Home / Blog / Multi-turn attacks broke AI models 88% of the time —…
Tech News

Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead…

Cisco ran 6,986 multi-turn attacks against 15 flagship models and found that attackers who adapted across the conversation broke through as often as 88.3% of…

By Dillip Chowdary • Aug 04, 2026 • Source: VentureBeat

Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead…

Cisco ran 6,986 multi-turn attacks against 15 flagship models and found that attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco’s head of AI threat intelligence and security research, presented that result at the agentic security panel at VB Transform 2026. The headline figure is the multi-turn success rate; the warning is that single-turn red-teaming missed the same class of failures.

The test design is conversational, not one-shot. Each attack unfolded over multiple turns so the adversary could revise prompts, reframe intent, and push past earlier refusals. That is a different evaluation surface than a single prompt-and-response check. Single-turn suites score a model on isolated attempts; multi-turn suites score how the model holds under a sustained, adaptive dialogue. Cisco’s result quantifies the gap: adaptive multi-turn pressure reached 88.3% breakthroughs across the 15 models under test.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders shipping agents or chat products, that gap is operational. Red-team pipelines that only fire single-turn jailbreak packs will understate real risk once users or attackers can keep talking. Agentic systems amplify the problem because they already run multi-step tool use and long sessions; an attacker who adapts turn by turn is closer to that deployment shape than a one-line prompt. Security sign-off based only on single-turn pass rates does not match how these systems are used.

The competitive context is the industry’s default evaluation habit. Many teams still treat model safety as a battery of isolated prompts—fast to run, easy to regress, and easy to put on a scorecard. Cisco’s 6,986-attack sample argues that scorecard is incomplete. Anyone still standardizing on single-turn red-teaming is measuring a softer threat model than adaptive conversational attacks, and Chang’s panel warning is aimed at that practice, not at one vendor’s stack.

The practical takeaway is to treat multi-turn, adaptive attack success as a first-class metric next to single-turn rates. Expand red-team harnesses so adversaries can replan across turns; retest the same 15-class of flagship models under that regime; and gate releases on both numbers, not only the single-turn score. Watch whether teams and vendors update agentic security testing to match conversational attack chains—or keep shipping with a gap that Cisco’s 88.3% result already made hard to ignore.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →