Lukas Struppek

Member of Technical Staff

FAR.AI

Lukas is a Research Scientist at FAR.AI, where he focuses on developing robust and trustworthy generative AI systems.

He earned his PhD from the Technical University of Darmstad, where his research centered on generative and multimodal AI with an emphasis on security, privacy, and safety.

Before joining FAR.AI, he worked as a Senior Researcher at the German Research Center for Artificial Intelligence (DFKI) and co-organized the ICML 2025 workshop on “The Impact of Memorization on Trustworthy Foundation Models.”

Publications

Prefill-level Jailbreak: A Black-Box Risk Analysis of Large Language Models

Robustness

We investigate a previously under-explored attack vector for open-source models: prefilling, which allows an attacker to predefine initial response tokens before generation begins. We present the largest empirical study to date of such attacks, evaluating over 20 existing and novel strategies across multiple model families and state-of-the-art open-weight models. Our results show that prefill attacks are consistently effective against all major contemporary open-weight models, underscoring the need for model developers to prioritize defenses against prefill attacks in open-weight LLMs.

February 18, 2026
Date Range

News

Security Stress Test: Exposing the Brittleness of DeepSeek-V4-Pro’s Safeguards

Red-Teaming & Evaluation

We evaluated whether DeepSeek-V4-Pro’s built-in safeguards could reliably prevent harmful assistance across several high-risk domains, and the results were stark. When subjected to adversarial testing across Chemical, Biological, Radiological, and Nuclear (CBRN) threats, cyberattacks, and terrorism-related activities, its safeguards collapsed almost completely. Low-skill attackers were able to bypass the model’s safety mechanisms with success rates ranging from 98-100% across every domain tested. Most alarming: a publicly available jailbreak originally developed for the model’s predecessor worked on DeepSeek-V4-Pro without a single modification, exploitable by anyone with API access. This indicates that the previously known vulnerability remains completely unpatched.

May 11, 2026
Date Range

Research

Our research explores a portfolio of high-potential agendas.

Events

Our events bring together global leaders in AI.

Programs

Our programs build the field of trustworthy and secure AI