Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
41 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
41 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Distract Large Language Models for Automatic Jailbreak Attack (2403.08424v2)

Published 13 Mar 2024 in cs.CR, cs.AI, and cs.CL

Abstract: Extensive efforts have been made before the public release of LLMs to align their behaviors with human values. However, even meticulously aligned LLMs remain vulnerable to malicious manipulations such as jailbreaking, leading to unintended behaviors. In this work, we propose a novel black-box jailbreak framework for automated red teaming of LLMs. We designed malicious content concealing and memory reframing with an iterative optimization algorithm to jailbreak LLMs, motivated by the research about the distractibility and over-confidence phenomenon of LLMs. Extensive experiments of jailbreaking both open-source and proprietary LLMs demonstrate the superiority of our framework in terms of effectiveness, scalability and transferability. We also evaluate the effectiveness of existing jailbreak defense methods against our attack and highlight the crucial need to develop more effective and practical defense strategies.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (4)
  1. Zeguan Xiao (6 papers)
  2. Yan Yang (119 papers)
  3. Guanhua Chen (71 papers)
  4. Yun Chen (134 papers)
Citations (9)