Exploiting Novel GPT-4 APIs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pelrine, Kellin, Taufeeque, Mohammad, Zając, Michał, McLean, Euan, Gleave, Adam
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909278638440448
author Pelrine, Kellin
Taufeeque, Mohammad
Zając, Michał
McLean, Euan
Gleave, Adam
author_facet Pelrine, Kellin
Taufeeque, Mohammad
Zając, Michał
McLean, Euan
Gleave, Adam
contents Language model attacks typically assume one of two extreme threat models: full white-box access to model weights, or black-box access limited to a text generation API. However, real-world APIs are often more flexible than just text generation: these APIs expose "gray-box" access leading to new threat vectors. To explore this, we red-team three new functionalities exposed in the GPT-4 APIs: fine-tuning, function calling and knowledge retrieval. We find that fine-tuning a model on as few as 15 harmful examples or 100 benign examples can remove core safeguards from GPT-4, enabling a range of harmful outputs. Furthermore, we find that GPT-4 Assistants readily divulge the function call schema and can be made to execute arbitrary function calls. Finally, we find that knowledge retrieval can be hijacked by injecting instructions into retrieval documents. These vulnerabilities highlight that any additions to the functionality exposed by an API can create new vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2312_14302
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Exploiting Novel GPT-4 APIs
Pelrine, Kellin
Taufeeque, Mohammad
Zając, Michał
McLean, Euan
Gleave, Adam
Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
I.2.7
Language model attacks typically assume one of two extreme threat models: full white-box access to model weights, or black-box access limited to a text generation API. However, real-world APIs are often more flexible than just text generation: these APIs expose "gray-box" access leading to new threat vectors. To explore this, we red-team three new functionalities exposed in the GPT-4 APIs: fine-tuning, function calling and knowledge retrieval. We find that fine-tuning a model on as few as 15 harmful examples or 100 benign examples can remove core safeguards from GPT-4, enabling a range of harmful outputs. Furthermore, we find that GPT-4 Assistants readily divulge the function call schema and can be made to execute arbitrary function calls. Finally, we find that knowledge retrieval can be hijacked by injecting instructions into retrieval documents. These vulnerabilities highlight that any additions to the functionality exposed by an API can create new vulnerabilities.
title Exploiting Novel GPT-4 APIs
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
I.2.7
url https://arxiv.org/abs/2312.14302