Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Liu, Yi, Deng, Gelei, Xu, Zhengzi, Li, Yuekang, Zheng, Yaowen, Zhang, Ying, Zhao, Lida, Zhang, Tianwei, Wang, Kailong, Liu, Yang
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917608766308352
author Liu, Yi
Deng, Gelei
Xu, Zhengzi
Li, Yuekang
Zheng, Yaowen
Zhang, Ying
Zhao, Lida
Zhang, Tianwei
Wang, Kailong
Liu, Yang
author_facet Liu, Yi
Deng, Gelei
Xu, Zhengzi
Li, Yuekang
Zheng, Yaowen
Zhang, Ying
Zhao, Lida
Zhang, Tianwei
Wang, Kailong
Liu, Yang
contents Large Language Models (LLMs), like ChatGPT, have demonstrated vast potential but also introduce challenges related to content constraints and potential misuse. Our study investigates three key research questions: (1) the number of different prompt types that can jailbreak LLMs, (2) the effectiveness of jailbreak prompts in circumventing LLM constraints, and (3) the resilience of ChatGPT against these jailbreak prompts. Initially, we develop a classification model to analyze the distribution of existing prompts, identifying ten distinct patterns and three categories of jailbreak prompts. Subsequently, we assess the jailbreak capability of prompts with ChatGPT versions 3.5 and 4.0, utilizing a dataset of 3,120 jailbreak questions across eight prohibited scenarios. Finally, we evaluate the resistance of ChatGPT against jailbreak prompts, finding that the prompts can consistently evade the restrictions in 40 use-case scenarios. The study underscores the importance of prompt structures in jailbreaking LLMs and discusses the challenges of robust jailbreak prompt generation and prevention.
format Preprint
id arxiv_https___arxiv_org_abs_2305_13860
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
Liu, Yi
Deng, Gelei
Xu, Zhengzi
Li, Yuekang
Zheng, Yaowen
Zhang, Ying
Zhao, Lida
Zhang, Tianwei
Wang, Kailong
Liu, Yang
Software Engineering
Artificial Intelligence
Computation and Language
Large Language Models (LLMs), like ChatGPT, have demonstrated vast potential but also introduce challenges related to content constraints and potential misuse. Our study investigates three key research questions: (1) the number of different prompt types that can jailbreak LLMs, (2) the effectiveness of jailbreak prompts in circumventing LLM constraints, and (3) the resilience of ChatGPT against these jailbreak prompts. Initially, we develop a classification model to analyze the distribution of existing prompts, identifying ten distinct patterns and three categories of jailbreak prompts. Subsequently, we assess the jailbreak capability of prompts with ChatGPT versions 3.5 and 4.0, utilizing a dataset of 3,120 jailbreak questions across eight prohibited scenarios. Finally, we evaluate the resistance of ChatGPT against jailbreak prompts, finding that the prompts can consistently evade the restrictions in 40 use-case scenarios. The study underscores the importance of prompt structures in jailbreaking LLMs and discusses the challenges of robust jailbreak prompt generation and prevention.
title Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study
topic Software Engineering
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2305.13860