{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T15:55:20Z","timestamp":1759334120051,"version":"build-2065373602"},"reference-count":36,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T00:00:00Z","timestamp":1752624000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T00:00:00Z","timestamp":1752624000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,7,16]]},"DOI":"10.1109\/qrs65678.2025.00017","type":"proceedings-article","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T17:51:28Z","timestamp":1759168288000},"page":"58-67","source":"Crossref","is-referenced-by-count":0,"title":["Defending Llms Against Jailbreak Prompts Through Key Information Protection and Selective Compression"],"prefix":"10.1109","author":[{"given":"Siyu","family":"Li","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics,Nanjing,Jiangsu,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Zhou","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics,Nanjing,Jiangsu,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics,Nanjing,Jiangsu,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tingting","family":"Han","sequence":"additional","affiliation":[{"name":"Birkbeck, University of London,London,United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"journal-title":"Jailbreaking and mitigation of vulnerabilities in large language models","year":"2024","author":"Peng","key":"ref1"},{"key":"ref2","first-page":"1","article-title":"Fine-tuning aligned language models compromises safety, even when users do not intend to!","author":"Qi","year":"2024","journal-title":"ICLR"},{"journal-title":"Advprompter: Fast adaptive adversarial prompting for llms","year":"2024","author":"Paulus","key":"ref3"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/satml64287.2025.00010"},{"journal-title":"Universal and transferable adversarial attacks on aligned language models","year":"2023","author":"Zou","key":"ref5"},{"journal-title":"Weak-to-strong jailbreaking on large language models","year":"2024","author":"Zhao","key":"ref6"},{"journal-title":"Red-Teaming Large Language Models using Chain of Utterances for SafetyAlignment","year":"2023","author":"Bhardwaj","key":"ref7"},{"journal-title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","year":"2023","author":"Jain","key":"ref8"},{"journal-title":"Parden, Can You Repeat That? Defending against Jailbreaks via Repetition","year":"2024","author":"Zhang","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.92"},{"key":"ref11","article-title":"Autodan: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","volume-title":"International Conference on Learning Representations","author":"Liu","year":"2023"},{"key":"ref12","article-title":"Jailbroken: How Does LLM Safety Training Fail?","author":"Wei","year":"2023","journal-title":"Neural Information Processing Systems"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2025.107699"},{"key":"ref14","article-title":"Llm Self Defense: By Self Examination, LLMs Know They Are Being Tricked","author":"Phute","year":"2023","journal-title":"Tiny Papers @ ICLR"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2025.107699"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3630010"},{"journal-title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models.","year":"2023","author":"Jain","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.302"},{"journal-title":"FlexLLM: Exploring LLM Customization for Moving Target Defense on Black-Box LLMs Against Jailbreak Attacks","year":"2024","author":"Chen","key":"ref19"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.598"},{"journal-title":"Mistral 7b","year":"2023","author":"Jiang","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3457913.3457937"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3728639"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3501256"},{"journal-title":"An overview of gradient descent optimization algorithms","year":"2016","author":"Ruder","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177729694"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-9868.2005.00503.x"},{"key":"ref28","first-page":"11387","article-title":"Individual calibration with randomized forecasting","volume-title":"International Conference on Machine Learning","author":"Zhao","year":"2020"},{"journal-title":"Qwen2 technical report","year":"2024","author":"Yang","key":"ref29"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.90"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P17-1147"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.568"},{"key":"ref33","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023","journal-title":"CoRR, abs\/2307.15043"},{"key":"ref34","first-page":"1","article-title":"Explaining time series via contrastive and locally sparse perturbations","author":"Liu","year":"2024","journal-title":"ICLR"},{"key":"ref35","article-title":"Smoothllm: Defending large language models against jailbreaking attacks","author":"Robey","year":"2023","journal-title":"CoRR, abs\/2310.03684"},{"key":"ref36","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023","journal-title":"CoRR, abs\/2307.09288"}],"event":{"name":"2025 25th International Conference on Software Quality, Reliability and Security (QRS)","start":{"date-parts":[[2025,7,16]]},"location":"Hangzhou, China","end":{"date-parts":[[2025,7,20]]}},"container-title":["2025 25th International Conference on Software Quality, Reliability and Security (QRS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11173421\/11173424\/11173493.pdf?arnumber=11173493","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,30]],"date-time":"2025-09-30T12:48:17Z","timestamp":1759236497000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11173493\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,16]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/qrs65678.2025.00017","relation":{},"subject":[],"published":{"date-parts":[[2025,7,16]]}}}