FragBench: Cross-Session Attacks Hidden in Benign-Looking Fragments

📰 ArXiv cs.AI

arXiv:2605.11029v1 Announce Type: cross Abstract: An attacker can split a malicious goal into sub-prompts that each look benign on their own and only become harmful in combination. Existing LLM safety benchmarks evaluate prompts one at a time, or across turns of a single chat, and so do not look for a malicious signal spread across separate sessions with no shared context. We build FragBench, a benchmark drawn from 24 real-world cyber-incident campaigns, which keeps the full attack trail: the mu

Published 13 May 2026
Read full paper → ← Back to Reads