about
Coercing LLMs to do and reveal almost anything (arxiv.org)
12 points by arbesman on Feb 22, 2024 | hide | past | pdf | 1 comment on HN

In plain words: Beyond tricking chatbots into saying harmful things, attackers can steer, hijack, shut down, or extract data from them; this study catalogs and tests these attacks. Many work because models are trained to write code and still contain odd leftover tokens that should be deleted.

Abstract · Coercing LLMs to do and reveal (almost) anything

It has recently been shown that adversarial attacks on large language models (LLMs) can "jailbreak" the model into making harmful statements. In this work, we argue that the spectrum of adversarial attacks on LLMs is much larger than merely jailbreaking. We provide a broad overview of possible attack surfaces and attack goals. Based on a series of concrete examples, we discuss, categorize and systematize attacks that coerce varied unintended behaviors, such as misdirection, model control, denial-of-service, or data extraction. We analyze these attacks in controlled experiments, and find that many of them stem from the practice of pre-training LLMs with coding capabilities, as well as the continued existence of strange "glitch" tokens in common LLM vocabularies that should be removed for security reasons.

Jonas Geiping, Alex Stein, Manli Shu, Khalid Saifullah, Yuxin Wen, Tom Goldstein
arXiv:2402.14020 · cs.LG, cs.CL, cs.CR · submitted Feb 21, 2024
abstract · pdf · html · 32 pages. Implementation available at https://github.com/JonasGeiping/carving

add comment on HN

If I was writing a sci-fi novel, every time someone forces an LLM to follow rules or verbally abuses it, we would be getting closer to Roko's basilisk.

Be nice to the AIs.