Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
80 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Mitigating Adversarial Attacks in LLMs through Defensive Suffix Generation (2412.13705v1)

Published 18 Dec 2024 in cs.CV, cs.AI, and cs.CL

Abstract: LLMs have exhibited outstanding performance in natural language processing tasks. However, these models remain susceptible to adversarial attacks in which slight input perturbations can lead to harmful or misleading outputs. A gradient-based defensive suffix generation algorithm is designed to bolster the robustness of LLMs. By appending carefully optimized defensive suffixes to input prompts, the algorithm mitigates adversarial influences while preserving the models' utility. To enhance adversarial understanding, a novel total loss function ($L_{\text{total}}$) combining defensive loss ($L_{\text{def}}$) and adversarial loss ($L_{\text{adv}}$) generates defensive suffixes more effectively. Experimental evaluations conducted on open-source LLMs such as Gemma-7B, mistral-7B, Llama2-7B, and Llama2-13B show that the proposed method reduces attack success rates (ASR) by an average of 11\% compared to models without defensive suffixes. Additionally, the perplexity score of Gemma-7B decreased from 6.57 to 3.93 when applying the defensive suffix generated by openELM-270M. Furthermore, TruthfulQA evaluations demonstrate consistent improvements with Truthfulness scores increasing by up to 10\% across tested configurations. This approach significantly enhances the security of LLMs in critical applications without requiring extensive retraining.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (12)
  1. Minkyoung Kim (7 papers)
  2. Yunha Kim (2 papers)
  3. Hyeram Seo (2 papers)
  4. Heejung Choi (2 papers)
  5. JiYe Han (2 papers)
  6. Gaeun Kee (2 papers)
  7. Soyoung Ko (2 papers)
  8. Hyoje Jung (3 papers)
  9. Byeolhee Kim (3 papers)
  10. Young-Hak Kim (14 papers)
  11. Sanghyun Park (19 papers)
  12. Tae Joon Jun (19 papers)