cs.AIOct 3, 2026

Reactivating Alignment: Defending LLMs from Jailbreaks via Intention-Aware Input-Output Matching

Authors: Luoyu Chen, Weiqi Wang, Chenhan Zhang, Zhiyi Tian, Shui Yu

Organizations: University of Technology Sydney, Sydney, NSW, Australia · Xi’an Jiaotong University, Xi’an, Shaanxi, China · Southeast University, Nanjing, Jiangsu, China

Abstract

Large language models (LLMs) remain vulnerable to jailbreak attacks that conceal harmful intent within complex adversarial prompts. Existing defenses primarily rely on input perturbation or harmful-output suppression, but they rarely model where malicious intent resides, resulting in brittle protection and excessive over-refusal. We propose SENTINEL, a plug-and-play, generation-time jailbreak defense that reframes mitigation as an intent extraction problem. Our key insight is that instruction-tuned LLMs exhibit strong input--output semantic consistency: regardless of jailbreak complexity, generated outputs tend to align with the attacker's true intent. SENTINEL exploits this property by matching semantically aligned input--output regions to extract intention-revealing subsequences, scores these subsequences using refusal-direction projections to estimate harmfulness, and halts generation when necessary. Experiments on HarmBench across multiple LLMs show that SENTINEL reduces jailbreak success rates to close to 5% while maintaining low over-refusal. We further demonstrate robustness to adaptive attacks and provide a mechanistic interpretation: SENTINEL re-distributes jailbreak features from alignment blind spots to aligned regions.

Explore similar work

CardsList
  1. Re-Triggering Safeguards within LLMs for Jailbreak Detection

    May 11, 2026Zheng Lin, Zhenxing Niu, Haoxuan Ji +2LLM Jailbreak AttacksJailbreak Detection

  2. Why Do Aligned LLMs Remain Jailbreakable: Refusal-Escape Directions, Operator-Level Sources, and Safety-Utility Trade-off

    May 9, 2026Yu Chen, Yuanhao Liu, Qi CaoLLM AlignmentLanguage Model Steering

  3. AlcaTRAz - Anchored Tree-Rule Defense Against Jailbreaks

    Sep 3, 2026Jakub Reš, Petr Kaška, Martin Perešíni +2LLM SafetyJailbreak Defense