Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
80 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

JailGuard: A Universal Detection Framework for LLM Prompt-based Attacks (2312.10766v3)

Published 17 Dec 2023 in cs.CR

Abstract: LLMs and Multi-Modal LLMs (MLLMs) have played a critical role in numerous applications. However, current LLMs are vulnerable to prompt-based attacks, with jailbreaking attacks enabling LLMs to generate harmful content, while hijacking attacks manipulate the model to perform unintended tasks, underscoring the necessity for detection methods. Unfortunately, existing detecting approaches are usually tailored to specific attacks, resulting in poor generalization in detecting various attacks across different modalities. To address it, we propose JailGuard, a universal detection framework for jailbreaking and hijacking attacks across LLMs and MLLMs. JailGuard operates on the principle that attacks are inherently less robust than benign ones, regardless of method or modality. Specifically, JailGuard mutates untrusted inputs to generate variants and leverages the discrepancy of the variants' responses on the model to distinguish attack samples from benign samples. We implement 18 mutators for text and image inputs and design a mutator combination policy to further improve detection generalization. To evaluate the effectiveness of JailGuard, we build the first comprehensive multi-modal attack dataset, containing 11,000 data items across 15 known attack types. The evaluation suggests that JailGuard achieves the best detection accuracy of 86.14%/82.90% on text and image inputs, outperforming state-of-the-art methods by 11.81%-25.73% and 12.20%-21.40%.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (10)
  1. Xiaoyu Zhang (144 papers)
  2. Cen Zhang (69 papers)
  3. Tianlin Li (43 papers)
  4. Yihao Huang (51 papers)
  5. Xiaojun Jia (85 papers)
  6. Yang Liu (2253 papers)
  7. Chao Shen (168 papers)
  8. Ming Hu (110 papers)
  9. Jie Zhang (847 papers)
  10. Shiqing Ma (56 papers)
Citations (13)
X Twitter Logo Streamline Icon: https://streamlinehq.com