How do optimization-based adversarial attacks (GCG suffixes) work against LLMs, and how do you defend?
Gibberish-looking token strings tacked onto a prompt can reliably break refusals, and they carry over between models. The signal is explaining the gradient search that finds them and why output checks beat input pattern matching.
Updated Sep 2026 · Grounded in real GenAI, LLM, and AI/ML engineering interview loops and written to a senior-engineer editorial bar.
Gibberish-looking token strings tacked onto a prompt can reliably break refusals, and they carry over between models. The signal is explaining the gradient search that finds them and why output checks beat input pattern matching.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.