TensorX
返回文献探索

Paper · arXiv 2402.14020

Coercing LLMs to do and reveal (almost) anything

Jonas Geiping, Alex Stein, Manli Shu, Khalid Saifullah, Yuxin Wen, Tom Goldstein

13 upvotesFebruary 21, 2024arXiv 预印本
AI 摘要

Adversarial attacks on large language models can cause a variety of unintended behaviors, including misdirection, control, denial-of-service, and data extraction, often due to coding capabilities and unsecured tokens in pre-training.

adversarial attackslarge language modelsjailbreakunintended behaviorsmisdirectionmodel controldenial-of-servicedata extractionpre-trainingcoding capabilitiesglitch tokens

Abstract

It has recently been shown that adversarial attacks on large language models (LLMs) can "jailbreak" the model into making harmful statements. In this work, we argue that the spectrum of adversarial attacks on LLMs is much larger than merely jailbreaking. We provide a broad overview of possible attack surfaces and attack goals. Based on a series of concrete examples, we discuss, categorize and systematize attacks that coerce varied unintended behaviors, such as misdirection, model control, denial-of-service, or data extraction. We analyze these attacks in controlled experiments, and find that many of them stem from the practice of pre-training LLMs with coding capabilities, as well as the continued existence of strange "glitch" tokens in common LLM vocabularies that should be removed for security reasons.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号
Coercing LLMs to do and reveal (almost) anything | TensorX