Research
Jailbreaking Open-Weight LLMs via Random Embedding Perturbations
Publication date unknown · Discovered arxiv.org
Page published
Publication date unknown · First observed: 8 Oct 2026
Coverage timeline
Single-source research — one report is available.
Why it matters
PEV demonstrates a cheap, fast, optimization-free way to bypass safety guardrails across widely adopted open-weight LLMs, lowering the barrier for attackers and exposing a systemic weakness defenders must account for when deploying such models.
Researchers from UC Santa Cruz present Perturbed Embedding Vector (PEV), a jailbreak technique that adds independent Gaussian noise to the embedding vectors of prompts to elicit unsafe responses from six open-weight LLMs on the JailbreakBench benchmark. PEV requires no gradient computations, per-prompt optimization, or weight modification, and achieves its first successful jailbreak within about one minute per model at up to an order of magnitude lower compute cost than prior attacks.