about
Small Changes and Jailbreaks Affect Large Language Model Performance (arxiv.org)
2 points by belter on Apr 10, 2024 | hide | past | pdf | discuss on HN

In plain words: Testing tiny prompt edits—wording, output format, or jailbreak tricks—shows how much the labels a language model gives on text classification tasks can shift. Even a trailing space can flip an answer, and code-formatted output or jailbreaks scramble labels far more than plain asking.

Abstract · The Butterfly Effect of Altering Prompts: How Small Changes and Jailbreaks Affect Large Language Model Performance

Large Language Models (LLMs) are regularly being used to label data across many domains and for myriad tasks. By simply asking the LLM for an answer, or ``prompting,'' practitioners are able to use LLMs to quickly get a response for an arbitrary task. This prompting is done through a series of decisions by the practitioner, from simple wording of the prompt, to requesting the output in a certain data format, to jailbreaking in the case of prompts that address more sensitive topics. In this work, we ask: do variations in the way a prompt is constructed change the ultimate decision of the LLM? We answer this using a series of prompt variations across a variety of text classification tasks. We find that even the smallest of perturbations, such as adding a space at the end of a prompt, can cause the LLM to change its answer. Further, we find that requesting responses in XML and commonly used jailbreaks can have cataclysmic effects on the data labeled by LLMs.

Abel Salinas, Fred Morstatter
arXiv:2401.03729 · cs.CL, cs.AI · submitted Jan 8, 2024 · updated Apr 1, 2024
abstract · pdf · html

add comment on HN