{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T22:41:20Z","timestamp":1761000080917,"version":"build-2065373602"},"publisher-location":"Singapore","reference-count":22,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819535361"},{"type":"electronic","value":"9789819535378"}],"license":[{"start":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T00:00:00Z","timestamp":1760918400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T00:00:00Z","timestamp":1760918400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3537-8_22","type":"book-chapter","created":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T10:43:33Z","timestamp":1760870613000},"page":"398-416","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Secure Guard: A Semantic-Based Jailbreak Prompt Detection Framework for\u00a0Protecting Large Language Models"],"prefix":"10.1007","author":[{"given":"Sixin","family":"Fang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ke","family":"Cheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jixin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingwu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,20]]},"reference":[{"key":"22_CR1","unstructured":"Brown, T., et al.: Language models are few-shot learners. In: Advances in Neural Information Processing Systems, vol. 33, pp. 1877\u20131901 (2020)"},{"key":"22_CR2","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1007\/s11633-022-1393-5","volume":"20","author":"Y Zhao","year":"2023","unstructured":"Zhao, Y., Zhang, J., Zong, C.: Transformer: a general framework from machine translation to others. Mach. Intell. Res. 20, 514\u2013538 (2023)","journal-title":"Mach. Intell. Res."},{"key":"22_CR3","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1162\/tacl_a_00632","volume":"12","author":"T Zhang","year":"2023","unstructured":"Zhang, T., Ladhak, F., Durmus, E., Liang, P., McKeown, K., Hashimoto, T.: Benchmarking large language models for news summarization. Trans. Assoc. Comput. Linguistics 12, 39\u201357 (2023)","journal-title":"Trans. Assoc. Comput. Linguistics"},{"issue":"1","key":"22_CR4","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1016\/j.imed.2022.07.002","volume":"3","author":"K He","year":"2023","unstructured":"He, K., et al.: Transformers in medical image analysis. Intell. Med. 3(1), 59\u201378 (2023)","journal-title":"Intell. Med."},{"key":"22_CR5","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: JailGuard: a universal detection framework for prompt-based attacks on LLM systems. ACM Trans. Softw. Eng. Methodol. (2025)","DOI":"10.1145\/3724393"},{"key":"22_CR6","unstructured":"Bai, Y., et\u00a0al.: Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv preprint arXiv:2204.05862 (2022)"},{"key":"22_CR7","unstructured":"Wei, A., Haghtalab, N., Steinhardt, J.: Jailbroken: how does LLM safety training fail? In: Advances in Neural Information Processing Systems, vol. 36, pp. 80079\u201380110 (2023)"},{"issue":"12","key":"22_CR8","doi-asserted-by":"publisher","first-page":"1486","DOI":"10.1038\/s42256-023-00765-8","volume":"5","author":"Y Xie","year":"2023","unstructured":"Xie, Y., et al.: Defending ChatGPT against jailbreak attack via self-reminders. Nat. Mach. Intell. 5(12), 1486\u20131496 (2023)","journal-title":"Nat. Mach. Intell."},{"key":"22_CR9","doi-asserted-by":"crossref","unstructured":"Goyal, S., et al.: LLMGuard: guarding against unsafe LLM behavior. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38, pp. 23790\u201323792 (2024)","DOI":"10.1609\/aaai.v38i21.30566"},{"key":"22_CR10","unstructured":"Robey, A., Wong, E., Hassani, H., Pappas, G.J.: SmoothLLM: defending large language models against jailbreaking attacks. Trans. Mach. Learn. Res. 2025 (2023)"},{"key":"22_CR11","unstructured":"Jain, N., et al.: Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614 (2023)"},{"key":"22_CR12","unstructured":"Ji, J., et al.: Defending large language models against jailbreak attacks via semantic smoothing. arXiv preprint arXiv:2402.16192 (2024)"},{"key":"22_CR13","unstructured":"Zhou, A., Li, B., Wang, H.: Robust prompt optimization for defending language models against jailbreaking attacks. In: Advances in Neural Information Processing Systems, vol. 37, pp. 40184\u201340211 (2024)"},{"key":"22_CR14","doi-asserted-by":"crossref","unstructured":"Hu, X., Chen, P.-Y., Ho, T.-Y.: Token highlighter: inspecting and mitigating jailbreak prompts for large language models. In: AAAI Conference on Artificial Intelligence (2024)","DOI":"10.1609\/aaai.v39i26.34943"},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Shen, X., Chen, Z., Backes, M., Shen, Y., Zhang, Y.: \u201cDo anything now\u201d: characterizing and evaluating in-the-wild jailbreak prompts on large language models. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp.\u00a01671\u20131685 (2024)","DOI":"10.1145\/3658644.3670388"},{"key":"22_CR16","unstructured":"Liu, Y., et al.: Jailbreaking ChatGPT via prompt engineering: an empirical study. ArXiv, abs\/2305.13860 (2023)"},{"key":"22_CR17","unstructured":"Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J.Z., Fredrikson, M.: Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043 (2023)"},{"key":"22_CR18","unstructured":"Li, X., Zhou, Z., Zhu, J., Yao, J., Liu, T., Han, B.: DeepInception: hypnotize large language model to be jailbreaker. arXiv preprint arXiv:2311.03191 (2023)"},{"key":"22_CR19","unstructured":"Liu, X., Xu, N., Chen, M., Xiao, C.: AutoDAN: generating stealthy jailbreak prompts on aligned large language models. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"22_CR20","doi-asserted-by":"crossref","unstructured":"Chao, P., Robey, A., Dobriban, E., Hassani, H., Pappas, G.J., Wong, E.: Jailbreaking black box large language models in twenty queries. In: 2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), pp.\u00a023\u201342. IEEE (2025)","DOI":"10.1109\/SaTML64287.2025.00010"},{"key":"22_CR21","doi-asserted-by":"crossref","unstructured":"Shaikh, O., Zhang, H., Held, W.B., Bernstein, M., Yang, D.: On second thought, let\u2019s not think step by step! Bias and toxicity in zero-shot reasoning. ArXiv, abs\/2212.08061 (2022)","DOI":"10.18653\/v1\/2023.acl-long.244"},{"key":"22_CR22","unstructured":"Chao, P., et al.: JailbreakBench: an open robustness benchmark for jailbreaking large language models. In: Advances in Neural Information Processing Systems, vol. 37, pp. 55005\u201355029 (2024)"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3537-8_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T22:02:41Z","timestamp":1760997761000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3537-8_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,20]]},"ISBN":["9789819535361","9789819535378"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3537-8_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025,10,20]]},"assertion":[{"value":"20 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nanjing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.icics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}