用微小毒化数据诱导大模型生成侵权内容,且难以察觉。
PoisonedParrot: Subtle Data Poisoning Attacks to Elicit Copyright-Infringing Content from Large Language Models
- 将版权文本片段嵌入毒化样本,利用现成大模型生成攻击数据。
- 攻击后模型生成版权内容概率显著上升,无明显副作用。
- 现有防御手段基本无效,适合关注模型安全与版权风险的研究者。
随着大型语言模型(LLMs)能力持续增强,其应用日益广泛。然而,如众多关于模型生成内容的诉讼所反映,版权侵权问题仍是一大挑战。本文提出PoisonedParrot:首个隐蔽的数据投毒攻击,可使未直接训练于特定版权内容的LLM生成侵权文本。该攻击通过现成的LLM将少量版权文本片段融入毒化样本中。尽管方法简单,但在多种实验中均表现出显著效果,能有效诱导模型生成版权内容,且无明显副作用。此外,我们发现现有防御措施对此类攻击几乎无效。最后,我们首次尝试提出一种防御方案:ParrotTrap。呼吁社区深入探索这一新兴威胁模型。
原文摘要 · Abstract (English)
As the capabilities of large language models (LLMs) continue to expand, their usage has become increasingly prevalent. However, as reflected in numerous ongoing lawsuits regarding LLM-generated content, addressing copyright infringement remains a significant challenge. In this paper, we introduce PoisonedParrot: the first stealthy data poisoning attack that induces an LLM to generate copyrighted content even when the model has not been directly trained on the specific copyrighted material. PoisonedParrot integrates small fragments of copyrighted text into the poison samples using an off-the-shelf LLM. Despite its simplicity, evaluated in a wide range of experiments, PoisonedParrot is surprisingly effective at priming the model to generate copyrighted content with no discernible side effects. Moreover, we discover that existing defenses are largely ineffective against our attack. Finally, we make the first attempt at mitigating copyright-infringement poisoning attacks by proposing a defense: ParrotTrap. We encourage the community to explore this emerging threat model further.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。