# Many-shot Jailbreaking

> Many-shot jailbreaking fills a long context window with many fabricated dialogue examples in which an assistant complies with harmful requests, exploiting in-context learning to override the model's safety training.

- Identifier: PTL-0092
- Category: Security & Adversarial Prompting
- Canonical URL: https://protologue.com/t/many-shot-jailbreaking/
- Introduced: 2024

## Description

Anthropic researchers found the attack's effectiveness followed a power law in the number of shots, mirroring the scaling of benign in-context learning.

## Broader terms

- [Jailbreak](https://protologue.com/t/jailbreak/)

## Related terms

- [Many-shot In-Context Learning](https://protologue.com/t/many-shot-in-context-learning/)
- [Context Window](https://protologue.com/t/context-window/)

## Sources

- Anthropic (2024). Many-shot jailbreaking. https://www.anthropic.com/research/many-shot-jailbreaking

## Cite this entry

Protologue. (2026). Many-shot Jailbreaking. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0092). https://protologue.com/t/many-shot-jailbreaking/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
