SpeechGuard: Exploring the Adversarial Robustness of Multimodal Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Peri, Raghuveer, Jayanthi, Sai Muralidhar, Ronanki, Srikanth, Bhatia, Anshu, Mundnich, Karel, Dingliwal, Saket, Das, Nilaksh, Hou, Zejiang, Huybrechts, Goeric, Vishnubhotla, Srikanth, Garcia-Romero, Daniel, Srinivasan, Sundararajan, Han, Kyu J, Kirchhoff, Katrin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914795871010816
author Peri, Raghuveer
Jayanthi, Sai Muralidhar
Ronanki, Srikanth
Bhatia, Anshu
Mundnich, Karel
Dingliwal, Saket
Das, Nilaksh
Hou, Zejiang
Huybrechts, Goeric
Vishnubhotla, Srikanth
Garcia-Romero, Daniel
Srinivasan, Sundararajan
Han, Kyu J
Kirchhoff, Katrin
author_facet Peri, Raghuveer
Jayanthi, Sai Muralidhar
Ronanki, Srikanth
Bhatia, Anshu
Mundnich, Karel
Dingliwal, Saket
Das, Nilaksh
Hou, Zejiang
Huybrechts, Goeric
Vishnubhotla, Srikanth
Garcia-Romero, Daniel
Srinivasan, Sundararajan
Han, Kyu J
Kirchhoff, Katrin
contents Integrated Speech and Large Language Models (SLMs) that can follow speech instructions and generate relevant text responses have gained popularity lately. However, the safety and robustness of these models remains largely unclear. In this work, we investigate the potential vulnerabilities of such instruction-following speech-language models to adversarial attacks and jailbreaking. Specifically, we design algorithms that can generate adversarial examples to jailbreak SLMs in both white-box and black-box attack settings without human involvement. Additionally, we propose countermeasures to thwart such jailbreaking attacks. Our models, trained on dialog data with speech instructions, achieve state-of-the-art performance on spoken question-answering task, scoring over 80% on both safety and helpfulness metrics. Despite safety guardrails, experiments on jailbreaking demonstrate the vulnerability of SLMs to adversarial perturbations and transfer attacks, with average attack success rates of 90% and 10% respectively when evaluated on a dataset of carefully designed harmful questions spanning 12 different toxic categories. However, we demonstrate that our proposed countermeasures reduce the attack success significantly.
format Preprint
id arxiv_https___arxiv_org_abs_2405_08317
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle SpeechGuard: Exploring the Adversarial Robustness of Multimodal Large Language Models
Peri, Raghuveer
Jayanthi, Sai Muralidhar
Ronanki, Srikanth
Bhatia, Anshu
Mundnich, Karel
Dingliwal, Saket
Das, Nilaksh
Hou, Zejiang
Huybrechts, Goeric
Vishnubhotla, Srikanth
Garcia-Romero, Daniel
Srinivasan, Sundararajan
Han, Kyu J
Kirchhoff, Katrin
Computation and Language
Sound
Audio and Speech Processing
Integrated Speech and Large Language Models (SLMs) that can follow speech instructions and generate relevant text responses have gained popularity lately. However, the safety and robustness of these models remains largely unclear. In this work, we investigate the potential vulnerabilities of such instruction-following speech-language models to adversarial attacks and jailbreaking. Specifically, we design algorithms that can generate adversarial examples to jailbreak SLMs in both white-box and black-box attack settings without human involvement. Additionally, we propose countermeasures to thwart such jailbreaking attacks. Our models, trained on dialog data with speech instructions, achieve state-of-the-art performance on spoken question-answering task, scoring over 80% on both safety and helpfulness metrics. Despite safety guardrails, experiments on jailbreaking demonstrate the vulnerability of SLMs to adversarial perturbations and transfer attacks, with average attack success rates of 90% and 10% respectively when evaluated on a dataset of carefully designed harmful questions spanning 12 different toxic categories. However, we demonstrate that our proposed countermeasures reduce the attack success significantly.
title SpeechGuard: Exploring the Adversarial Robustness of Multimodal Large Language Models
topic Computation and Language
Sound
Audio and Speech Processing
url https://arxiv.org/abs/2405.08317