Smoothed Embeddings for Robust Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hase, Ryo, Rashid, Md Rafi Ur, Lewis, Ashley, Liu, Jing, Koike-Akino, Toshiaki, Parsons, Kieran, Wang, Ye
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916586417291264
author Hase, Ryo
Rashid, Md Rafi Ur
Lewis, Ashley
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Wang, Ye
author_facet Hase, Ryo
Rashid, Md Rafi Ur
Lewis, Ashley
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Wang, Ye
contents Improving the safety and reliability of large language models (LLMs) is a crucial aspect of realizing trustworthy AI systems. Although alignment methods aim to suppress harmful content generation, LLMs are often still vulnerable to jailbreaking attacks that employ adversarial inputs that subvert alignment and induce harmful outputs. We propose the Randomized Embedding Smoothing and Token Aggregation (RESTA) defense, which adds random noise to the embedding vectors and performs aggregation during the generation of each output token, with the aim of better preserving semantic information. Our experiments demonstrate that our approach achieves superior robustness versus utility tradeoffs compared to the baseline defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2501_16497
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Smoothed Embeddings for Robust Language Models
Hase, Ryo
Rashid, Md Rafi Ur
Lewis, Ashley
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Wang, Ye
Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
68T07 (Primary), 68T50 (Secondary)
Improving the safety and reliability of large language models (LLMs) is a crucial aspect of realizing trustworthy AI systems. Although alignment methods aim to suppress harmful content generation, LLMs are often still vulnerable to jailbreaking attacks that employ adversarial inputs that subvert alignment and induce harmful outputs. We propose the Randomized Embedding Smoothing and Token Aggregation (RESTA) defense, which adds random noise to the embedding vectors and performs aggregation during the generation of each output token, with the aim of better preserving semantic information. Our experiments demonstrate that our approach achieves superior robustness versus utility tradeoffs compared to the baseline defenses.
title Smoothed Embeddings for Robust Language Models
topic Machine Learning
Artificial Intelligence
Computation and Language
Cryptography and Security
68T07 (Primary), 68T50 (Secondary)
url https://arxiv.org/abs/2501.16497