TombRaider: Entering the Vault of History to Jailbreak Large Language Models

Junchen Ding, Jiahao Zhang, Yi Liu, Ziqi Ding, Gelei Deng, Yuekang Li


Abstract
**Warning: This paper contains content that may involve potentially harmful behaviours, discussed strictly for research purposes.**Jailbreak attacks can hinder the safety of Large Language Model (LLM) applications, especially chatbots. Studying jailbreak techniques is an important AI red teaming task for improving the safety of these applications. In this paper, we introduce TombRaider, a novel jailbreak technique that exploits the ability to store, retrieve, and use historical knowledge of LLMs. TombRaider employs two agents, the inspector agent to extract relevant historical information and the attacker agent to generate adversarial prompts, enabling effective bypassing of safety filters. We intensively evaluated TombRaider on six popular models. Experimental results showed that TombRaider could outperform state-of-the-art jailbreak techniques, achieving nearly 100% attack success rates (ASRs) on bare models and maintaining over 55.4% ASR against defence mechanisms. Our findings highlight critical vulnerabilities in existing LLM safeguards, underscoring the need for more robust safety defences.
Anthology ID:
2025.emnlp-main.279
Volume:
Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing
Month:
November
Year:
2025
Address:
Suzhou, China
Editors:
Christos Christodoulopoulos, Tanmoy Chakraborty, Carolyn Rose, Violet Peng
Venue:
EMNLP
SIG:
Publisher:
Association for Computational Linguistics
Note:
Pages:
5478–5493
Language:
URL:
https://preview.aclanthology.org/ingest-emnlp/2025.emnlp-main.279/
DOI:
Bibkey:
Cite (ACL):
Junchen Ding, Jiahao Zhang, Yi Liu, Ziqi Ding, Gelei Deng, and Yuekang Li. 2025. TombRaider: Entering the Vault of History to Jailbreak Large Language Models. In Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing, pages 5478–5493, Suzhou, China. Association for Computational Linguistics.
Cite (Informal):
TombRaider: Entering the Vault of History to Jailbreak Large Language Models (Ding et al., EMNLP 2025)
Copy Citation:
PDF:
https://preview.aclanthology.org/ingest-emnlp/2025.emnlp-main.279.pdf
Checklist:
 2025.emnlp-main.279.checklist.pdf