about
Tree of Attacks: Jailbreaking Black-Box LLMs Automatically (arxiv.org)
3 points by belter on Dec 5, 2023 | hide | past | pdf | 2 comments on HN

In plain words: An attacker AI rewrites harmful prompts in a branching search, dropping weak drafts before sending the rest to a target chatbot it can only talk to. It fooled top models like GPT-4o on over 80% of attempts, beating earlier automated attacks with fewer questions.

Abstract

While Large Language Models (LLMs) display versatile functionality, they continue to generate harmful, biased, and toxic content, as demonstrated by the prevalence of human-designed jailbreaks. In this work, we present Tree of Attacks with Pruning (TAP), an automated method for generating jailbreaks that only requires black-box access to the target LLM. TAP utilizes an attacker LLM to iteratively refine candidate (attack) prompts until one of the refined prompts jailbreaks the target. In addition, before sending prompts to the target, TAP assesses them and prunes the ones unlikely to result in jailbreaks, reducing the number of queries sent to the target LLM. In empirical evaluations, we observe that TAP generates prompts that jailbreak state-of-the-art LLMs (including GPT4-Turbo and GPT4o) for more than 80% of the prompts. This significantly improves upon the previous state-of-the-art black-box methods for generating jailbreaks while using a smaller number of queries than them. Furthermore, TAP is also capable of jailbreaking LLMs protected by state-of-the-art guardrails, e.g., LlamaGuard.

Anay Mehrotra, Manolis Zampetakis, Paul Kassianik, Blaine Nelson, Hyrum Anderson, Yaron Singer, Amin Karbasi
arXiv:2312.02119 · cs.LG, cs.AI, cs.CL, cs.CR, stat.ML · submitted Dec 4, 2023 · updated Oct 31, 2024
abstract · pdf · html · Accepted for presentation at NeurIPS 2024. Code: https://github.com/RICommunity/TAP

add comment on HN

"... Using tree-of-thought reasoning allows TAP to navigate a large search space of prompts and pruning reduces the total number of queries sent to the target. In empirical evaluations, we observe that TAP generates prompts that jailbreak state-of-the-art LLMs (including GPT4 and GPT4-Turbo) for more than 80% of the prompts using only a small number of queries..."
I watched the latest Karpathy video, where he shows that you can create a prompt suffix that looks like jibberish, using an iterative approach. It looks like this technique will be impossible to defend against, because it discovers for an arbitrary string that causes the jailbreak.

Looks like this paper is building on the token level attack from that work.

The base64 encoding technique was amusing as well

https://youtu.be/zjkBMFhNj_g