Target-driven Attack for Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Chong, Jin, Mingyu, Shu, Dong, Wang, Taowen, Liu, Dongfang, Jin, Xiaobo
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915017250570240
author Zhang, Chong
Jin, Mingyu
Shu, Dong
Wang, Taowen
Liu, Dongfang
Jin, Xiaobo
author_facet Zhang, Chong
Jin, Mingyu
Shu, Dong
Wang, Taowen
Liu, Dongfang
Jin, Xiaobo
contents Current large language models (LLM) provide a strong foundation for large-scale user-oriented natural language tasks. Many users can easily inject adversarial text or instructions through the user interface, thus causing LLM model security challenges like the language model not giving the correct answer. Although there is currently a large amount of research on black-box attacks, most of these black-box attacks use random and heuristic strategies. It is unclear how these strategies relate to the success rate of attacks and thus effectively improve model robustness. To solve this problem, we propose our target-driven black-box attack method to maximize the KL divergence between the conditional probabilities of the clean text and the attack text to redefine the attack's goal. We transform the distance maximization problem into two convex optimization problems based on the attack goal to solve the attack text and estimate the covariance. Furthermore, the projected gradient descent algorithm solves the vector corresponding to the attack text. Our target-driven black-box attack approach includes two attack strategies: token manipulation and misinformation attack. Experimental results on multiple Large Language Models and datasets demonstrate the effectiveness of our attack method.
format Preprint
id arxiv_https___arxiv_org_abs_2411_07268
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Target-driven Attack for Large Language Models
Zhang, Chong
Jin, Mingyu
Shu, Dong
Wang, Taowen
Liu, Dongfang
Jin, Xiaobo
Computation and Language
Artificial Intelligence
Current large language models (LLM) provide a strong foundation for large-scale user-oriented natural language tasks. Many users can easily inject adversarial text or instructions through the user interface, thus causing LLM model security challenges like the language model not giving the correct answer. Although there is currently a large amount of research on black-box attacks, most of these black-box attacks use random and heuristic strategies. It is unclear how these strategies relate to the success rate of attacks and thus effectively improve model robustness. To solve this problem, we propose our target-driven black-box attack method to maximize the KL divergence between the conditional probabilities of the clean text and the attack text to redefine the attack's goal. We transform the distance maximization problem into two convex optimization problems based on the attack goal to solve the attack text and estimate the covariance. Furthermore, the projected gradient descent algorithm solves the vector corresponding to the attack text. Our target-driven black-box attack approach includes two attack strategies: token manipulation and misinformation attack. Experimental results on multiple Large Language Models and datasets demonstrate the effectiveness of our attack method.
title Target-driven Attack for Large Language Models
topic Computation and Language
Artificial Intelligence
url https://arxiv.org/abs/2411.07268