Eliciting Language Model Behaviors with Investigator Agents

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Li, Xiang Lisa, Chowdhury, Neil, Johnson, Daniel D., Hashimoto, Tatsunori, Liang, Percy, Schwettmann, Sarah, Steinhardt, Jacob
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916595143540736
author Li, Xiang Lisa
Chowdhury, Neil
Johnson, Daniel D.
Hashimoto, Tatsunori
Liang, Percy
Schwettmann, Sarah
Steinhardt, Jacob
author_facet Li, Xiang Lisa
Chowdhury, Neil
Johnson, Daniel D.
Hashimoto, Tatsunori
Liang, Percy
Schwettmann, Sarah
Steinhardt, Jacob
contents Language models exhibit complex, diverse behaviors when prompted with free-form text, making it difficult to characterize the space of possible outputs. We study the problem of behavior elicitation, where the goal is to search for prompts that induce specific target behaviors (e.g., hallucinations or harmful responses) from a target language model. To navigate the exponentially large space of possible prompts, we train investigator models to map randomly-chosen target behaviors to a diverse distribution of outputs that elicit them, similar to amortized Bayesian inference. We do this through supervised fine-tuning, reinforcement learning via DPO, and a novel Frank-Wolfe training objective to iteratively discover diverse prompting strategies. Our investigator models surface a variety of effective and human-interpretable prompts leading to jailbreaks, hallucinations, and open-ended aberrant behaviors, obtaining a 100% attack success rate on a subset of AdvBench (Harmful Behaviors) and an 85% hallucination rate.
format Preprint
id arxiv_https___arxiv_org_abs_2502_01236
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Eliciting Language Model Behaviors with Investigator Agents
Li, Xiang Lisa
Chowdhury, Neil
Johnson, Daniel D.
Hashimoto, Tatsunori
Liang, Percy
Schwettmann, Sarah
Steinhardt, Jacob
Machine Learning
Artificial Intelligence
Computation and Language
Language models exhibit complex, diverse behaviors when prompted with free-form text, making it difficult to characterize the space of possible outputs. We study the problem of behavior elicitation, where the goal is to search for prompts that induce specific target behaviors (e.g., hallucinations or harmful responses) from a target language model. To navigate the exponentially large space of possible prompts, we train investigator models to map randomly-chosen target behaviors to a diverse distribution of outputs that elicit them, similar to amortized Bayesian inference. We do this through supervised fine-tuning, reinforcement learning via DPO, and a novel Frank-Wolfe training objective to iteratively discover diverse prompting strategies. Our investigator models surface a variety of effective and human-interpretable prompts leading to jailbreaks, hallucinations, and open-ended aberrant behaviors, obtaining a 100% attack success rate on a subset of AdvBench (Harmful Behaviors) and an 85% hallucination rate.
title Eliciting Language Model Behaviors with Investigator Agents
topic Machine Learning
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2502.01236