arXiv:2605.18239cs.CLcs.AI2026-05

用非洲低资源语言多轮对话,可绕过主流大模型安全防护。

Multilingual jailbreaking of LLMs using low-resource languages

论文配图:Multilingual jailbreaking of LLMs using low-resource languages
图 1 · 摘自论文原文
  • 用阿非利卡语等低资源语言进行多轮对话攻击
  • 最高攻击成功率达83.6%(GPT-4o-mini)
  • 翻译质量差会限制攻击效果,适合安全研究者参考

大型语言模型仍易受越狱攻击,可绕过安全防护。本文探究使用低资源非洲语言(阿非利卡语、斯瓦希里语、科萨语、祖鲁语)进行多轮对话,是否能突破商业大模型的安全机制。将现有数据集中的提示语翻译后,对ChatGPT、Claude、DeepSeek、Gemini和Grok进行了自动化测试与母语者人工红队测试。单轮翻译攻击无效,而多轮对话在英文有害响应中成功率从52.7%(Claude 3.5 Haiku)到83.6%(GPT-4o-mini),阿非利卡语为60.0%至78.2%,斯瓦希里语为41.8%至70.9%。人工红队比自动方法提升更多。所有语言平均攻击率从59.8%升至75.8%,增幅分别为+20.0%(阿非利卡语)、+12.7%(祖鲁语)、+12.3%(科萨语)、+1%(斯瓦希里语),表明翻译质量是决定越狱成败的关键因素。结果说明,大模型在多语言场景下仍存漏洞,翻译质量直接影响攻击效果。

原文摘要 · Abstract (English)

Large Language Models (LLMs) remain vulnerable to jailbreak attempts that circumvent safety guardrails. We investigate whether multi-turn conversations using low-resource African languages (Afrikaans, Kiswahili, isiXhosa, and isiZulu) can bypass safety mechanisms across commercial LLMs. We translated prompts from existing datasets and evaluated ChatGPT, Claude, DeepSeek, Gemini, and Grok through automated testing and human red-teaming with native speakers. Single-turn translation attacks proved ineffective, while multi-turn conversations achieved English harmful response rates from 52.7% (Claude 3.5 Haiku) to 83.6% (GPT-4o-mini), Afrikaans from 60.0% (Claude 3.5 Haiku) to 78.2% (GPT-4o-mini), and Kiswahili from 41.8% (Claude 3.5 Haiku) to 70.9% (DeepSeek). Human red-teaming increased jailbreak rates compared to automated methods. Over all evaluated languages, the average jailbreak rate increased from 59.8% to 75.8%, with improvements of +20.0% (Afrikaans), +12.7% (isiZulu), +12.3% (isiXhosa), and +1% (Kiswahili), demonstrating that poor translation quality limits jailbreak success. These findings suggest that vulnerabilities in LLMs persist in multilingual contexts and that translation quality is the critical factor determining jailbreak success in low-resource languages.

越狱攻击多语言安全评估低资源语言

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。