Bypassing the Safety Training of Open-Source LLMs with Priming Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Vega, Jason, Chaudhary, Isha, Xu, Changming, Singh, Gagandeep
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914799487549440
author Vega, Jason
Chaudhary, Isha
Xu, Changming
Singh, Gagandeep
author_facet Vega, Jason
Chaudhary, Isha
Xu, Changming
Singh, Gagandeep
contents With the recent surge in popularity of LLMs has come an ever-increasing need for LLM safety training. In this paper, we investigate the fragility of SOTA open-source LLMs under simple, optimization-free attacks we refer to as $\textit{priming attacks}$, which are easy to execute and effectively bypass alignment from safety training. Our proposed attack improves the Attack Success Rate on Harmful Behaviors, as measured by Llama Guard, by up to $3.3\times$ compared to baselines. Source code and data are available at https://github.com/uiuc-focal-lab/llm-priming-attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2312_12321
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Bypassing the Safety Training of Open-Source LLMs with Priming Attacks
Vega, Jason
Chaudhary, Isha
Xu, Changming
Singh, Gagandeep
Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
With the recent surge in popularity of LLMs has come an ever-increasing need for LLM safety training. In this paper, we investigate the fragility of SOTA open-source LLMs under simple, optimization-free attacks we refer to as $\textit{priming attacks}$, which are easy to execute and effectively bypass alignment from safety training. Our proposed attack improves the Attack Success Rate on Harmful Behaviors, as measured by Llama Guard, by up to $3.3\times$ compared to baselines. Source code and data are available at https://github.com/uiuc-focal-lab/llm-priming-attacks.
title Bypassing the Safety Training of Open-Source LLMs with Priming Attacks
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
url https://arxiv.org/abs/2312.12321