Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Schulhoff, Sander, Pinto, Jeremy, Khan, Anaum, Bouchard, Louis-François, Si, Chenglei, Anati, Svetlina, Tagliabue, Valen, Kost, Anson Liu, Carnahan, Christopher, Boyd-Graber, Jordan
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909125681610752
author Schulhoff, Sander
Pinto, Jeremy
Khan, Anaum
Bouchard, Louis-François
Si, Chenglei
Anati, Svetlina
Tagliabue, Valen
Kost, Anson Liu
Carnahan, Christopher
Boyd-Graber, Jordan
author_facet Schulhoff, Sander
Pinto, Jeremy
Khan, Anaum
Bouchard, Louis-François
Si, Chenglei
Anati, Svetlina
Tagliabue, Valen
Kost, Anson Liu
Carnahan, Christopher
Boyd-Graber, Jordan
contents Large Language Models (LLMs) are deployed in interactive contexts with direct user engagement, such as chatbots and writing assistants. These deployments are vulnerable to prompt injection and jailbreaking (collectively, prompt hacking), in which models are manipulated to ignore their original instructions and follow potentially malicious ones. Although widely acknowledged as a significant security threat, there is a dearth of large-scale resources and quantitative studies on prompt hacking. To address this lacuna, we launch a global prompt hacking competition, which allows for free-form human input attacks. We elicit 600K+ adversarial prompts against three state-of-the-art LLMs. We describe the dataset, which empirically verifies that current LLMs can indeed be manipulated via prompt hacking. We also present a comprehensive taxonomical ontology of the types of adversarial prompts.
format Preprint
id arxiv_https___arxiv_org_abs_2311_16119
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition
Schulhoff, Sander
Pinto, Jeremy
Khan, Anaum
Bouchard, Louis-François
Si, Chenglei
Anati, Svetlina
Tagliabue, Valen
Kost, Anson Liu
Carnahan, Christopher
Boyd-Graber, Jordan
Cryptography and Security
Artificial Intelligence
Computation and Language
Large Language Models (LLMs) are deployed in interactive contexts with direct user engagement, such as chatbots and writing assistants. These deployments are vulnerable to prompt injection and jailbreaking (collectively, prompt hacking), in which models are manipulated to ignore their original instructions and follow potentially malicious ones. Although widely acknowledged as a significant security threat, there is a dearth of large-scale resources and quantitative studies on prompt hacking. To address this lacuna, we launch a global prompt hacking competition, which allows for free-form human input attacks. We elicit 600K+ adversarial prompts against three state-of-the-art LLMs. We describe the dataset, which empirically verifies that current LLMs can indeed be manipulated via prompt hacking. We also present a comprehensive taxonomical ontology of the types of adversarial prompts.
title Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2311.16119