{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T18:21:16Z","timestamp":1783102876576,"version":"3.54.6"},"reference-count":70,"publisher":"Elsevier BV","issue":"7","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["YJ202429"],"award-info":[{"award-number":["YJ202429"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["SCU2024D012"],"award-info":[{"award-number":["SCU2024D012"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013804","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100013804","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402331"],"award-info":[{"award-number":["62402331"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Processing &amp; Management"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.ipm.2026.104831","type":"journal-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T16:16:53Z","timestamp":1777047413000},"page":"104831","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"special_numbering":"PA","title":["EvoJail: Evolutionary diverse jailbreak prompt generation for large language models"],"prefix":"10.1016","volume":"63","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3112-4861","authenticated-orcid":false,"given":"Rui","family":"Tang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8766-0936","authenticated-orcid":false,"given":"Kaiyu","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5100-9772","authenticated-orcid":false,"given":"Pengsen","family":"Cheng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7909-3753","authenticated-orcid":false,"given":"Hao","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1197-5906","authenticated-orcid":false,"given":"Haizhou","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4711-4112","authenticated-orcid":false,"given":"Shuyu","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.ipm.2026.104831_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112914","article-title":"LLM-based IR-system for bank supervisors","volume":"310","author":"Aarab","year":"2025","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.ipm.2026.104831_b2","series-title":"Gpt-4 technical report","author":"Achiam","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b3","unstructured":"Andriushchenko, M., Croce, F., & Flammarion, N. (2025). Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks. In The thirteenth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.114433","article-title":"Structural chain of thoughts for radiology education","volume":"330","author":"Awasthi","year":"2025","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.ipm.2026.104831_b5","unstructured":"Basani, A. R., & Zhang, X. (2025). Gasp: Efficient black-box generation of adversarial suffixes for jailbreaking llms. In Annual conference on neural information processing systems."},{"key":"10.1016\/j.ipm.2026.104831_b6","series-title":"Explore, establish, exploit: Red teaming language models from scratch","author":"Casper","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b7","doi-asserted-by":"crossref","unstructured":"Chao, P., Debenedetti, E., Robey, A., Andriushchenko, M., Croce, F., Sehwag, V., Dobriban, E., Flammarion, N., Pappas, G. J., Tram\u00e8r, F., et al. (2024). JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models. In The thirty-eight conference on neural information processing systems datasets and benchmarks track.","DOI":"10.52202\/079017-1745"},{"key":"10.1016\/j.ipm.2026.104831_b8","series-title":"Jailbreaking black box large language models in twenty queries","author":"Chao","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b9","series-title":"Evolve the method, not the prompts: Evolutionary synthesis of jailbreak attacks on LLMs","author":"Chen","year":"2025"},{"key":"10.1016\/j.ipm.2026.104831_b10","series-title":"NDSS","article-title":"MASTERKEY: Automated jailbreaking of large language model chatbots","author":"Deng","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b11","series-title":"Pandora: Jailbreak gpts by retrieval augmented generation poisoning","author":"Deng","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b12","unstructured":"Deng, Y., Zhang, W., Pan, S. J., & Bing, L. (2024). Multilingual Jailbreak Challenges in Large Language Models. In The twelfth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b13","doi-asserted-by":"crossref","unstructured":"Diao, M., Li, R., Liu, S., Liao, G., Wang, J., Cai, X., & Xu, W. (2025). Seas: Self-evolving adversarial safety optimization for large language models. vol. 39, In Proceedings of the AAAI conference on artificial intelligence (pp. 23778\u201323786). 22.","DOI":"10.1609\/aaai.v39i22.34549"},{"key":"10.1016\/j.ipm.2026.104831_b14","doi-asserted-by":"crossref","unstructured":"Ding, P., Kuang, J., Ma, D., Cao, X., Xian, Y., Chen, J., & Huang, S. (2024). A Wolf in Sheep\u2019s Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily. In Proceedings of the 2024 conference of the North American chapter of the association for computational linguistics: human language technologies (volume 1: long papers) (pp. 2136\u20132153).","DOI":"10.18653\/v1\/2024.naacl-long.118"},{"key":"10.1016\/j.ipm.2026.104831_b15","unstructured":"Doumbouya, M. K. B., Nandi, A., Poesia, G., Ghilardi, D., Goldie, A., Bianchi, F., Jurafsky, D., & Manning, C. D. (2025). h4rm3l: A language for composable jailbreak attack synthesis. In The thirteenth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b16","series-title":"The llama 3 herd of models","author":"Dubey","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b17","unstructured":"Gong, X., Li, M., Zhang, Y., Ran, F., Chen, C., Chen, Y., Wang, Q., & Lam, K.-Y. (2025). {PAPILLON}: Efficient and stealthy fuzz {Testing-Powered} jailbreaks for {LLMs}. In 34th USENIX security symposium (pp. 2401\u20132420)."},{"key":"10.1016\/j.ipm.2026.104831_b18","series-title":"International conference on machine learning","first-page":"16974","article-title":"COLD-attack: Jailbreaking LLMs with stealthiness and controllability","author":"Guo","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b19","doi-asserted-by":"crossref","first-page":"128260","DOI":"10.52202\/079017-4073","article-title":"Query-based adversarial prompt generation","volume":"37","author":"Hayase","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.ipm.2026.104831_b20","doi-asserted-by":"crossref","first-page":"1445","DOI":"10.1109\/TLT.2024.3384765","article-title":"Teaching plan generation and evaluation with GPT-4: Unleashing the potential of LLM in instructional design","volume":"17","author":"Hu","year":"2024","journal-title":"IEEE Transactions on Learning Technologies"},{"key":"10.1016\/j.ipm.2026.104831_b21","unstructured":"Huang, Y., Gupta, S., Xia, M., Li, K., & Chen, D. (2024). Catastrophic Jailbreak of Open-source LLMs via Exploiting Generation. In The twelfth international conference on learning representations."},{"issue":"6","key":"10.1016\/j.ipm.2026.104831_b22","doi-asserted-by":"crossref","DOI":"10.1016\/j.ipm.2025.104239","article-title":"Red teaming large language models: A comprehensive review and critical analysis","volume":"62","author":"Jabbar","year":"2025","journal-title":"Information Processing & Management"},{"key":"10.1016\/j.ipm.2026.104831_b23","unstructured":"Jia, X., Pang, T., Du, C., Huang, Y., Gu, J., Liu, Y., Cao, X., & Lin, M. (2025). Improved Techniques for Optimization-Based Jailbreaking on Large Language Models. In The thirteenth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b24","doi-asserted-by":"crossref","DOI":"10.1145\/3717067","article-title":"Deceiving LLM through compositional instruction with hidden attacks","author":"Jiang","year":"2025","journal-title":"ACM Transactions on Autonomous and Adaptive Systems"},{"key":"10.1016\/j.ipm.2026.104831_b25","article-title":"Decomposition, synthesis and attack: A multi-instruction fusion method for jailbreaking LLMs","author":"Jiang","year":"2025","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.ipm.2026.104831_b26","unstructured":"Jiang, Y., Li, M., Backes, M., & Zhang, Y. (2025). Adjacent Words, Divergent Intents: Jailbreaking Large Language Models via Task Concurrency. In Annual conference on neural information processing systems."},{"key":"10.1016\/j.ipm.2026.104831_b27","doi-asserted-by":"crossref","unstructured":"Jiang, F., Xu, Z., Niu, L., Xiang, Z., Ramasubramanian, B., Li, B., & Poovendran, R. (2024). Artprompt: Ascii art-based jailbreak attacks against aligned llms. In Proceedings of the 62nd annual meeting of the association for computational linguistics (volume 1: long papers) (pp. 15157\u201315173).","DOI":"10.18653\/v1\/2024.acl-long.809"},{"key":"10.1016\/j.ipm.2026.104831_b28","unstructured":"Jin, H., Chen, R., Zhou, A., Zhang, Y., & Wang, H. (2024). GUARD: Role-playing to Generate Natural-language Jailbreakings to Test Guideline Adherence of Large Language Models. In ICLR 2024 workshop on secure and trustworthy large language models."},{"key":"10.1016\/j.ipm.2026.104831_b29","series-title":"2024 IEEE security and privacy workshops","first-page":"132","article-title":"Exploiting programmatic behavior of llms: Dual-use through standard security attacks","author":"Kang","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b30","unstructured":"Lermen, S., & Rogers-Smith, C. (2024). LoRA Fine-tuning Efficiently Undoes Safety Training in Llama 2-Chat 70B. In ICLR 2024 workshop on secure and trustworthy large language models."},{"key":"10.1016\/j.ipm.2026.104831_b31","doi-asserted-by":"crossref","unstructured":"Li, H., Cao, Y., Yu, Y., Javaji, S. R., Deng, Z., He, Y., Jiang, Y., Zhu, Z., Subbalakshmi, K., Huang, J., et al. (2025). Investorbench: A benchmark for financial decision-making tasks with llm-based agent. In Proceedings of the 63rd annual meeting of the association for computational linguistics (volume 1: long papers) (pp. 2509\u20132525).","DOI":"10.18653\/v1\/2025.acl-long.126"},{"key":"10.1016\/j.ipm.2026.104831_b32","series-title":"Findings of the association for computational linguistics: EMNLP 2023","first-page":"4138","article-title":"Multi-step jailbreaking privacy attacks on ChatGPT","author":"Li","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b33","series-title":"Semantic mirror jailbreak: Genetic algorithm based jailbreak prompts against open-source llms","author":"Li","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b34","unstructured":"Li, L., Liu, Y., He, D., & LI, Y. (2025). One Model Transfer to All: On Robust Jailbreak Prompts Generation against LLMs. In The thirteenth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b35","series-title":"A cross-language investigation into jailbreak attacks in large language models","author":"Li","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b36","series-title":"Deepinception: Hypnotize large language model to be jailbreaker","author":"Li","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b37","unstructured":"Lin, B. Y., Ravichander, A., Lu, X., Dziri, N., Sclar, M., Chandu, K., Bhagavatula, C., & Choi, Y. (2024). The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning. In The twelfth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b38","series-title":"International conference on machine learning","first-page":"38623","article-title":"FlipAttack: Jailbreak LLMs via flipping","author":"Liu","year":"2025"},{"issue":"3","key":"10.1016\/j.ipm.2026.104831_b39","doi-asserted-by":"crossref","DOI":"10.1016\/j.ipm.2025.104544","article-title":"SEAttack: A self-evolving jailbreak attack to induce toxic responses for non-toxic queries in large language models","volume":"63","author":"Liu","year":"2026","journal-title":"Information Processing & Management"},{"key":"10.1016\/j.ipm.2026.104831_b40","unstructured":"Liu, X., Li, P., Suh, E., Vorobeychik, Y., Mao, Z., Jha, S., McDaniel, P., Sun, H., Li, B., & Xiao, C. (2025). Autodan-turbo: A lifelong agent for strategy self-exploration to jailbreak llms. In The thirteenth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b41","unstructured":"Liu, X., Xu, N., Chen, M., & Xiao, C. (2024). AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. In The twelfth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b42","series-title":"Codechameleon: Personalized encryption framework for jailbreaking large language models","author":"Lv","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b43","doi-asserted-by":"crossref","first-page":"61065","DOI":"10.52202\/079017-1952","article-title":"Tree of attacks: Jailbreaking black-box llms automatically","volume":"37","author":"Mehrotra","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.ipm.2026.104831_b44","unstructured":"Qi, X., Zeng, Y., Xie, T., Chen, P.-Y., Jia, R., Mittal, P., & Henderson, P. (2024). Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!. In The twelfth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b45","series-title":"Smoothllm: Defending large language models against jailbreaking attacks","author":"Robey","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b46","series-title":"Evolution strategies as a scalable alternative to reinforcement learning","author":"Salimans","year":"2017"},{"issue":"5","key":"10.1016\/j.ipm.2026.104831_b47","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1016\/0306-4573(88)90021-0","article-title":"Term-weighting approaches in automatic text retrieval","volume":"24","author":"Salton","year":"1988","journal-title":"Information Processing & Management"},{"key":"10.1016\/j.ipm.2026.104831_b48","series-title":"Scalable and transferable black-box jailbreaks for language models via persona modulation","author":"Shah","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b49","doi-asserted-by":"crossref","unstructured":"Shen, X., Chen, Z., Backes, M., Shen, Y., & Zhang, Y. (2024). \u201cDo anything now\u201d: Characterizing and evaluating in-the-wild jailbreak prompts on large language models. In Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security (pp. 1671\u20131685).","DOI":"10.1145\/3658644.3670388"},{"issue":"8","key":"10.1016\/j.ipm.2026.104831_b50","doi-asserted-by":"crossref","first-page":"1930","DOI":"10.1038\/s41591-023-02448-8","article-title":"Large language models in medicine","volume":"29","author":"Thirunavukarasu","year":"2023","journal-title":"Nature Medicine"},{"key":"10.1016\/j.ipm.2026.104831_b51","doi-asserted-by":"crossref","unstructured":"Wang, X., Jian, S., Li, S., Li, X., Ji, B., Jun, M., Liu, X., Wang, J., Zhang, J., Yu, J., et al. (2025). Stand on The Shoulders of Giants: Building JailExpert from Previous Attack Experience. In Proceedings of the 2025 conference on empirical methods in natural language processing (pp. 3826\u20133843).","DOI":"10.18653\/v1\/2025.emnlp-main.190"},{"key":"10.1016\/j.ipm.2026.104831_b52","doi-asserted-by":"crossref","unstructured":"Wang, H., Li, H., Huang, M., & Sha, L. (2024). ASETF: A Novel Method for Jailbreak Attack on LLMs through Translate Suffix Embeddings. In Proceedings of the 2024 conference on empirical methods in natural language processing (pp. 2697\u20132711).","DOI":"10.18653\/v1\/2024.emnlp-main.157"},{"key":"10.1016\/j.ipm.2026.104831_b53","series-title":"Jailbreak and guard aligned language models with only few in-context demonstrations","author":"Wei","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b54","unstructured":"Wu, T., Xue, Z., Liu, Y., Zhang, J., Hooi, B., & Ng, S.-K. (2025). Geneshift: Impact of different scenario shift on Jailbreaking LLM. In ICLR 2025 workshop on foundation models in the wild."},{"key":"10.1016\/j.ipm.2026.104831_b55","doi-asserted-by":"crossref","unstructured":"Xie, Y., Fang, M., Pi, R., & Gong, N. (2024). GradSafe: Detecting Jailbreak Prompts for LLMs via Safety-Critical Gradient Analysis. In Proceedings of the 62nd annual meeting of the association for computational linguistics (volume 1: long papers) (pp. 507\u2013518).","DOI":"10.18653\/v1\/2024.acl-long.30"},{"key":"10.1016\/j.ipm.2026.104831_b56","series-title":"Attack via overfitting: 10-shot benign fine-tuning to jailbreak LLMs","author":"Xie","year":"2025"},{"key":"10.1016\/j.ipm.2026.104831_b57","unstructured":"Xiong, C., Chen, P.-Y., & Ho, T.-Y. (2025). CoP: Agentic Red-teaming for Large Language Models using Composition of Principles. In Annual conference on neural information processing systems."},{"key":"10.1016\/j.ipm.2026.104831_b58","unstructured":"Yang, X., Wang, X., Zhang, Q., Petzold, L. R., Wang, W. Y., Zhao, X., & Lin, D. (2024). Shadow Alignment: The Ease of Subverting Safely-Aligned Language Models. In ICLR 2024 workshop on secure and trustworthy large language models."},{"key":"10.1016\/j.ipm.2026.104831_b59","series-title":"ICASSP 2024-2024 IEEE international conference on acoustics, speech and signal processing","first-page":"4485","article-title":"Fuzzllm: A novel and universal fuzzing framework for proactively discovering jailbreak vulnerabilities in large language models","author":"Yao","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b60","series-title":"Jailbreak attacks and defenses against large language models: A survey","author":"Yi","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b61","unstructured":"Yu, J., Lin, X., Yu, Z., & Xing, X. (2024). LLM-Fuzzer: Scaling assessment of large language model jailbreaks. In 33rd USENIX security symposium (pp. 4657\u20134674)."},{"key":"10.1016\/j.ipm.2026.104831_b62","unstructured":"Yuan, Y., Jiao, W., Wang, W., Huang, J.-t., He, P., Shi, S., & Tu, Z. (2024). GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher. In The twelfth international conference on learning representations."},{"key":"10.1016\/j.ipm.2026.104831_b63","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Lin, H., Zhang, J., Yang, D., Jia, R., & Shi, W. (2024). How Johnny Can Persuade LLMs to Jailbreak Them: Rethinking Persuasion to Challenge AI Safety by Humanizing LLMs. In Proceedings of the 62nd annual meeting of the association for computational linguistics (volume 1: long papers) (pp. 14322\u201314350).","DOI":"10.18653\/v1\/2024.acl-long.773"},{"key":"10.1016\/j.ipm.2026.104831_b64","doi-asserted-by":"crossref","unstructured":"Zhan, Q., Fang, R., Bindu, R., Gupta, A., Hashimoto, T. B., & Kang, D. (2024). Removing RLHF Protections in GPT-4 via Fine-Tuning. In Proceedings of the 2024 conference of the North American chapter of the association for computational linguistics: human language technologies (volume 2: short papers) (pp. 681\u2013687).","DOI":"10.18653\/v1\/2024.naacl-short.59"},{"key":"10.1016\/j.ipm.2026.104831_b65","series-title":"Make them spill the beans! coercive knowledge extraction from (production) llms","author":"Zhang","year":"2023"},{"key":"10.1016\/j.ipm.2026.104831_b66","unstructured":"Zhao, X., Yang, X., Pang, T., Du, C., Li, L., Wang, Y.-X., & Wang, W. Y. (2024). Weak-to-Strong Jailbreaking on Large Language Models. In ICML 2024 next generation of AI safety workshop."},{"key":"10.1016\/j.ipm.2026.104831_b67","doi-asserted-by":"crossref","unstructured":"Zheng, W., Zeng, P., Li, Y., Wu, H., Lin, N., Chen, J., Yang, A., & Zhou, Y. (2025). Jailbreaking? One Step Is Enough!. In Proceedings of the 63rd annual meeting of the association for computational linguistics (volume 1: long papers) (pp. 11623\u201311642).","DOI":"10.18653\/v1\/2025.acl-long.570"},{"key":"10.1016\/j.ipm.2026.104831_b68","series-title":"Don\u2019t say no: Jailbreaking LLM by suppressing refusal","author":"Zhou","year":"2024"},{"key":"10.1016\/j.ipm.2026.104831_b69","unstructured":"Zhu, S., Zhang, R., An, B., Wu, G., Barrow, J., Wang, Z., Huang, F., Nenkova, A., & Sun, T. (2024). AutoDAN: Interpretable Gradient-Based Adversarial Attacks on Large Language Models. In First conference on language modeling."},{"key":"10.1016\/j.ipm.2026.104831_b70","series-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023"}],"container-title":["Information Processing &amp; Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0306457326002220?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0306457326002220?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:54:44Z","timestamp":1783101284000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0306457326002220"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":70,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2026,11]]}},"alternative-id":["S0306457326002220"],"URL":"https:\/\/doi.org\/10.1016\/j.ipm.2026.104831","relation":{},"ISSN":["0306-4573"],"issn-type":[{"value":"0306-4573","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"EvoJail: Evolutionary diverse jailbreak prompt generation for large language models","name":"articletitle","label":"Article Title"},{"value":"Information Processing & Management","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.ipm.2026.104831","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104831"}}