Crabs: Consuming Resource via Auto-generation for LLM-DoS Attack under Black-box Settings

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Yuanhe, Zhou, Zhenhong, Zhang, Wei, Wang, Xinyue, Jia, Xiaojun, Liu, Yang, Su, Sen
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912393916841984
author Zhang, Yuanhe
Zhou, Zhenhong
Zhang, Wei
Wang, Xinyue
Jia, Xiaojun
Liu, Yang
Su, Sen
author_facet Zhang, Yuanhe
Zhou, Zhenhong
Zhang, Wei
Wang, Xinyue
Jia, Xiaojun
Liu, Yang
Su, Sen
contents Large Language Models (LLMs) have demonstrated remarkable performance across diverse tasks yet still are vulnerable to external threats, particularly LLM Denial-of-Service (LLM-DoS) attacks. Specifically, LLM-DoS attacks aim to exhaust computational resources and block services. However, existing studies predominantly focus on white-box attacks, leaving black-box scenarios underexplored. In this paper, we introduce Auto-Generation for LLM-DoS (AutoDoS) attack, an automated algorithm designed for black-box LLMs. AutoDoS constructs the DoS Attack Tree and expands the node coverage to achieve effectiveness under black-box conditions. By transferability-driven iterative optimization, AutoDoS could work across different models in one prompt. Furthermore, we reveal that embedding the Length Trojan allows AutoDoS to bypass existing defenses more effectively. Experimental results show that AutoDoS significantly amplifies service response latency by over 250$\times\uparrow$, leading to severe resource consumption in terms of GPU utilization and memory usage. Our work provides a new perspective on LLM-DoS attacks and security defenses. Our code is available at https://github.com/shuita2333/AutoDoS.
format Preprint
id arxiv_https___arxiv_org_abs_2412_13879
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Crabs: Consuming Resource via Auto-generation for LLM-DoS Attack under Black-box Settings
Zhang, Yuanhe
Zhou, Zhenhong
Zhang, Wei
Wang, Xinyue
Jia, Xiaojun
Liu, Yang
Su, Sen
Computation and Language
Artificial Intelligence
Cryptography and Security
Large Language Models (LLMs) have demonstrated remarkable performance across diverse tasks yet still are vulnerable to external threats, particularly LLM Denial-of-Service (LLM-DoS) attacks. Specifically, LLM-DoS attacks aim to exhaust computational resources and block services. However, existing studies predominantly focus on white-box attacks, leaving black-box scenarios underexplored. In this paper, we introduce Auto-Generation for LLM-DoS (AutoDoS) attack, an automated algorithm designed for black-box LLMs. AutoDoS constructs the DoS Attack Tree and expands the node coverage to achieve effectiveness under black-box conditions. By transferability-driven iterative optimization, AutoDoS could work across different models in one prompt. Furthermore, we reveal that embedding the Length Trojan allows AutoDoS to bypass existing defenses more effectively. Experimental results show that AutoDoS significantly amplifies service response latency by over 250$\times\uparrow$, leading to severe resource consumption in terms of GPU utilization and memory usage. Our work provides a new perspective on LLM-DoS attacks and security defenses. Our code is available at https://github.com/shuita2333/AutoDoS.
title Crabs: Consuming Resource via Auto-generation for LLM-DoS Attack under Black-box Settings
topic Computation and Language
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2412.13879