AI RESEARCH
FragBench: Cross-Session Attacks Hidden in Benign-Looking Fragments
arXiv CS.AI
•
ArXi:2605.11029v1 Announce Type: cross An attacker can split a malicious goal into sub-prompts that each look benign on their own and only become harmful in combination. Existing LLM safety benchmarks evaluate prompts one at a time, or across turns of a single chat, and so do not look for a malicious signal spread across separate sessions with no shared context.