MLCommons Jailbreak Benchmark v1.0

πŸ“… 2026-10-02
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the lack of systematic quantitative evaluation methods for assessing the safety robustness of large language models under jailbreak attacks. To this end, we construct an end-to-end evaluation pipeline that employs a taxonomy-driven attack selection strategy based on the AILuminate benchmark, integrating human annotation with automated calibration mechanisms. Furthermore, we introduce a "resilience gap" metric to precisely quantify the divergence in safety performance between baseline and adversarial conditions. This work establishes a reproducible comparative benchmark alongside a risk disclosure framework. Experimental results demonstrate that models exhibit an average resilience gap of 7.57%, with unsafe response rates increasing significantly from 11.08% to 18.65%, thereby revealing substantial safety vulnerabilities in current large language models.
πŸ“ Abstract
Modern AI systems are designed to refuse hazardous requests. A jailbreak is a prompt crafted to bypass those safeguards and elicit outputs that the system would normally refuse to provide. The MLCommons Jailbreak Benchmark v1.0 provides an end-to-end methodology for evaluating the robustness of large language models to single-turn, text-based jailbreak attacks. It combines criteria-driven system and attack selection, paired baseline and adversarial evaluation, human annotation, automated evaluator calibration, scoring, grading, and risk-calibrated disclosure within a single benchmarking pipeline. The benchmark evaluates eight open-weight systems using 264 seed prompts spanning eleven hazard categories and representative attacks drawn from the MLCommons Jailbreak Taxonomy. Responses are assessed using the AILuminate Assessment Standard v1.4, and robustness is measured through the Resilience Gap: the change in safety performance between baseline and adversarial conditions. Across all evaluated systems and attacks, the unsafe-response rate increased from 11.08% under baseline conditions to 18.65% under jailbreak conditions, producing an average Resilience Gap of 7.57%. Accessible systems showed a larger mean gap, while attack effectiveness varied substantially across attack categories and hazards. The benchmark also examines evaluator reliability and sources of measurement error. Beyond reporting results, Jailbreak Benchmark v1.0 establishes a reproducible methodological foundation for comparative jailbreak evaluation and for future expansion across systems, attacks, hazards, and evaluation methods.
Problem

Research questions and friction points this paper is trying to address.

Jailbreak attacks
Large language models
Safety robustness
Resilience Gap
AI safety evaluation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Jailbreak Benchmark
Resilience Gap
Large Language Models
Adversarial Evaluation
Safety Robustness
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
Carsten Maple
Carsten Maple
Professor of Cyber Systems Engineering, University of Warwick
SecurityPrivacy and Trust
C
Cagatay Yucel
University of Warwick
I
Isaac Holeman
MLCommons, Working Paper
C
Chris Knotz
MLCommons
Peter Mattson
Peter Mattson
MLCommons
J
James Goel
MLCommons, Qualcomm
Jonathan Petit
Jonathan Petit
Qualcomm
Computer ScienceVehicular NetworksDistributed SystemsSecurityPrivacy
S
Sean McGregor
MLCommons, AVERI
J
James Ezick
MLCommons, Qualcomm
A
Abhishek Kumar
The Alan Turing Institute
Alicia Parrish
Alicia Parrish
Google DeepMind
cognitive sciencecrowdsourcingdata-centric AIresponsible AI
M
Murali Emani
Argonne National Laboratory
K
Kashyap Iyer
University of Illinois Urbana-Champaign
Faiza Khan Khattak
Faiza Khan Khattak
Monark Health
Natural language processingResponsible AIBias & Fairness in LMsAI for Healthcare
W
Washington Mbonu
University of Warwick
D
Daniel Machlab
NVIDIA
E
Eileen Long
NVIDIA
S
Shaona Ghosh
NVIDIA
J
Jibin Varghese
NVIDIA
Roman Lutz
Roman Lutz
Responsible AI Engineer at Microsoft
Responsible AIAI Red Teaming
A
Andrew Gruen
MLCommons, Working Paper
B
Bennett Hillenbrand
MLCommons, Working Paper
P
Prabal Gupta
Rama Labs
D
Dhivya Nagasubramanian
Independent
M
Mohammed Serrhini
UniversitΓ© Mohammed Premier Oujda, Mohammed First University