervised pretraining can learn in-context reinforcement learning. In: Advances in Neural Information Processing Systems, vol. 36 (2024)","DOI":"10.52202\/075280-1866"},{"key":"32_CR10","unstructured":"Li, M., et al.: In-context learning with many demonstration examples. arXiv preprint arXiv:2302.04931 (2023)"},{"key":"32_CR11","unstructured":"Liao, Z., Sun, H.: Amplegcg: learning a universal and transferable generative model of adversarial suffixes for jailbreaking both open and closed llms. arXiv preprint arXiv:2404.07921 (2024)"},{"key":"32_CR12","unstructured":"Liu, X., Xu, N., Chen, M., Xiao, C.: Autodan: generating stealthy jailbreak prompts on aligned large language models. arXiv preprint arXiv:2310.04451 (2023)"},{"key":"32_CR13","unstructured":"Mazeika, M., et\u00a0al.: Harmbench: a standardized evaluation framework for automated red teaming and robust refusal. arXiv preprint arXiv:2402.04249 (2024)"},{"key":"32_CR14","unstructured":"Paulus, A., Zharmagambetov, A., Guo, C., Amos, B., Tian, Y.: Advprompter: fast adaptive adversarial prompting for llms. arXiv preprint arXiv:2404.16873 (2024)"},{"key":"32_CR15","doi-asserted-by":"crossref","unstructured":"Rafailov, R., Sharma, A., Mitchell, E., Manning, C.D., Ermon, S., Finn, C.: Direct preference optimization: your language model is secretly a reward model. In: Advances in Neural Information Processing Systems, vol. 36 (2024)","DOI":"10.52202\/075280-2338"},{"key":"32_CR16","unstructured":"Raparthy, S.C., Hambro, E., Kirk, R., Henaff, M., Raileanu, R.: Generalization to new sequential decision making tasks with in-context learning. arXiv preprint arXiv:2312.03801 (2023)"},{"key":"32_CR17","doi-asserted-by":"crossref","unstructured":"Sun, Z., et al.: Principle-driven self-alignment of language models from scratch with minimal human supervision. In: Advances in Neural Information Processing Systems, vol. 36 (2024)","DOI":"10.52202\/075280-0115"},{"key":"32_CR18","unstructured":"Vaswani, A.: Attention is all you need. In: Advances in Neural Information Processing Systems (2017)"},{"key":"32_CR19","unstructured":"Wolf, Y., Wies, N., Avnery, O., Levine, Y., Shashua, A.: Fundamental limitations of alignment in large language models. arXiv preprint arXiv:2304.11082 (2023)"},{"key":"32_CR20","unstructured":"Wu, Z., Gao, H., He, J., Wang, P.: The dark side of function calling: pathways to jailbreaking large language models. arXiv preprint arXiv:2407.17915 (2024)"},{"key":"32_CR21","unstructured":"Xu, X., et al.: An LLM can fool itself: a prompt-based adversarial attack. arXiv preprint arXiv:2310.13345 (2023)"},{"key":"32_CR22","unstructured":"Yu, J., Lin, X., Yu, Z., Xing, X.: $$\\{$$LLM-Fuzzer$$\\}$$: scaling assessment of large language model jailbreaks. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 4657\u20134674 (2024)"},{"key":"32_CR23","unstructured":"Yu, Z., Liu, X., Liang, S., Cameron, Z., Xiao, C., Zhang, N.: Don\u2019t listen to me: understanding and exploring jailbreak prompts of large language models. arXiv preprint arXiv:2403.17336 (2024)"},{"key":"32_CR24","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Lin, H., Zhang, J., Yang, D., Jia, R., Shi, W.: How johnny can persuade LLMs to jailbreak them: rethinking persuasion to challenge AI safety by humanizing LLMs. arXiv preprint arXiv:2401.06373 (2024)","DOI":"10.18653\/v1\/2024.acl-long.773"},{"key":"32_CR25","unstructured":"Zhao, W.X., et\u00a0al.: A survey of large language models. arXiv preprint arXiv:2303.18223 (2023)"},{"key":"32_CR26","unstructured":"Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J.Z., Fredrikson, M.: Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043 (2023)"}],"container-title":["Lecture Notes in Computer Science","Natural Language Processing and Chinese Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3343-5_32","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T12:29:49Z","timestamp":1783600189000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3343-5_32"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,23]]},"ISBN":["9789819533428","9789819533435"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3343-5_32","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,23]]},"assertion":[{"value":"23 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NLPCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"CCF International Conference on Natural Language Processing and Chinese Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Urumqi","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nlpcc2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/tcci.ccf.org.cn\/conference\/2025\/index.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}