{
  "id": "many-shot-jailbreaking",
  "code": "PTL-0092",
  "term": "Many-shot Jailbreaking",
  "aliases": [],
  "category": "security",
  "definition": "Many-shot jailbreaking fills a long context window with many fabricated dialogue examples in which an assistant complies with harmful requests, exploiting in-context learning to override the model's safety training.",
  "description": "Anthropic researchers found the attack's effectiveness followed a power law in the number of shots, mirroring the scaling of benign in-context learning.",
  "example": null,
  "broader": [
    "jailbreak"
  ],
  "narrower": [],
  "related": [
    "many-shot-in-context-learning",
    "context-window"
  ],
  "introduced": 2024,
  "sources": [
    {
      "title": "Many-shot jailbreaking",
      "authors": "Anthropic",
      "year": 2024,
      "url": "https://www.anthropic.com/research/many-shot-jailbreaking"
    }
  ],
  "url": "https://protologue.com/t/many-shot-jailbreaking/",
  "citation": "Protologue. (2026). Many-shot Jailbreaking. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0092). https://protologue.com/t/many-shot-jailbreaking/"
}