Projects per year
Abstract
Large Language Models (LLMs) have achieved remarkable progress, but their deployment has exposed critical vulnerabilities, particularly to jailbreak attacks that circumvent safety alignments. Guardrails—external defense mechanisms that monitor and control LLM interactions—have emerged as a promising solution. However, the current landscape of LLM guardrails is fragmented, lacking a unified taxonomy and comprehensive evaluation framework. In this Systematization of Knowledge (SoK) paper, we present the first holistic analysis of jailbreak guardrails for LLMs. We propose a novel, multi-dimensional taxonomy that categorizes guardrails along six key dimensions, and introduce a Security-Efficiency-Utility evaluation framework to assess their practical effectiveness. Through extensive analysis and experiments, we identify the strengths and limitations of existing guardrail approaches, provide insights into optimizing their defense mechanisms, and explore their universality across attack types. Our work offers a structured foundation for future research and development, aiming to guide the principled advancement and deployment of robust LLM guardrails.
| Original language | English |
|---|---|
| Title of host publication | 2026 IEEE Symposium on Security and Privacy (SP) : Proceedings |
| Editors | Alina OPREA, Cristina NITA-ROTARU, Nicolas PAPERNOT |
| Publisher | IEEE |
| Pages | 39-58 |
| Number of pages | 20 |
| ISBN (Electronic) | 9798331560652 |
| DOIs | |
| Publication status | Published - May 2026 |
| Event | 47th IEEE Symposium on Security and Privacy, SP 2026 - San Francisco, United States Duration: 18 May 2026 → 21 May 2026 |
Publication series
| Name | Proceedings of the IEEE Symposium on Security and Privacy |
|---|---|
| Publisher | IEEE |
| ISSN (Print) | 1081-6011 |
| ISSN (Electronic) | 2375-1207 |
Symposium
| Symposium | 47th IEEE Symposium on Security and Privacy, SP 2026 |
|---|---|
| Abbreviated title | SP 2026 |
| Country/Territory | United States |
| City | San Francisco |
| Period | 18/05/26 → 21/05/26 |
Funding
The HKUST authors are supported in part by an RGC CRF grant under contract C6015-23G and a research fund provided by HSBC. Daoyuan Wu was partially supported by Lingnan Grant SUG-002/2526.
Fingerprint
Dive into the research topics of 'Sok: Evaluating Jailbreak Guardrails for Large Language Models'. Together they form a unique fingerprint.Projects
- 1 Active
-
Understanding and Testing the Security of Large Language Model Context Protocols (MCP)
WU, D. (PI)
1/09/25 → 31/08/27
Project: Grant Research
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver