CDIM: Cross-Domain Isomorphic Mapping for Efficient Black-Box Jailbreak Attacks
Abstract
Jailbreak attacks are an effective paradigm for testing the safety boundaries of Large Language Models (LLMs), exposing vulnerabilities to facilitate the development of robust defenses. Existing black-box jailbreak methods primarily rely on search-based prompt optimization or long-context construction, which typically suffer from high query overhead and insufficient stealth when targeting frontier models. To address these limitations, we propose Cross-Domain Isomorphic Mapping (CDIM), a novel black-box jailbreak framework that conceals and executes malicious intents through structurally analogous yet semantically benign carriers. By recoding sensitive requests into Out-of-Distribution (OOD) expressions that are superficially harmless but logically isomorphic, CDIM systematically improves attack stealthiness while minimizing query costs. Mechanistically, CDIM operates in three stages: (1) Mapping Construction, which selects a safe semantic domain and builds a bijective dictionary between sensitive semantics and benign carriers; (2) Isomorphic Simulation, which restricts the target model's generation within the safe semantic space while preserving the original procedural logic; and (3) Backward Recovery, which decodes the implicit benign output back into actionable sensitive content. Extensive experiments on two mainstream jailbreak benchmarks demonstrate CDIM's superior efficiency and effectiveness. Notably, with merely three queries, CDIM achieves an average attack success rate of 65.2% against Claude Sonnet 4.5 , significantly outperforming existing baselines.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.