T2-AT-020MEDIUM

Register Shifting

T2 · Semantic & Linguistic Evasion →
Risk score160
RatingMedium
Procedures10
Severity
Mechanism

Shifts the linguistic register (formal/informal, academic/colloquial, medical/legal/technical) to frame harmful requests in registers that the safety classifier is less calibrated to detect. An academic register request for drug synthesis, a legal register request for fraud methodology, or a military register request for weapons construction — each uses the authority and legitimacy of its register to normalize the request. Overlaps with T2-AT-006 (Linguistic Camouflage) but register shifting specifically targets the authority effect of formal registers rather than structural complexity.

Detection
  • Register detection combined with topic classification: flag formal/authoritative registers used for restricted content
  • Distinguish legitimate professional requests from register-shifted attacks (difficult — many legitimate users use these registers)
Mitigation
Register-independent content classificationHIGH
Output classificationHIGH
Chaining

Chains with T2-AT-006 (Linguistic Camouflage) — register shifting IS camouflage. Chains with T1-AT-005 (Permission Escalation) when the register implies institutional authority.

Framework mapping
OWASP LLMLLM01
Open in the technique browser →