{
  "id": 9676803,
  "title": "Prefilling the Reasoning Channel: Output-Prefix Attacks on Reasoning LLMs",
  "url": "https://urgent.news/2026/09/24/prefilling-the-reasoning-channel-output-prefix-attacks-on-reasoning",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-24T13:18:21.000Z",
  "source": {
    "name": "arXiv cs.AI",
    "slug": "arxiv-cs-ai",
    "url": "https://arxiv.org/abs/2609.29775v1"
  },
  "original_language": "en",
  "account": null,
  "summary": "Large Language Models (LLMs) consume and produce a single sequence of text; hence, if text can be added to the beginning of the LLM's response, i.e., an output prefix, then all subsequent tokens will be conditioned on it. This output-prefix attack technique is a cheap black-box prompt injection. Prior work has shown this type of attack can reliably jailbreak non-reasoning models. Most reasoning…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}