frontier proprietary and open-weight models yielded high attack success rates when prompted in verse, indicating a deeper, ...