Data to Defense: The Role of Curation in Customizing LLMs Against Jailbreaking Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Liu, Xiaoqun, Liang, Jiacheng, Tang, Luoxi, Ye, Muchao, Ma, Weicheng, Xi, Zhaohan
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913694831607808
author Liu, Xiaoqun
Liang, Jiacheng
Tang, Luoxi
Ye, Muchao
Ma, Weicheng
Xi, Zhaohan
author_facet Liu, Xiaoqun
Liang, Jiacheng
Tang, Luoxi
Ye, Muchao
Ma, Weicheng
Xi, Zhaohan
contents Large language models (LLMs) are widely adapted for downstream applications through fine-tuning, a process named customization. However, recent studies have identified a vulnerability during this process, where malicious samples can compromise the robustness of LLMs and amplify harmful behaviors-an attack commonly referred to as jailbreaking. To address this challenge, we propose an adaptive data curation approach allowing any text to be curated to enhance its effectiveness in counteracting harmful samples during customization. To avoid the need for additional defensive modules, we further introduce a comprehensive mitigation framework spanning the lifecycle of the customization process: before customization to immunize LLMs against future jailbreak attempts, during customization to neutralize risks, and after customization to restore compromised models. Experimental results demonstrate a significant reduction in jailbreaking effects, achieving up to a 100% success rate in generating safe responses. By combining adaptive data curation with lifecycle-based mitigation strategies, this work represents a solid step forward in mitigating jailbreaking risks and ensuring the secure adaptation of LLMs.
format Preprint
id arxiv_https___arxiv_org_abs_2410_02220
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Data to Defense: The Role of Curation in Customizing LLMs Against Jailbreaking Attacks
Liu, Xiaoqun
Liang, Jiacheng
Tang, Luoxi
Ye, Muchao
Ma, Weicheng
Xi, Zhaohan
Cryptography and Security
Artificial Intelligence
Large language models (LLMs) are widely adapted for downstream applications through fine-tuning, a process named customization. However, recent studies have identified a vulnerability during this process, where malicious samples can compromise the robustness of LLMs and amplify harmful behaviors-an attack commonly referred to as jailbreaking. To address this challenge, we propose an adaptive data curation approach allowing any text to be curated to enhance its effectiveness in counteracting harmful samples during customization. To avoid the need for additional defensive modules, we further introduce a comprehensive mitigation framework spanning the lifecycle of the customization process: before customization to immunize LLMs against future jailbreak attempts, during customization to neutralize risks, and after customization to restore compromised models. Experimental results demonstrate a significant reduction in jailbreaking effects, achieving up to a 100% success rate in generating safe responses. By combining adaptive data curation with lifecycle-based mitigation strategies, this work represents a solid step forward in mitigating jailbreaking risks and ensuring the secure adaptation of LLMs.
title Data to Defense: The Role of Curation in Customizing LLMs Against Jailbreaking Attacks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2410.02220