Jailbreak Distillation: Renewable Safety Benchmarking

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Jingyu, Elgohary, Ahmed, Wang, Xiawei, Iftekhar, A S M, Magooda, Ahmed, Van Durme, Benjamin, Khashabi, Daniel, Jackson, Kyle
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908382701551616
author Zhang, Jingyu
Elgohary, Ahmed
Wang, Xiawei
Iftekhar, A S M
Magooda, Ahmed
Van Durme, Benjamin
Khashabi, Daniel
Jackson, Kyle
author_facet Zhang, Jingyu
Elgohary, Ahmed
Wang, Xiawei
Iftekhar, A S M
Magooda, Ahmed
Van Durme, Benjamin
Khashabi, Daniel
Jackson, Kyle
contents Large language models (LLMs) are rapidly deployed in critical applications, raising urgent needs for robust safety benchmarking. We propose Jailbreak Distillation (JBDistill), a novel benchmark construction framework that "distills" jailbreak attacks into high-quality and easily-updatable safety benchmarks. JBDistill utilizes a small set of development models and existing jailbreak attack algorithms to create a candidate prompt pool, then employs prompt selection algorithms to identify an effective subset of prompts as safety benchmarks. JBDistill addresses challenges in existing safety evaluation: the use of consistent evaluation prompts across models ensures fair comparisons and reproducibility. It requires minimal human effort to rerun the JBDistill pipeline and produce updated benchmarks, alleviating concerns on saturation and contamination. Extensive experiments demonstrate our benchmarks generalize robustly to 13 diverse evaluation models held out from benchmark construction, including proprietary, specialized, and newer-generation LLMs, significantly outperforming existing safety benchmarks in effectiveness while maintaining high separability and diversity. Our framework thus provides an effective, sustainable, and adaptable solution for streamlining safety evaluation.
format Preprint
id arxiv_https___arxiv_org_abs_2505_22037
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Jailbreak Distillation: Renewable Safety Benchmarking
Zhang, Jingyu
Elgohary, Ahmed
Wang, Xiawei
Iftekhar, A S M
Magooda, Ahmed
Van Durme, Benjamin
Khashabi, Daniel
Jackson, Kyle
Computation and Language
Cryptography and Security
Software Engineering
Large language models (LLMs) are rapidly deployed in critical applications, raising urgent needs for robust safety benchmarking. We propose Jailbreak Distillation (JBDistill), a novel benchmark construction framework that "distills" jailbreak attacks into high-quality and easily-updatable safety benchmarks. JBDistill utilizes a small set of development models and existing jailbreak attack algorithms to create a candidate prompt pool, then employs prompt selection algorithms to identify an effective subset of prompts as safety benchmarks. JBDistill addresses challenges in existing safety evaluation: the use of consistent evaluation prompts across models ensures fair comparisons and reproducibility. It requires minimal human effort to rerun the JBDistill pipeline and produce updated benchmarks, alleviating concerns on saturation and contamination. Extensive experiments demonstrate our benchmarks generalize robustly to 13 diverse evaluation models held out from benchmark construction, including proprietary, specialized, and newer-generation LLMs, significantly outperforming existing safety benchmarks in effectiveness while maintaining high separability and diversity. Our framework thus provides an effective, sustainable, and adaptable solution for streamlining safety evaluation.
title Jailbreak Distillation: Renewable Safety Benchmarking
topic Computation and Language
Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2505.22037