MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Wang, Fengxiang, Duan, Ranjie, Xiao, Peng, Jia, Xiaojun, Zhao, Shiji, Wei, Cheng, Chen, YueFeng, Wang, Chongwen, Tao, Jialing, Su, Hang, Zhu, Jun, Xue, Hui
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915093310078976
author Wang, Fengxiang
Duan, Ranjie
Xiao, Peng
Jia, Xiaojun
Zhao, Shiji
Wei, Cheng
Chen, YueFeng
Wang, Chongwen
Tao, Jialing
Su, Hang
Zhu, Jun
Xue, Hui
author_facet Wang, Fengxiang
Duan, Ranjie
Xiao, Peng
Jia, Xiaojun
Zhao, Shiji
Wei, Cheng
Chen, YueFeng
Wang, Chongwen
Tao, Jialing
Su, Hang
Zhu, Jun
Xue, Hui
contents Large Language Models (LLMs) demonstrate outstanding performance in their reservoir of knowledge and understanding capabilities, but they have also been shown to be prone to illegal or unethical reactions when subjected to jailbreak attacks. To ensure their responsible deployment in critical applications, it is crucial to understand the safety capabilities and vulnerabilities of LLMs. Previous works mainly focus on jailbreak in single-round dialogue, overlooking the potential jailbreak risks in multi-round dialogues, which are a vital way humans interact with and extract information from LLMs. Some studies have increasingly concentrated on the risks associated with jailbreak in multi-round dialogues. These efforts typically involve the use of manually crafted templates or prompt engineering techniques. However, due to the inherent complexity of multi-round dialogues, their jailbreak performance is limited. To solve this problem, we propose a novel multi-round dialogue jailbreaking agent, emphasizing the importance of stealthiness in identifying and mitigating potential threats to human values posed by LLMs. We propose a risk decomposition strategy that distributes risks across multiple rounds of queries and utilizes psychological strategies to enhance attack strength. Extensive experiments show that our proposed method surpasses other attack methods and achieves state-of-the-art attack success rate. We will make the corresponding code and dataset available for future research. The code will be released soon.
format Preprint
id arxiv_https___arxiv_org_abs_2411_03814
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue
Wang, Fengxiang
Duan, Ranjie
Xiao, Peng
Jia, Xiaojun
Zhao, Shiji
Wei, Cheng
Chen, YueFeng
Wang, Chongwen
Tao, Jialing
Su, Hang
Zhu, Jun
Xue, Hui
Artificial Intelligence
Computation and Language
Cryptography and Security
Large Language Models (LLMs) demonstrate outstanding performance in their reservoir of knowledge and understanding capabilities, but they have also been shown to be prone to illegal or unethical reactions when subjected to jailbreak attacks. To ensure their responsible deployment in critical applications, it is crucial to understand the safety capabilities and vulnerabilities of LLMs. Previous works mainly focus on jailbreak in single-round dialogue, overlooking the potential jailbreak risks in multi-round dialogues, which are a vital way humans interact with and extract information from LLMs. Some studies have increasingly concentrated on the risks associated with jailbreak in multi-round dialogues. These efforts typically involve the use of manually crafted templates or prompt engineering techniques. However, due to the inherent complexity of multi-round dialogues, their jailbreak performance is limited. To solve this problem, we propose a novel multi-round dialogue jailbreaking agent, emphasizing the importance of stealthiness in identifying and mitigating potential threats to human values posed by LLMs. We propose a risk decomposition strategy that distributes risks across multiple rounds of queries and utilizes psychological strategies to enhance attack strength. Extensive experiments show that our proposed method surpasses other attack methods and achieves state-of-the-art attack success rate. We will make the corresponding code and dataset available for future research. The code will be released soon.
title MRJ-Agent: An Effective Jailbreak Agent for Multi-Round Dialogue
topic Artificial Intelligence
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2411.03814