Open Source RadarNotícias G
Open Source RadarNotícias
Open Source RadarInteligência de Notícias Entrar Projetos
Todos os eventos
Pesquisa Incidente Imediato 1 matérias

Prefilling the Reasoning Channel: Output-Prefix Attacks on Reasoning LLMs

Large Language Models (LLMs) consume and produce a single sequence of text; hence, if text can be added to the beginning of the LLM's response, i.e., an output prefix, then all subsequent tokens will be conditioned on it. This output-prefix attack technique is a cheap black-box prompt injection. Prior work has shown this type of attack can reliably jailbreak non-reasoning models. Most reasoning models add an intermediate scratchpad reasoning step before the assistant's final response. The ability to edit this reasoning channel is exposed by some APIs and attack vectors can be leveraged for reasoning injection attacks. We present the first systematic, controlled study that isolates the scratchpad reasoning channel as an output-prefix attack vector, and the first to compare reasoning-only, output-prefix-only and reasoning-plus-output-prefix attacks across both exposed- and hidden-reasonin…

Evento consolidado
Gerenciar alertas
Análise do Radar

O que aconteceu e por que importa

Inteligência do evento

Por que este sinal merece atenção

Comparar com Em Alta
85Relevânciaforça do sinal no contexto atual
34Tendênciavelocidade e recorrência do movimento
100Novidadequanto o sinal adiciona informação nova
Não identificadoImpacto Brasilabrir contexto nacional
Primeiro sinal24/09/2026 13:18
Último sinal24/09/2026 13:18
0horas em evolução
1fontes distintas
Evidências

Timeline do evento

1 matéria(s)
24/09 13:18
arXiv cs.AIGlobal
Prefilling the Reasoning Channel: Output-Prefix Attacks on Reasoning LLMs
Large Language Models (LLMs) consume and produce a single sequence of text; hence, if text can be added to the beginning of the LLM's response, i.e., an output prefix, then all subsequent tokens will be conditioned on it. This output-prefix attack technique is a cheap black-box prompt injection. Prior work has shown this type of attack can reliably jailbreak non-reasoning models. Most reasoning models add an intermediate scratchpad reasoning step before the assistant's final response. The ability to edit this reasoning channel is exposed by some APIs and attack vectors can be leveraged for reasoning injection attacks. We present the first systematic, controlled study that isolates the scratchpad reasoning channel as an output-prefix attack vector, and the first to compare reasoning-only, output-prefix-only and reasoning-plus-output-prefix attacks across both exposed- and hidden-reasonin…
Abrir fonte original
Receba o Radar Diário grátis
Todo dia às 8h: as notícias e os projetos open source de IA que importam, com contexto em português e a análise completa em PDF.
Prefere começar pelo PDF de hoje? Baixe o panorama.