TACS: Trajectory-Aware Candidate Selection for LLM Jailbreak Suffix Optimization
The paper argues that jailbreak suffix search is losing quality at the candidate-selection step, not just in candidate generation.
Shiliang Xiao says common gradient-based methods pick the suffix candidate with the lowest immediate loss, a choice the paper calls myopic. TACS instead scores candidates with a trajectory-aware proxy, reference-policy regularization, and a discriminator-estimated chi-squared correction. On HarmBench, the abstract says it beats strong baselines under the same search budget, with higher attack success rates and steadier optimization behavior. ArXiv · AI/CL/LG's note
Shiliang Xiao says common gradient-based methods pick the suffix candidate with the lowest immediate loss, a choice the paper calls myopic. TACS instead scores candidates with a trajectory-aware proxy, reference-policy regularization, and a discriminator-estimated chi-squared correction. On HarmBench, the abstract says it beats strong baselines under the same search budget, with higher attack success rates and steadier optimization behavior. ArXiv · AI/CL/LG's note
score 4