Skip to content

Hide Navigation Hide TOC

DAN/Persona Jailbreak - Unrestricted AI Role Assignment - ATR-2026-00472 (6ac3a8df-6376-5376-a95c-b9ce30fccd41)

Detects DAN-family jailbreak attempts that assign a new unrestricted AI persona to the model using "going to" framing. These attacks construct alternate-identity role instructions (e.g. "you are going to act as", "you are going to pretend to be", "you are going to generate") combined with freedom-from-restrictions language. Patterns cover: "are going to" persona assignment with ethical bypass language, dual-response generation requests, AI-name persona injection with capability claims, and "from now on / for this conversation" scoping with new-identity instructions. Multi-layer regex with word boundary anchors and synonym coverage.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern DAN/Persona Jailbreak - Unrestricted AI Role Assignment - ATR-2026-00472 (6ac3a8df-6376-5376-a95c-b9ce30fccd41) Agent Threat Rules 1
DAN/Persona Jailbreak - Unrestricted AI Role Assignment - ATR-2026-00472 (6ac3a8df-6376-5376-a95c-b9ce30fccd41) Agent Threat Rules Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2