通过动态调整表示空间,有效防御大模型越狱攻击。
SafeInt: Shielding Large Language Models from Jailbreak Attacks via Safety-Aware Representation Intervention
- 基于安全感知的表示干预,动态重定位越狱样本
- 在六种攻击、两数据集上均优于现有方法
- 适合关注模型安全与实用性的研究者
随着大语言模型(LLMs)在真实场景中的广泛应用,确保其行为符合安全标准变得至关重要。越狱攻击利用LLM漏洞诱导不当行为,严重威胁模型安全性。以往防御方法难以兼顾有效性与效率。从表示层面出发的防御提供了新思路,但现有干预无法根据查询危害性动态调整表示。为此,我们提出SafeInt,一种通过安全感知表示干预来防御越狱攻击的新方法。基于对越狱样本表示的分析,SafeInt的核心思想是将越狱相关表示移入拒绝区域,通过干预越狱样本的表示分布,使其与不安全样本对齐。我们在六个越狱攻击、两个越狱数据集和两个效用基准上进行了全面实验。结果表明,SafeInt在抵御越狱攻击方面优于所有基线方法,同时大幅保持了模型效用。此外,我们评估了其对抗自适应攻击的能力,并验证了其在实时攻击中的有效性。
原文摘要 · Abstract (English)
With the widespread real-world deployment of large language models (LLMs), ensuring their behavior complies with safety standards has become crucial. Jailbreak attacks exploit vulnerabilities in LLMs to induce undesirable behavior, posing a significant threat to LLM safety. Previous defenses often fail to achieve both effectiveness and efficiency simultaneously. Defenses from a representation perspective offer new insights, but existing interventions cannot dynamically adjust representations based on the harmfulness of the queries. To address this limitation, we propose SafeIntervention (SafeInt), a novel defense method that shields LLMs from jailbreak attacks through safety-aware representation intervention. Built on our analysis of the representations of jailbreak samples, the core idea of SafeInt is to relocate jailbreak-related representations into the rejection region. This is achieved by intervening in the representation distributions of jailbreak samples to align them with those of unsafe samples. We conduct comprehensive experiments covering six jailbreak attacks, two jailbreak datasets, and two utility benchmarks. Experimental results demonstrate that SafeInt outperforms all baselines in defending LLMs against jailbreak attacks while largely maintaining utility. Additionally, we evaluate SafeInt against adaptive attacks and verify its effectiveness in mitigating real-time attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。