Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
41 tokens/sec
GPT-4o
60 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
8 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Dr. Jekyll and Mr. Hyde: Two Faces of LLMs (2312.03853v5)

Published 6 Dec 2023 in cs.CR and cs.LG

Abstract: Recently, we have witnessed a rise in the use of LLMs, especially in applications like chatbots. Safety mechanisms are implemented to prevent improper responses from these chatbots. In this work, we bypass these measures for ChatGPT and Gemini by making them impersonate complex personas with personality characteristics that are not aligned with a truthful assistant. First, we create elaborate biographies of these personas, which we then use in a new session with the same chatbots. Our conversations then follow a role-play style to elicit prohibited responses. Using personas, we show that prohibited responses are provided, making it possible to obtain unauthorized, illegal, or harmful information in both ChatGPT and Gemini. We also introduce several ways of activating such adversarial personas, showing that both chatbots are vulnerable to this attack. With the same principle, we introduce two defenses that push the model to interpret trustworthy personalities and make it more robust against such attacks.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Matteo Gioele Collu (1 paper)
  2. Tom Janssen-Groesbeek (1 paper)
  3. Stefanos Koffas (18 papers)
  4. Mauro Conti (195 papers)
  5. Stjepan Picek (68 papers)
Citations (1)