Give a taxonomy of LLM jailbreaks and the layered defenses that actually hold up.
Roleplay, obfuscation, optimization-based suffixes, and multi-turn escalation are distinct attack classes that call for distinct defenses. The signal is organizing the space and pairing each class with a control instead of hoping one filter covers all.
Updated Sep 2026 · Grounded in real GenAI, LLM, and AI/ML engineering interview loops and written to a senior-engineer editorial bar.
Roleplay, obfuscation, optimization-based suffixes, and multi-turn escalation are distinct attack classes that call for distinct defenses. The signal is organizing the space and pairing each class with a control instead of hoping one filter covers all.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.