IndicJR: A Judge-Free Benchmark of Jailbreak Robustness in South Asian Languages

0Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Safety alignment of large language models (LLMs) is mostly evaluated in English and contract-bound, leaving multilingual vulnerabilities understudied. We introduce Indic Jailbreak Robustness (IJR), a judge-free benchmark for adversarial safety across 12 Indic and South Asian languages (2.1 Billion speakers), covering 45,216 prompts in JSON (contract-bound) and FREE (naturalistic) tracks. IJR reveals three patterns. (1) Contracts inflate refusals but do not stop jailbreaks: in JSON, LLaMA and Sarvam exceed 0.92 JSR, and in FREE all models reach ≈1.0 with refusals collapsing. (2) English→Indic attacks transfer strongly, with format wrappers often outperforming instruction wrappers. (3) Orthography matters: romanized/mixed inputs reduce JSR under JSON, with correlations to romanization share and tokenization (ρ ≈ 0.28–0.32) indicating systematic effects. Human audits confirm detector reliability, and lite-to-full comparisons preserve conclusions. IJR offers a reproducible multilingual stress test revealing risks hidden by English-only, contract-focused evaluations, especially for South Asian users who frequently code-switch and romanize.

Cite

CITATION STYLE

APA

Pattnayak, P., & Chowdhuri, S. (2026). IndicJR: A Judge-Free Benchmark of Jailbreak Robustness in South Asian Languages. In EACL 2026 - 19th Conference of the European Chapter of the Association for Computational Linguistics, Proceedings of the Conference, Vol. 1 - (Long Papers) (Vol. 5, pp. 649–668). Association for Computational Linguistics (ACL). https://doi.org/10.18653/v1/2026.eacl-industry.50

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free