TensorX
返回文献探索

Paper · arXiv 2308.04265

FLIRT: Feedback Loop In-context Red Teaming

Ninareh Mehrabi, Palash Goyal, Christophe Dupuy, Qian Hu, Shalini Ghosh, Richard Zemel, Kai-Wei Chang, Aram Galstyan, Rahul Gupta

14 upvotesAugust 8, 2023arXiv 预印本
AI 摘要

An automatic red teaming framework uses in-context learning to identify vulnerabilities in generative models, particularly effective for text-to-image and text-to-text models like Stable Diffusion.

in-context learningadversarial promptstext-to-image modelsstable diffusiontext-to-text modelstoxic response generation

Abstract

Warning: this paper contains content that may be inappropriate or offensive. As generative models become available for public use in various applications, testing and analyzing vulnerabilities of these models has become a priority. Here we propose an automatic red teaming framework that evaluates a given model and exposes its vulnerabilities against unsafe and inappropriate content generation. Our framework uses in-context learning in a feedback loop to red team models and trigger them into unsafe content generation. We propose different in-context attack strategies to automatically learn effective and diverse adversarial prompts for text-to-image models. Our experiments demonstrate that compared to baseline approaches, our proposed strategy is significantly more effective in exposing vulnerabilities in Stable Diffusion (SD) model, even when the latter is enhanced with safety features. Furthermore, we demonstrate that the proposed framework is effective for red teaming text-to-text models, resulting in significantly higher toxic response generation rate compared to previously reported numbers.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号