Vulnerability of LLMs to Vertically Aligned Text Manipulations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Zhecheng, Wang, Yiwei, Hooi, Bryan, Cai, Yujun, Xiong, Zhen, Peng, Nanyun, Chang, Kai-wei
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916970527457280
author Li, Zhecheng
Wang, Yiwei
Hooi, Bryan
Cai, Yujun
Xiong, Zhen
Peng, Nanyun
Chang, Kai-wei
author_facet Li, Zhecheng
Wang, Yiwei
Hooi, Bryan
Cai, Yujun
Xiong, Zhen
Peng, Nanyun
Chang, Kai-wei
contents Vertical text input is commonly encountered in various real-world applications, such as mathematical computations and word-based Sudoku puzzles. While current large language models (LLMs) have excelled in natural language tasks, they remain vulnerable to variations in text formatting. Recent research demonstrates that modifying input formats, such as vertically aligning words for encoder-based models, can substantially lower accuracy in text classification tasks. While easily understood by humans, these inputs can significantly mislead models, posing a potential risk of bypassing detection in real-world scenarios involving harmful or sensitive information. With the expanding application of LLMs, a crucial question arises: Do decoder-based LLMs exhibit similar vulnerabilities to vertically formatted text input? In this paper, we investigate the impact of vertical text input on the performance of various LLMs across multiple text classification datasets and analyze the underlying causes. Our findings are as follows: (i) Vertical text input significantly degrades the accuracy of LLMs in text classification tasks. (ii) Chain-of-Thought (CoT) reasoning does not help LLMs recognize vertical input or mitigate its vulnerability, but few-shot learning with careful analysis does. (iii) We explore the underlying cause of the vulnerability by analyzing the inherent issues in tokenization and attention matrices.
format Preprint
id arxiv_https___arxiv_org_abs_2410_20016
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Vulnerability of LLMs to Vertically Aligned Text Manipulations
Li, Zhecheng
Wang, Yiwei
Hooi, Bryan
Cai, Yujun
Xiong, Zhen
Peng, Nanyun
Chang, Kai-wei
Computation and Language
Vertical text input is commonly encountered in various real-world applications, such as mathematical computations and word-based Sudoku puzzles. While current large language models (LLMs) have excelled in natural language tasks, they remain vulnerable to variations in text formatting. Recent research demonstrates that modifying input formats, such as vertically aligning words for encoder-based models, can substantially lower accuracy in text classification tasks. While easily understood by humans, these inputs can significantly mislead models, posing a potential risk of bypassing detection in real-world scenarios involving harmful or sensitive information. With the expanding application of LLMs, a crucial question arises: Do decoder-based LLMs exhibit similar vulnerabilities to vertically formatted text input? In this paper, we investigate the impact of vertical text input on the performance of various LLMs across multiple text classification datasets and analyze the underlying causes. Our findings are as follows: (i) Vertical text input significantly degrades the accuracy of LLMs in text classification tasks. (ii) Chain-of-Thought (CoT) reasoning does not help LLMs recognize vertical input or mitigate its vulnerability, but few-shot learning with careful analysis does. (iii) We explore the underlying cause of the vulnerability by analyzing the inherent issues in tokenization and attention matrices.
title Vulnerability of LLMs to Vertically Aligned Text Manipulations
topic Computation and Language
url https://arxiv.org/abs/2410.20016