New BPJ jailbreak bypasses top defenses with single-bit black-box attacks

StephenLCasper · x · 2026-08-13

A new paper introduces Boundary Point Jailbreaking (BPJ), a fully automated black-box attack that uses only a single bit of information per query—whether the classifier flags the interaction—to evade the strongest industry safeguards, including Constitutional Classifiers and GPT-5's input classifier. BPJ converts a target harmful string into a curriculum of intermediate targets and actively selects boundary points to detect small improvements, achieving the first automated attack against GPT-5's classifier without human seeds.

Original post →

More from Safety

Safety channel →