Towards Understanding the Fragility of Multilingual LLMs against Fine-Tuning Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Poppi, Samuele, Yong, Zheng-Xin, He, Yifei, Chern, Bobbie, Zhao, Han, Yang, Aobo, Chi, Jianfeng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912251415363584
author Poppi, Samuele
Yong, Zheng-Xin
He, Yifei
Chern, Bobbie
Zhao, Han
Yang, Aobo
Chi, Jianfeng
author_facet Poppi, Samuele
Yong, Zheng-Xin
He, Yifei
Chern, Bobbie
Zhao, Han
Yang, Aobo
Chi, Jianfeng
contents Recent advancements in Large Language Models (LLMs) have sparked widespread concerns about their safety. Recent work demonstrates that safety alignment of LLMs can be easily removed by fine-tuning with a few adversarially chosen instruction-following examples, i.e., fine-tuning attacks. We take a further step to understand fine-tuning attacks in multilingual LLMs. We first discover cross-lingual generalization of fine-tuning attacks: using a few adversarially chosen instruction-following examples in one language, multilingual LLMs can also be easily compromised (e.g., multilingual LLMs fail to refuse harmful prompts in other languages). Motivated by this finding, we hypothesize that safety-related information is language-agnostic and propose a new method termed Safety Information Localization (SIL) to identify the safety-related information in the model parameter space. Through SIL, we validate this hypothesis and find that only changing 20% of weight parameters in fine-tuning attacks can break safety alignment across all languages. Furthermore, we provide evidence to the alternative pathways hypothesis for why freezing safety-related parameters does not prevent fine-tuning attacks, and we demonstrate that our attack vector can still jailbreak LLMs adapted to new languages.
format Preprint
id arxiv_https___arxiv_org_abs_2410_18210
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Understanding the Fragility of Multilingual LLMs against Fine-Tuning Attacks
Poppi, Samuele
Yong, Zheng-Xin
He, Yifei
Chern, Bobbie
Zhao, Han
Yang, Aobo
Chi, Jianfeng
Computation and Language
Artificial Intelligence
Cryptography and Security
Machine Learning
Recent advancements in Large Language Models (LLMs) have sparked widespread concerns about their safety. Recent work demonstrates that safety alignment of LLMs can be easily removed by fine-tuning with a few adversarially chosen instruction-following examples, i.e., fine-tuning attacks. We take a further step to understand fine-tuning attacks in multilingual LLMs. We first discover cross-lingual generalization of fine-tuning attacks: using a few adversarially chosen instruction-following examples in one language, multilingual LLMs can also be easily compromised (e.g., multilingual LLMs fail to refuse harmful prompts in other languages). Motivated by this finding, we hypothesize that safety-related information is language-agnostic and propose a new method termed Safety Information Localization (SIL) to identify the safety-related information in the model parameter space. Through SIL, we validate this hypothesis and find that only changing 20% of weight parameters in fine-tuning attacks can break safety alignment across all languages. Furthermore, we provide evidence to the alternative pathways hypothesis for why freezing safety-related parameters does not prevent fine-tuning attacks, and we demonstrate that our attack vector can still jailbreak LLMs adapted to new languages.
title Towards Understanding the Fragility of Multilingual LLMs against Fine-Tuning Attacks
topic Computation and Language
Artificial Intelligence
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2410.18210