Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wei, Zeming, Wang, Yifei, Li, Ang, Mo, Yichuan, Wang, Yisen
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916259509043200
author Wei, Zeming
Wang, Yifei
Li, Ang
Mo, Yichuan
Wang, Yisen
author_facet Wei, Zeming
Wang, Yifei
Li, Ang
Mo, Yichuan
Wang, Yisen
contents Large Language Models (LLMs) have shown remarkable success in various tasks, yet their safety and the risk of generating harmful content remain pressing concerns. In this paper, we delve into the potential of In-Context Learning (ICL) to modulate the alignment of LLMs. Specifically, we propose the In-Context Attack (ICA) which employs harmful demonstrations to subvert LLMs, and the In-Context Defense (ICD) which bolsters model resilience through examples that demonstrate refusal to produce harmful responses. We offer theoretical insights to elucidate how a limited set of in-context demonstrations can pivotally influence the safety alignment of LLMs. Through extensive experiments, we demonstrate the efficacy of ICA and ICD in respectively elevating and mitigating the success rates of jailbreaking prompts. Our findings illuminate the profound influence of ICL on LLM behavior, opening new avenues for improving the safety of LLMs.
format Preprint
id arxiv_https___arxiv_org_abs_2310_06387
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations
Wei, Zeming
Wang, Yifei
Li, Ang
Mo, Yichuan
Wang, Yisen
Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
Large Language Models (LLMs) have shown remarkable success in various tasks, yet their safety and the risk of generating harmful content remain pressing concerns. In this paper, we delve into the potential of In-Context Learning (ICL) to modulate the alignment of LLMs. Specifically, we propose the In-Context Attack (ICA) which employs harmful demonstrations to subvert LLMs, and the In-Context Defense (ICD) which bolsters model resilience through examples that demonstrate refusal to produce harmful responses. We offer theoretical insights to elucidate how a limited set of in-context demonstrations can pivotally influence the safety alignment of LLMs. Through extensive experiments, we demonstrate the efficacy of ICA and ICD in respectively elevating and mitigating the success rates of jailbreaking prompts. Our findings illuminate the profound influence of ICL on LLM behavior, opening new avenues for improving the safety of LLMs.
title Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations
topic Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2310.06387