Adversarial Distilled Retrieval-Augmented Guarding Model for Online Malicious Intent Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Guo, Yihao, Bian, Haocheng, Zhou, Liutong, Wang, Ze, Zhang, Zhaoyi, Kawala, Francois, Dean, Milan, Fischer, Ian, Peng, Yuantao, Tokgozoglu, Noyan, Barrientos, Ivan, Shaik, Riyaaz, Li, Rachel, Venkataraman, Chandru, Far, Reza Shifteh, Pawar, Moses, Sundaranatha, Venkat, Xu, Michael, Chu, Frank
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909881495191552
author Guo, Yihao
Bian, Haocheng
Zhou, Liutong
Wang, Ze
Zhang, Zhaoyi
Kawala, Francois
Dean, Milan
Fischer, Ian
Peng, Yuantao
Tokgozoglu, Noyan
Barrientos, Ivan
Shaik, Riyaaz
Li, Rachel
Venkataraman, Chandru
Far, Reza Shifteh
Pawar, Moses
Sundaranatha, Venkat
Xu, Michael
Chu, Frank
author_facet Guo, Yihao
Bian, Haocheng
Zhou, Liutong
Wang, Ze
Zhang, Zhaoyi
Kawala, Francois
Dean, Milan
Fischer, Ian
Peng, Yuantao
Tokgozoglu, Noyan
Barrientos, Ivan
Shaik, Riyaaz
Li, Rachel
Venkataraman, Chandru
Far, Reza Shifteh
Pawar, Moses
Sundaranatha, Venkat
Xu, Michael
Chu, Frank
contents With the deployment of Large Language Models (LLMs) in interactive applications, online malicious intent detection has become increasingly critical. However, existing approaches fall short of handling diverse and complex user queries in real time. To address these challenges, we introduce ADRAG (Adversarial Distilled Retrieval-Augmented Guard), a two-stage framework for robust and efficient online malicious intent detection. In the training stage, a high-capacity teacher model is trained on adversarially perturbed, retrieval-augmented inputs to learn robust decision boundaries over diverse and complex user queries. In the inference stage, a distillation scheduler transfers the teacher's knowledge into a compact student model, with a continually updated knowledge base collected online. At deployment, the compact student model leverages top-K similar safety exemplars retrieved from the online-updated knowledge base to enable both online and real-time malicious query detection. Evaluations across ten safety benchmarks demonstrate that ADRAG, with a 149M-parameter model, achieves 98.5% of WildGuard-7B's performance, surpasses GPT-4 by 3.3% and Llama-Guard-3-8B by 9.5% on out-of-distribution detection, while simultaneously delivering up to 5.6x lower latency at 300 queries per second (QPS) in real-time applications.
format Preprint
id arxiv_https___arxiv_org_abs_2509_14622
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Distilled Retrieval-Augmented Guarding Model for Online Malicious Intent Detection
Guo, Yihao
Bian, Haocheng
Zhou, Liutong
Wang, Ze
Zhang, Zhaoyi
Kawala, Francois
Dean, Milan
Fischer, Ian
Peng, Yuantao
Tokgozoglu, Noyan
Barrientos, Ivan
Shaik, Riyaaz
Li, Rachel
Venkataraman, Chandru
Far, Reza Shifteh
Pawar, Moses
Sundaranatha, Venkat
Xu, Michael
Chu, Frank
Cryptography and Security
Artificial Intelligence
Machine Learning
With the deployment of Large Language Models (LLMs) in interactive applications, online malicious intent detection has become increasingly critical. However, existing approaches fall short of handling diverse and complex user queries in real time. To address these challenges, we introduce ADRAG (Adversarial Distilled Retrieval-Augmented Guard), a two-stage framework for robust and efficient online malicious intent detection. In the training stage, a high-capacity teacher model is trained on adversarially perturbed, retrieval-augmented inputs to learn robust decision boundaries over diverse and complex user queries. In the inference stage, a distillation scheduler transfers the teacher's knowledge into a compact student model, with a continually updated knowledge base collected online. At deployment, the compact student model leverages top-K similar safety exemplars retrieved from the online-updated knowledge base to enable both online and real-time malicious query detection. Evaluations across ten safety benchmarks demonstrate that ADRAG, with a 149M-parameter model, achieves 98.5% of WildGuard-7B's performance, surpasses GPT-4 by 3.3% and Llama-Guard-3-8B by 9.5% on out-of-distribution detection, while simultaneously delivering up to 5.6x lower latency at 300 queries per second (QPS) in real-time applications.
title Adversarial Distilled Retrieval-Augmented Guarding Model for Online Malicious Intent Detection
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2509.14622