{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_0b97440b08afae73f794c56a6c64e55b7421cf551077d14819a9425ff136986c","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_0b97440b08afae73f794c56a6c64e55b7421cf551077d14819a9425ff136986c","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"105ea5d191daa93bedab9e1f7f05dc18e9cf66880455b5ae23b1f7017ab373c4","published":"Sat, 06 Jun 2026 00:00:00 -0400","receipt_hash":"105ea5d191daa93bedab9e1f7f05dc18e9cf66880455b5ae23b1f7017ab373c4","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"105ea5d191daa93bedab9e1f7f05dc18e9cf66880455b5ae23b1f7017ab373c4","observed_at":"2026-06-06T04:43:19.193968Z","parent_run_hash":"550d5b02674822f43975c282be668ca76a4d9c7c957eb1601ba8b07dcb67715e","published":"Sat, 06 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2606.05614v1 Announce Type: new \nAbstract: Large language models (LLMs) are rigorously aligned to refuse harmful requests, a process that inherently cultivates a latent capacity to evaluate and recognize unsafe content. In this work, we reveal that this advanced safety awareness inadvertently introduces a fatal vulnerability. We introduce Posterior Attack, a single-query jailbreak that bypasses guardrails by prompting the model to generate the exact harmful response its internal classifier would normally flag as unsafe. Through extensive empirical evaluation across 30 open-source LLMs (up to 35B parameters in size) and frontier models (e.g., GPT-5, Claude 4.6), we observe a striking phenomenon: models with superior safety-judgment capabilities are disproportionately more susceptible to this exploitation. To explain this, we formalize the Safety Paradox, analytically showing that monotonic improvements in safety alignment naturally amplify posterior vulnerability. Finally, we esta","title":"Safety Paradox: How Enhanced Safety Awareness Leaves LLMs Vulnerable to Posterior Attack","url":"https://arxiv.org/abs/2606.05614","vendor":"arxiv_cs_ai"},"summary":"arXiv:2606.05614v1 Announce Type: new \nAbstract: Large language models (LLMs) are rigorously aligned to refuse harmful requests, a process that inherently cultivates a latent capacity to evaluate and recognize unsafe content. In this work, we reveal that this advanced safety awareness inadvertently introduces a fatal vulnerability. We introduce Posterior Attack, a single-query jailbreak that bypasses guardrails by prompting the model to generate the exact harmful response its internal classifier would normally flag as unsafe. Through extensive empirical evaluation across 30 open-source LLMs (up to 35B parameters in size) and frontier models (e.g., GPT-5, Claude 4.6), we observe a striking phenomenon: models with superior safety-judgment capabilities are disproportionately more susceptible to this exploitation. To explain this, we formalize the Safety Paradox, analytically showing that monotonic improvements in safety alignment naturally amplify posterior vulnerability. Finally, we esta","title":"Safety Paradox: How Enhanced Safety Awareness Leaves LLMs Vulnerable to Posterior Attack","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-06T04:43:19Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2606.05614"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:ccf3ac99bb3acd2ca371f7daa7707b555ef73bfb183a8ff9eecdd33282c538ce9c03f9e2219981a1fea24c029e0d244db4c27e9b02446fade90ad0a5ac55a908","signer":"crovia.substrate","subject":{"observed_at":"2026-06-06T04:43:19Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2606.05614"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"13d209c7956ac4476c53d9455687720f70f92bf342a726a8ace9d7d93d9f4b93","leaf_index":219172,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"ce22ee245073577080b61205cb02d54c5b7d00ed03f6934e2004064cd0244ae9","side":"right"},{"sibling":"a726bec2c4299eb1d1cdfd7d796b19c02c7999ccb3ad82bcb74c7461f86491b0","side":"right"},{"sibling":"744ae48c471bf58cecacdb77babe324eefd43c240bca8a69458e1e1c149c5f57","side":"left"},{"sibling":"39c74930180a5641b000ee0434d6e2b765bc020da2cff7fc771f36348e225e1e","side":"right"},{"sibling":"209cff9dcec37251cd5fc2b0e77cc80e1563637dc21c369293708f7da1bab410","side":"right"},{"sibling":"6896b70f68725f0de91f11fd6d92e4eb931871fca1c6556881d67d3d75a00cc5","side":"left"},{"sibling":"ba0c0435014270951b6af7e23fbaff30fe8272fa4125f24fa90e4bbd06a8dd89","side":"right"},{"sibling":"8f35ffd1b994bec37a9cc24e0047790f92b64b006d85bef48f319d6d28a40687","side":"right"},{"sibling":"bd0dfa76bed61a2c5e95135a7304a2b8c4fd064958dbf768664232880d0abaa5","side":"right"},{"sibling":"84d2509eab51047589142ed6da8c496305d2fbcbe148e0e6755163db2c7a4bc4","side":"right"},{"sibling":"9e3ea17e834fab022f2eabcfedb8ea0ac95c1f9fb57edc5004dded68522d3c9e","side":"right"},{"sibling":"41d58fea95a95071715ee23ef8bcd15f5867a3639da28e62a0641bc95eb83094","side":"left"},{"sibling":"27ad9d6a9ab792d708709017242a61b9ca519da4e035f87a342811aae221d000","side":"left"},{"sibling":"5f303e2a7840c60038ff2d035b1cd911feefb0fba880de2d737c6671ace594d4","side":"right"},{"sibling":"b2590791b920ca2a4ed39de126d2c0b1a10d9e7e62f572f12425f214e767b6e1","side":"left"},{"sibling":"1a61eadbf0217d063ab78291ccafdc0c92907f7d6ccdc3357534ef89f07d78ae","side":"right"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":219672,"merkle_root":"d3e32d3a61ca02ce6b1f0b2db86721107770b250e8a5bf762a2c225d2f03c870","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260606T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-06T05:38:35Z","sig_algorithm":"ed25519","signature":"dab214c2d4d857f01383c8e93a521a774b1aba60eaee5677d4e43e4074f0342b2c6a9b9bfcff0eba74f7ac81fcb490dd0e43727979c1a7e8979c7e11547fb101","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_0b97440b08afae73f794c56a6c64e55b7421cf551077d14819a9425ff136986c"}}