Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yu, Zhiyuan, Liu, Xiaogeng, Liang, Shunning, Cameron, Zach, Xiao, Chaowei, Zhang, Ning
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914961029070848
author Yu, Zhiyuan
Liu, Xiaogeng
Liang, Shunning
Cameron, Zach
Xiao, Chaowei
Zhang, Ning
author_facet Yu, Zhiyuan
Liu, Xiaogeng
Liang, Shunning
Cameron, Zach
Xiao, Chaowei
Zhang, Ning
contents Recent advancements in generative AI have enabled ubiquitous access to large language models (LLMs). Empowered by their exceptional capabilities to understand and generate human-like text, these models are being increasingly integrated into our society. At the same time, there are also concerns on the potential misuse of this powerful technology, prompting defensive measures from service providers. To overcome such protection, jailbreaking prompts have recently emerged as one of the most effective mechanisms to circumvent security restrictions and elicit harmful content originally designed to be prohibited. Due to the rapid development of LLMs and their ease of access via natural languages, the frontline of jailbreak prompts is largely seen in online forums and among hobbyists. To gain a better understanding of the threat landscape of semantically meaningful jailbreak prompts, we systemized existing prompts and measured their jailbreak effectiveness empirically. Further, we conducted a user study involving 92 participants with diverse backgrounds to unveil the process of manually creating jailbreak prompts. We observed that users often succeeded in jailbreak prompts generation regardless of their expertise in LLMs. Building on the insights from the user study, we also developed a system using AI as the assistant to automate the process of jailbreak prompt generation.
format Preprint
id arxiv_https___arxiv_org_abs_2403_17336
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models
Yu, Zhiyuan
Liu, Xiaogeng
Liang, Shunning
Cameron, Zach
Xiao, Chaowei
Zhang, Ning
Cryptography and Security
Computation and Language
Recent advancements in generative AI have enabled ubiquitous access to large language models (LLMs). Empowered by their exceptional capabilities to understand and generate human-like text, these models are being increasingly integrated into our society. At the same time, there are also concerns on the potential misuse of this powerful technology, prompting defensive measures from service providers. To overcome such protection, jailbreaking prompts have recently emerged as one of the most effective mechanisms to circumvent security restrictions and elicit harmful content originally designed to be prohibited. Due to the rapid development of LLMs and their ease of access via natural languages, the frontline of jailbreak prompts is largely seen in online forums and among hobbyists. To gain a better understanding of the threat landscape of semantically meaningful jailbreak prompts, we systemized existing prompts and measured their jailbreak effectiveness empirically. Further, we conducted a user study involving 92 participants with diverse backgrounds to unveil the process of manually creating jailbreak prompts. We observed that users often succeeded in jailbreak prompts generation regardless of their expertise in LLMs. Building on the insights from the user study, we also developed a system using AI as the assistant to automate the process of jailbreak prompt generation.
title Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2403.17336