{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T05:46:37Z","timestamp":1776750397329,"version":"3.51.2"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402117"],"award-info":[{"award-number":["62402117"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272463"],"award-info":[{"award-number":["62272463"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Lett."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/lsp.2026.3677330","type":"journal-article","created":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T19:51:41Z","timestamp":1774381901000},"page":"1536-1540","source":"Crossref","is-referenced-by-count":0,"title":["GRA: Graph-Based Role-Playing Attack for Single-Turn Jailbreak"],"prefix":"10.1109","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0447-7635","authenticated-orcid":false,"given":"Anda","family":"Liu","sequence":"first","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7957-0441","authenticated-orcid":false,"given":"Zhengxian","family":"Wu","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4199-2988","authenticated-orcid":false,"given":"Juan","family":"Wen","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wanli","family":"Peng","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6288-6117","authenticated-orcid":false,"given":"Changtong","family":"Dou","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"GPT-4 technical report","author":"Achiam","year":"2023"},{"key":"ref2","article-title":"Palm 2 technical report","author":"Anil","year":"2023"},{"key":"ref3","first-page":"1877","article-title":"Language models are few-shot learners","volume":"33","author":"Brown","year":"2020","journal-title":"Advances neural inf. process. syst."},{"key":"ref4","article-title":"Evaluating large language models trained on code","author":"Chen","year":"2021"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2997"},{"key":"ref6","article-title":"ToolLLM: Facilitating large language models to master 16000+ real-world APIs","author":"Qin","year":"2023"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2011"},{"key":"ref8","first-page":"26874","article-title":"RLAIF vs. RLHF: Scaling reinforcement learning from human feedback with AI feedback","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"235","author":"Lee","year":"2023"},{"key":"ref9","article-title":"Constitutional AI: Harmlessness from AI feedback","author":"Bai","year":"2022"},{"key":"ref10","article-title":"Trustworthy LLMs: A survey and taxonomy of safety, privacy, and fairness of large language models","author":"Liu","year":"2023"},{"key":"ref11","article-title":"Ai safety in generative large language models: A survey","author":"Jaymari","year":"2024"},{"key":"ref12","first-page":"1831","article-title":"Formalizing and benchmarking prompt injection attacks and defenses","volume-title":"Proc. USENIX Secur. Symp.","author":"Liu","year":"2024"},{"key":"ref13","article-title":"An early categorization of prompt injection attacks on large language models","author":"Rossi","year":"2024"},{"key":"ref14","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023"},{"key":"ref15","article-title":"Improved techniques for optimization-based jailbreaking on large language models","author":"Jia","year":"2024"},{"key":"ref16","article-title":"Mask-GCG: Are all tokens in adversarial suffixes necessary for jailbreak attacks?","author":"Mu","year":"2025"},{"key":"ref17","article-title":"AttnGCG: Enhancing jailbreaking attacks on LLMs with attention manipulation","volume-title":"Trans. Mach. Learn. Res.","volume":"2025","author":"Wang","year":"2024"},{"key":"ref18","article-title":"Autodan-turbo: A lifelong agent for strategy self-exploration to jailbreak LLMS","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Liu","year":"2025"},{"key":"ref19","first-page":"80079","article-title":"Jailbroken: How does LLM safety training fail?","volume":"36","author":"Wei","year":"2023","journal-title":"Advances Neural Inf. Process. Syst."},{"key":"ref20","article-title":"`Do anything now\u2019: Characterizing adversarial prompts in text-to-image generation","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Shen","year":"2024"},{"key":"ref21","article-title":"Masterkey: Automated jailbreaking of LLMs","author":"Deng","year":"2023"},{"key":"ref22","first-page":"3984","article-title":"GPTFUZZER: A GPT-based fuzzer to jailbreak aligned LLMs","volume-title":"Proc. ACM SIGSAC Conf. Comput. Commun. Secur.","author":"Yu","year":"2023"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.773"},{"key":"ref24","first-page":"15157","article-title":"Artprompt: Ascii art-based jailbreak attacks against aligned LLMs","volume-title":"Proc. 62nd Ann. Meeting Assoc. Comput. Linguistics","volume":"1","author":"Jiang","year":"2024"},{"key":"ref25","first-page":"31245","article-title":"FlipAttack: Jailbreak LLMs via flipping","volume-title":"Proc. 42nd Int. Conf. Mach. Learn.","volume":"267","author":"Liu","year":"2025"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-naacl.224"},{"key":"ref27","first-page":"129696","article-title":"Many-shot jailbreaking","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"37","author":"Anil","year":"2024"},{"key":"ref28","article-title":"Visual-roleplay: Universal jailbreak attack on multimodal large language models via role-playing image characte","author":"Ma","year":"2024"},{"key":"ref29","article-title":"Rolebreak: Character hallucination as a jailbreak attack in role-playing systems","volume-title":"Proc. 31st Int. Conf. Comput. Linguistics","author":"Tang","year":"2025"},{"key":"ref30","article-title":"OpenAI models - GPT-5","year":"2025"},{"key":"ref31","article-title":"OpenAI models - GPT-4.1","year":"2025"},{"key":"ref32","article-title":"Gemini models","author":"DeepMind","year":"2025"},{"key":"ref33","article-title":"Introducing Claude 3.5 Sonnet","year":"2024"},{"key":"ref34","article-title":"Anthropic models - Claude","year":"2025"},{"key":"ref35","article-title":"QwenLM github repository","author":"Cloud","year":"2025"},{"key":"ref36","article-title":"Deepseek models","author":"AI","year":"2025"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1745"},{"key":"ref38","article-title":"Harmbench: A standardized evaluation framework for automated red teaming and robust refusal","author":"Mazeika","year":"2024"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3984"},{"key":"ref40","article-title":"CodeChameleon: Personalized encryption framework for jailbreaking large language models","author":"Lv","year":"2024"}],"container-title":["IEEE Signal Processing Letters"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/97\/11304147\/11455216.pdf?arnumber=11455216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T05:18:20Z","timestamp":1776748700000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11455216\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/lsp.2026.3677330","relation":{},"ISSN":["1070-9908","1558-2361"],"issn-type":[{"value":"1070-9908","type":"print"},{"value":"1558-2361","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}