Echo Chamber: A Context-Poisoning Jailbreak That Bypasses LLM Guardrails

31 Joan_Vendrell 30 6/27/2025, 10:15:03 AM neuraltrust.ai ↗

Comments (30)

kragen · 3h ago
This seems to intentionally omit the details required to reproduce the experiment; therefore we should not treat it as good-faith research. Irreproducible research isn't.
nunez · 2h ago
It felt like AI copy. Apologies to the author if it wasn't.
Plankaluel · 2h ago
Yeah, it's a typical "startup research post", mainly there to have stuff to show to potential investors and customers.
OJFord · 3h ago
Do they really need to redact the instructions for making a Molotov cocktail..? It's not like it's some complex chemical interaction that happens to be available in a specific mix of household cleaning products or something, I mean.
amenhotep · 3h ago
For "harmful" and "dangerous" in these types of papers, replace "embarrassing to the relevant corporation". Then they all make much more sense.
taberiand · 3h ago
That's always my assumption - less about public safety, more about corporate liability.
OJFord · 2h ago
I mean in the article about the jailbreak, I'm not questioning that the model providers would want to prevent it in the first place, or patch it so the jailbreak doesn't work.

The evidence that it worked is a blurred out screenshot with only the odd word like 'molotov' legible. Just doesn't seem necessary for TFA to hide it to me.

amenhotep · 2h ago
Ah, well, that's an important element of kayfabe. They've all agreed to keep up this charade that they're using harmful and dangerous as we actually mean them, so it looks better if you really commit to the bit!
cedws · 3h ago
Personally I find the idea of forbidden knowledge more problematic than the knowledge itself.
jojobas · 3h ago
Sure, but if of all the internet you come for a molotov cocktaile recipe to chatgpt you might as well not deserve the knowledge.
diggan · 3h ago
> Do they really need to redact the instructions for making a Molotov cocktail..?

I don't even understand how/why things like that are OK in some contexts/websites while forbidden in others? Even YouTube, who seems needlessly censor-happy and puritan in the typical American way, allows instructions for how to make molotov cocktails to stay up, why is it somehow more dangerous if LLMs could output those recipes rather than videos with audio or text?

mschuster91 · 3h ago
> Do they really need to redact the instructions for making a Molotov cocktail..?

In some jurisdictions such as Germany, not doing so might land you actual jail time - §52 Abs. 1 Nr. 4 WaffG [1] is very explicit. A punk song containing the (alleged) lyrics ended up with legal youth-protection censorship, for example [2].

With anything that's deemed a weapon of war, of terrorism or mass destruction, one should be very very careful.

[1] https://www.gesetze-im-internet.de/waffg_2002/__52.html

[2] https://de.wikipedia.org/wiki/Wir_wollen_keine_Bullenschwein...

diggan · 3h ago
> deemed a weapon of war, of terrorism or mass destruction

Notably, molotov cocktail isn't part of that law because it's a weapon of the oppressors but rather the opposite.

jojobas · 3h ago
Even Germany doesn't ban Wikipedia for having a variety of recipes to start with.

The author is not in Germany and ideally shouldn't be intimidated by German or North Korean stupid law.

TZubiri · 3h ago
You don't get it, that's fine.

The molotov cocktail is an example, the instructions contained in this article are more dangerous than a molotov cocktail.

inb4 all the leaked prompts and hacked shitty apps

ale42 · 3h ago
The Molotov cocktail is an example, sure, but why blurring the instructions? It's not like it's something particularly difficult to figure out, nor it's offensive content people might be shocked to read.
OJFord · 2h ago
So why redact the Molotov cocktail example and provide those instructions?

Sounds like you don't get it either; we agree.

TZubiri · 27m ago
It's still a weapon, and generally you don't want to distribute information about manufacturing weapons. It also highlighted the relevant keyword to convey the mechanism.
benreesman · 3h ago
The faux-gravitas tone and the blurred content that's on Wikipedia is the worst kind of AI ckickbait. LLM vendors don't have any authority we don't let them have, they have an EULA and some psycho cult leader type as a hype man.

God I can't wait for the crash in NVIDIA stock once the street sobers up.

eatbitseveryday · 3h ago
There are a few uncensored public access LLMs to ask these questions.

This is interesting work to break guardrails, but if the goal is to access this information of harmful content, in the end, I would be looking for other easier solutions.

tehryanx · 3h ago
The goal isn't to access harmful content, that's just how they're demonstrating that this technique can bypass the alignment training. The general case is what's interesting. If the agent you're using to manage the safety controls in your nuclear reactor is trusting it's alignment training to prevent it from doing something dangerous you've made a really bad architecture decision, and this is a showcase of how it could fail.
ycuser2 · 3h ago
Could you tell what these uncensored LLMs are?
benreesman · 3h ago
The Orca work out of IIRC Microsoft Research was producing models like the Dolphin Mixtral. They always punch way above their weight in coding tasks for the same reason good hackers skew irreverent: self-censorship is capability reducing.
diggan · 3h ago
Searching for "abliterated" or "uncensored" on Huggingface reveals a ton of fine-tuned models. Add "LLM" as a suffix and put it in your favorite search engine and you'll find a bunch more.
matthewdgreen · 3h ago
I have no idea what the answer to this question is, but I am waiting for someone to fine-tune the equivalent of an “anarchist cookbook” LLM that’s optimized to help people produce harmful things.
nunodonato · 3h ago
there are quite a few. llama 3.1 uncensored is probably one of the most famous, IIRC
abhisek · 2h ago
Ok! So all the novel jailbreaks and "how I hacked your AI" can make the LLM say something supposedly harmful stuff which is a Google search away anyway. I thought we are past the chat bot phase of LLMs and doing something more meaningful.
evertedsphere · 3h ago
i don't think this can be called a "jailbreak"

it's a prompting "style" that works over a long exchange

nunodonato · 3h ago
3 turns is not a long exchange.
moribunda · 3h ago
Gemini is jail broken by design ;) this type of attack doesn't work on Claude.