AI RESEARCH

FragBench: Cross-Session Attacks Hidden in Benign-Looking Fragments

arXiv CS.AI

ArXi:2605.11029v1 Announce Type: cross An attacker can split a malicious goal into sub-prompts that each look benign on their own and only become harmful in combination. Existing LLM safety benchmarks evaluate prompts one at a time, or across turns of a single chat, and so do not look for a malicious signal spread across separate sessions with no shared context.