RESEARCH. CONNECTED.

Explore the scholarly record.

Discover prefix ownership, publishers, journals and DOI metadata. Understand the data behind every publication.

XBreaking: understanding how LLMs security alignment can be broken

Marco Arazzi, Vignesh Kumar Kembu, Antonino Nocera iD, Vinod P.

DOI10.1007/s00521-026-12511-3
PublisherSpringer Science and Business Media LLC
Journal / SourceNeural Computing and Applications
Published2026-10
Metadata Deposited2026-10-10 (updated: 2026-10-10)
Subject—
Languageen
ISSN0941-0643, 1433-3058
Typejournal-article
Volume / Issue / Pages38 / 19 / —
Citations0
References deposited75
Access / license metadataOpen license identified License 1 ↗A reuse license does not by itself establish whether the full text is freely readable.

Abstract

Abstract Large Language Models are fundamental actors in the modern IT landscape dominated by AI solutions. However, security threats associated with them might prevent their reliable adoption in critical application scenarios such as government organizations and medical institutions. For this reason, commercial LLMs typically undergo a sophisticated censoring mechanism to eliminate any harmful output they could possibly produce. These mechanisms maintain the integrity of LLM alignment by guaranteeing that the models respond safely and ethically. In response to this, attacks on LLMs are a significant threat to such protections, and many previous approaches have already demonstrated their effectiveness across diverse domains. Existing LLM attacks mostly adopt a generate-and-test strategy to craft malicious input. To improve the comprehension of censoring mechanisms and design a targeted attack, we propose an Explainable AI (XAI) solution that comparatively analyzes the behavior of censored and uncensored models to derive unique exploitable alignment patterns. Then, we propose XBreaking , a novel approach that exploits these unique patterns to break the security and alignment constraints of LLMs by targeted noise injection. Our thorough experimental campaign returns important insights about the censoring mechanisms and demonstrates the effectiveness and performance of our approach. Content Warning: This paper contains examples of harmful language