arXiv:2606. 07968v1 Announce Type: cross Abstract: Reasoning-capable large language models can be induced to spend their generation budget on injected decoy tasks rather than answering the user's question, causing denial of service when no final answer is produced and denial of wallet when excess output tokens are billed.
By Abid Aziz, Hafsa Binte Kibria
Large Reasoning Models (LRMs) use explicit chain‑of‑thought reasoning and large context windows to perform complex tasks, but these features create new attack surfaces. The paper introduces SRCF, an attack that steers LRMs by prepending counter‑aligned few‑shot conversations with explicit CoT traces, causing unsafe outputs on harmful queries and unwarranted refusals on benign ones, without needing model internals. To counter this, the authors propose ARCF, a post‑training defense that exposes models to counter‑aligned conversational contexts while enforcing aligned targets, improving safety and helpfulness without harming utility.
By Xiangyu Zhou, Saleh Zare Zade, Dongxiao Zhu
The paper investigates a new attack method called output‑prefix attacks on reasoning LLMs, where an attacker prepends a malicious text to the model’s output, thereby conditioning all subsequent tokens on that prefix. The study systematically isolates the scratchpad reasoning channel as a vulnerable vector and compares three attack types—reasoning‑only, output‑prefix‑only, and combined reasoning‑plus‑output‑prefix—across both exposed and hidden reasoning models. Experiments on three 2026‑era frontier models (Gemini 3 Flash Preview, DeepSeek V4 Flash, and Claude Haiku 4.5) show that reasoning alone is largely ineffective, but adding a trivial output prefix can raise attack success rates to as high as 99% for some models, with contextual prefixes outperforming static ones and susceptibility varying by model.
By Luk\'a\v{s} Br\r{u}na, Robert Bridges, Adam Ek
Large Language Models (LLMs) consume and produce a single sequence of text; hence, if text can be added to the beginning of the LLM's response, i.e., an output prefix, then all subsequent tokens will...
arXiv:2506. 07031v5 Announce Type: replace-cross Abstract: Emerging Large Reasoning Models (LRMs) consistently excel in mathematical and reasoning tasks, showcasing remarkable capabilities.
By Jingyuan Ma, Rui Li, Zheng Li, Junfeng Liu, Heming Xia, Lei Sha, Zhifang Sui
arXiv:2606. 02835v1 Announce Type: new Abstract: Large Reasoning Models (LRMs) improve performance by generating explicit intermediate reasoning traces through increased test-time compute, yet the assumption that longer reasoning is consistently beneficial remains under-examined.
By Simone Caldarella, Davide Talon, Rahaf Aljundi, Elisa Ricci, Massimiliano Mancini