Research · curated 16 Sep 2026

‘From Prompt to Perturbation’: An Adaptive Framework for Voice-Based Jailbreaks on Audio LLMs

Coverage timeline

16 Sep 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Voice-based jailbreaks demonstrate that audio-enabled LLM assistants expose additional acoustic-semantic attack surfaces beyond text, which defenders deploying speech interfaces must account for.

Researchers from the University of Sydney, University of Chicago, and UT San Antonio present an adaptive jailbreak framework ('From Prompt to Perturbation') targeting both cascaded audio pipelines (ASR-to-LLM) and end-to-end large audio-language models. The framework uses a feedback-guided mutation engine to automatically generate and refine jailbreak candidates across textual prompts and acoustic perturbations, achieving higher attack success rates than prior methods across six representative audio-based LLM systems.