{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T20:10:06Z","timestamp":1780517406935,"version":"3.54.1"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2024M751050"],"award-info":[{"award-number":["2024M751050"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Hubei Province Postdoctoral Innovation Talent Training Project","award":["2024HBBHCXB042"],"award-info":[{"award-number":["2024HBBHCXB042"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572356"],"award-info":[{"award-number":["62572356"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput. Soc. Syst."],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1109\/tcss.2026.3664981","type":"journal-article","created":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T20:50:40Z","timestamp":1772225440000},"page":"3190-3200","source":"Crossref","is-referenced-by-count":0,"title":["Take off Your Disguise: Detecting Disguised Prompt-Based Jailbreak Attacks Against LLMs"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1345-5736","authenticated-orcid":false,"given":"Hui","family":"Liu","sequence":"first","affiliation":[{"name":"School of Computer Science and Hubei Provincial Key Laboratory of Artificial Intelligence and Smart Learning, Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3898-8003","authenticated-orcid":false,"given":"Fujv","family":"Wen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Hubei Provincial Key Laboratory of Artificial Intelligence and Smart Learning, Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5020-0083","authenticated-orcid":false,"given":"Hongqin","family":"Du","sequence":"additional","affiliation":[{"name":"School of Computer Science and Hubei Provincial Key Laboratory of Artificial Intelligence and Smart Learning, Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2855-4246","authenticated-orcid":false,"given":"Jiabao","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Computer Science, Hefei University of Technology, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4307-9380","authenticated-orcid":false,"given":"Bo","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.aiopen.2023.08.012"},{"key":"ref2","article-title":"Gemini: A family of highly capable multimodal models","author":"Team","year":"2023"},{"key":"ref3","article-title":"The LLAMA 3 herd of models","author":"Grattafiori","year":"2024"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1093\/jamiaopen\/ooaf067"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3497725"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.270"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1609\/aiide.v20i1.31877"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3494265"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3476030"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3747588"},{"key":"ref11","first-page":"5210","article-title":"BackdoorAlign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment","volume":"37","author":"Wang","year":"2024","journal-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1072"},{"key":"ref13","article-title":"Training a helpful and harmless assistant with reinforcement learning from human feedback","author":"Bai","year":"2022"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP55913.2025.11084361"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2024.104222"},{"key":"ref16","first-page":"4711","article-title":"Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction","volume-title":"Proc. USENIX Secur. Symp. (USENIX Secur.)","author":"Liu","year":"2024"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.813"},{"key":"ref18","article-title":"GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Yuan","year":"2024"},{"key":"ref19","article-title":"Guard: Role-playing to generate natural-language jailbreakings to test guideline adherence of large language models","volume-title":"Proc. ICLR Workshop Secure Trustworthy Large Lang. Models","author":"Jin","year":"2024"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3746027.3755726"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.118"},{"key":"ref22","article-title":"Smoke and mirrors: Jailbreaking LLM-based code generation via implicit malicious prompts","author":"Ouyang","year":"2025"},{"key":"ref23","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023"},{"key":"ref24","article-title":"AutoDAN: Interpretable gradient-based adversarial attacks on large language models","author":"Zhu","year":"2023"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49660.2025.10888812"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670388"},{"key":"ref27","article-title":"Data extraction attacks in retrieval-augmented generation via backdoors","author":"Peng","year":"2024"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3482723"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2023.3321345"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2025.3575694"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.304"},{"key":"ref32","article-title":"Detecting language model attacks with perplexity","author":"Alon","year":"2023"},{"key":"ref33","article-title":"Baseline defenses for adversarial attacks against aligned language models","author":"Jain","year":"2023"},{"key":"ref34","article-title":"SmoothLLM: Defending large language models against jailbreaking attacks","author":"Robey","year":"2023"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.ijcnlp-short.2"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.948"},{"key":"ref37","article-title":"Is the system message really important to jailbreaks in large language models?","author":"Zou","year":"2024"},{"key":"ref38","article-title":"Prompt-driven LLM safeguarding via directed representation optimization","author":"Zheng","year":"2024"},{"key":"ref39","article-title":"Llama 3: Open foundation and instruction-tuned language models","year":"2024"},{"key":"ref40","article-title":"Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context","author":"Team","year":"2024"},{"key":"ref41","article-title":"Gpt-4o mini: Advancing cost-efficient intelligence","year":"2024"},{"key":"ref42","article-title":"Gpt-4o system card","author":"Hurst","year":"2024"},{"key":"ref43","first-page":"74764","article-title":"How far can camels go? Exploring the state of instruction tuning on open resources","volume":"36","author":"Wang","year":"2023","journal-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-023-00765-8"},{"key":"ref45","article-title":"When \u2018competency\u2019 in reasoning opens the door to vulnerability: Jailbreaking LLMs via novel complex ciphers","author":"Handa","year":"2024"}],"container-title":["IEEE Transactions on Computational Social Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6570650\/11543411\/11415694.pdf?arnumber=11415694","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T19:43:51Z","timestamp":1780515831000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11415694\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":45,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tcss.2026.3664981","relation":{},"ISSN":["2329-924X","2373-7476"],"issn-type":[{"value":"2329-924X","type":"electronic"},{"value":"2373-7476","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6]]}}}