Alignment-Enhanced Decoding:Defending via Token-Level Adaptive Refining of Probability Distributions

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Liu, Quan, Zhou, Zhenhong, He, Longzhu, Liu, Yi, Zhang, Wei, Su, Sen
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866929639109165056
author Liu, Quan
Zhou, Zhenhong
He, Longzhu
Liu, Yi
Zhang, Wei
Su, Sen
author_facet Liu, Quan
Zhou, Zhenhong
He, Longzhu
Liu, Yi
Zhang, Wei
Su, Sen
contents Large language models are susceptible to jailbreak attacks, which can result in the generation of harmful content. While prior defenses mitigate these risks by perturbing or inspecting inputs, they ignore competing objectives, the underlying cause of alignment failures. In this paper, we propose Alignment-Enhanced Decoding (AED), a novel defense that employs adaptive decoding to address the root causes of jailbreak issues. We first define the Competitive Index to quantify alignment failures and utilize feedback from self-evaluation to compute post-alignment logits. Then, AED adaptively combines AED and post-alignment logits with the original logits to obtain harmless and helpful distributions. Consequently, our method enhances safety alignment while maintaining helpfulness. We conduct experiments across five models and four common jailbreaks, with the results validating the effectiveness of our approach. Code is available at https://github.com/GIGABaozi/AED.git.
format Preprint
id arxiv_https___arxiv_org_abs_2408_07663
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Alignment-Enhanced Decoding:Defending via Token-Level Adaptive Refining of Probability Distributions
Liu, Quan
Zhou, Zhenhong
He, Longzhu
Liu, Yi
Zhang, Wei
Su, Sen
Computation and Language
Artificial Intelligence
Large language models are susceptible to jailbreak attacks, which can result in the generation of harmful content. While prior defenses mitigate these risks by perturbing or inspecting inputs, they ignore competing objectives, the underlying cause of alignment failures. In this paper, we propose Alignment-Enhanced Decoding (AED), a novel defense that employs adaptive decoding to address the root causes of jailbreak issues. We first define the Competitive Index to quantify alignment failures and utilize feedback from self-evaluation to compute post-alignment logits. Then, AED adaptively combines AED and post-alignment logits with the original logits to obtain harmless and helpful distributions. Consequently, our method enhances safety alignment while maintaining helpfulness. We conduct experiments across five models and four common jailbreaks, with the results validating the effectiveness of our approach. Code is available at https://github.com/GIGABaozi/AED.git.
title Alignment-Enhanced Decoding:Defending via Token-Level Adaptive Refining of Probability Distributions
topic Computation and Language
Artificial Intelligence
url https://arxiv.org/abs/2408.07663