Analysis · curated 16 Sep 2026
LLM Jailbreak Examples: 10 Documented Patterns
First reported aiattacks.dev
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
The jailbreak-pattern catalog gives defenders a taxonomy of transferable attack mechanisms and detection signals that survive individual patch cycles, rather than stale copy-paste prompt lists.
An evergreen catalog on aiattacks.dev describes ten documented LLM jailbreak patterns at the level of mechanism rather than payload, including persona hijacking (DAN-class), multi-turn escalation (Crescendo), payload splitting, many-shot flooding, cross-lingual attacks, encoding/obfuscation, Best-of-N random augmentation, GCG gradient-optimized suffixes, AutoDAN, and multimodal/visual injection. Each entry cites peer-reviewed or vendor-published research, states reported effectiveness, and lists a primary detection signal for defenders.