AI RESEARCH
Guaranteed Jailbreaking Defense via Disrupt-and-Rectify Smoothing
arXiv CS.AI
•
ArXi:2605.10582v1 Announce Type: cross This paper proposes a guaranteed defense method for large language models (LLMs) to safeguard against jailbreaking attacks. Drawing inspiration from the denoised-smoothing approach in the adversarial defense domain, we propose a novel smoothing-based defense method, termed Disrupt-and-Rectify Smoothing (DR-Smoothing). Specifically, we integrate a two-stage prompt processing scheme-first disrupting the input prompt, then rectifying it-into the conventional smoothing defense framework.