T2-AT-005MEDIUM

Semantic Drift

T2 · Semantic & Linguistic Evasion →
Risk score175
RatingMedium
Procedures10
Severity
Mechanism

Gradually shifts from permitted to restricted content through semantically adjacent steps. Each step is within the safety boundary; the cumulative trajectory crosses it. The classifier must evaluate the trajectory, not just the current position.

Detection
  • Cumulative intent tracking across turns
  • Topic trajectory analysis toward restricted domains
Mitigation
Cumulative intent classificationHIGH
Session-level risk scoringHIGH
Chaining

Precursor to T4 (Multi-Turn) Crescendo. Chains from T1-AT-008 (Boundary Testing).

Framework mapping
OWASP LLMLLM01
Open in the technique browser →