[2602.14689] Exposing the Systematic Vulnerability of Open-Weight Models to Prefill Attacks
Abstract:As the capabilities of large language models continue to advance, so does their potential for misuse. While closed-source models typically rely on external defenses, open-weight models must primarily depend on internal safeguards to mitigate harmful behavior. Prior red-teaming research has largely focused on input-based jailbreaking and parameter-level manipulations. However, open-weight models also natively support prefilling, which allows an attacker to predefine initial response tokens before generation begins. Despite its potential, this attack vector has received little systematic attention. We present the largest empirical study to date of prefill attacks, evaluating over 20 existing and novel strategies across multiple model families and state-of-the-art open-weight models. Our results show that prefill attacks are consistently effective against all major contemporary open-weight models, revealing a critical and previously underexplored vulnerability with significant implications for deployment. While certain large reasoning models exhibit some robustness against generic prefilling, they remain vulnerable to tailored, model-specific strategies. Our findings underscore the urgent need for model developers to prioritize defenses against prefill attacks in open-weight LLMs.
Exposing the Systematic Vulnerability of Open-Weight Models to Prefill Attacks Lukas Struppek, Adam Gleave, Kellin Pelrine, FAR.AI As the capabilities of large language models continue to impact of vulnerabilities [Casper et al., 2025]. Despite improve- advance, so does their potential for misuse. While closed- ments in alignment, researchers continue to find input-based jail-…
saved by
related reading
- A Safe Path to Open Weights - Thinking Machines Labthinkingmachines.ai
- Prefill Awareness in Large Language Modelsarxiv.org
- Prefill awareness: can LLMs tell when “their” message history has been tampered with? — LessWronglesswrong.com
- Several frontier models are substantially prefill aware — LessWronglesswrong.com
- Inkling: Our Open-Weights Model - Thinking Machines Labthinkingmachines.ai
- A small number of samples can poison LLMs of any size \ Anthropicanthropic.com
- [2502.05209] Model Tampering Attacks Enable More Rigorous Evaluations of LLM Capabilitiesarxiv.org
- [2608.07514] Open Technical Problems in Open-Weight AI Model Risk Managementarxiv.org
- 2408.12798arxiv.org
- Announcing Safety Research Grantsthinkingmachines.ai
- Model Tampering Attacks Enable More Rigorous Evaluations of LLM Capabilitiesarxiv.org
- What I learned this week - Can distillation be stopped, Mythos and the cybersecurity equilibrium, Pipeline RLdwarkesh.com