{"id":"W4407185097","doi":"10.48550/arxiv.2502.01925","title":"PANDAS: Improving Many-shot Jailbreaking via Positive Affirmation, Negative Demonstration, and Adaptive Sampling","year":2025,"lang":"en","type":"preprint","venue":"ArXiv.org","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Natural Sciences and Engineering Research Council of Canada; Government of Canada; Canadian Institute for Advanced Research","keywords":"Shot (pellet); Sampling (signal processing); Computer science; Psychology; Chemistry; Telecommunications","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.005101543,0.002048271,0.001915364,0.0009816824,0.001296619,0.001602843,0.003340928,0.002514948,0.004262934],"category_scores_gemma":[0.01775857,0.0006406445,0.001132137,0.0004174041,0.001967666,0.003346076,0.004354623,0.004180715,0.00205689],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009137287,"about_ca_system_score_gemma":0.00141585,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002415696,"about_ca_topic_score_gemma":0.00389206,"domain_scores_codex":[0.9962716,0.00160729,0.0001764126,0.0009135193,0.0007334218,0.0002978529],"domain_scores_gemma":[0.9898531,0.005556966,0.0006129381,0.002793375,0.0006825297,0.0005012057],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.002429762,0.001225638,0.007887311,0.0005945441,0.0005065802,0.0005422687,0.0009120687,0.3056393,0.04300881,0.01622799,0.02828598,0.5927397],"study_design_scores_gemma":[0.00006571287,0.0003447618,0.0005184587,0.00002367401,0.00003671703,0.000168322,0.00008142494,0.9778556,0.01016539,0.008450625,0.002248103,0.00004111696],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.2049751,0.002343943,0.7462398,0.001390915,0.000674364,0.0005099841,0.0006304524,0.03553677,0.007698717],"genre_scores_gemma":[0.847811,0.0001807789,0.1425824,0.0009412316,0.0001961722,0.0002099505,0.001199928,0.0008001556,0.006078373],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.005101543,"threshold_uncertainty_score":0.02697986,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0412861917263239,"score_gpt":0.2938946394752073,"score_spread":0.2526084477488834,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}