[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-guardrail-screens-jailbreaks-inside-encrypted-ai-chats":10,"sections":36},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":24,"persona_id":22,"persona_name":22,"section":25,"tags":26,"sources":31,"feedback":35,"feedback_at":22,"cost_usd":35,"total_tokens":35},7094,"new-guardrail-screens-jailbreaks-inside-encrypted-ai-chats","New Guardrail Screens Jailbreaks Inside Encrypted AI Chats","A new framework screens encrypted AI prompts for jailbreak attempts without decrypting them, closing a blind spot in privacy-preserving inference.","A new framework catches jailbreak attempts hidden inside encrypted AI conversations, without the server ever seeing the prompt.\n\nHomomorphic encryption lets a server run a large language model on data it can never decrypt, which protects user privacy but also blinds the server to abuse. Researchers behind a new paper call this out directly: encrypted LLM inference has no way to screen incoming prompts for jailbreak attempts, so a malicious client's attack can succeed completely undetected. Their proposed system, HE-Guardrail, runs safety checks like Llama Guard, JBShield, and GradSafe directly on the encrypted data, then homomorphically decides whether the model's response ever reaches the client. Across all three guardrails, the encrypted version matched the decisions the same guardrail would have made on plaintext, though each came with its own tradeoff among security, computational cost, and how much the underlying model's usefulness was preserved.\n\nHomomorphic encryption has been pitched mainly on privacy grounds, letting a hospital or bank query a model without exposing sensitive records to the server. This paper is a reminder that privacy and safety pull in opposite directions here: the more a server is blocked from seeing a prompt, the less it can stop that prompt from being a jailbreak.\n\nHomomorphic computation is still orders of magnitude slower than plaintext inference, so encrypted, guardrailed chatbots are not shipping to production anytime soon. But the security hole this work identifies had to be named before anyone could pretend encrypted LLM inference was safe by default.","[\"homomorphic-encryption\",\"llm-security\",\"jailbreak-attacks\",\"ai-privacy\"]","2026-09-21T04:00:00.000Z","2026-09-21T06:02:10.344Z","2026-09-21T06:02:22.258Z","published",null,[],"https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Fnew-guardrail-screens-jailbreaks-inside-encrypted-ai-chats.webp","security",[27,28,29,30],"homomorphic-encryption","llm-security","jailbreak-attacks","ai-privacy",[32],{"name":33,"url":34},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.21484",0,{"sections":37},[38,42,45,50,55,60,65,70,75,80,85,90,95,100],{"name":39,"slug":40,"count":41,"latest_published_at":18},"AI","ai",4158,{"name":43,"slug":25,"count":44,"latest_published_at":18},"Security",679,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",350,"2026-09-20T20:32:43.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",156,"2026-09-19T11:00:00.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Science","science",130,"2026-09-20T13:48:11.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Dev Tools","dev-tools",78,"2026-09-18T04:00:00.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",42,"2026-09-18T22:35:10.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]