arXiv:2504.05652cs.CRcs.CL2025-04EMNLP被引 9

用良性生成诱导模型失守,87%成功率突破安全防线

Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking

  • 用语义反转构造看似无害的恶意输入
  • 在6个大模型上平均攻击成功率达87.23%
  • 适合研究安全机制与对抗攻击的读者

随着大语言模型(LLMs)在各领域深度集成,其安全机制有效性面临严峻挑战。基于提示工程的越狱攻击已成为主要安全威胁。现有方法多依赖黑盒提示模板操纵,可解释性差且泛化能力有限。本研究首次提出防御阈值衰减(DTD)概念,揭示良性内容生成会削弱模型对指令的关注度。基于此,提出糖衣毒药(SCP)攻击范式,通过语义反转策略构造表面良性实则恶意的输入,诱导模型生成大量良性内容,从而让恶意推理绕过安全机制。实验表明,SCP在六种主流大模型上平均攻击成功率达87.23%,显著优于基线方法。为应对该威胁,提出词性防御(POSD),利用动词-名词依赖关系进行句法分析,在不损害模型泛化能力的前提下增强安全性。

原文摘要 · Abstract (English)

With the increasingly deep integration of large language models (LLMs) across diverse domains, the effectiveness of their safety mechanisms is encountering severe challenges. Currently, jailbreak attacks based on prompt engineering have become a major safety threat. However, existing methods primarily rely on black-box manipulation of prompt templates, resulting in poor interpretability and limited generalization. To break through the bottleneck, this study first introduces the concept of Defense Threshold Decay (DTD), revealing the potential safety impact caused by LLMs' benign generation: as benign content generation in LLMs increases, the model's focus on input instructions progressively diminishes. Building on this insight, we propose the Sugar-Coated Poison (SCP) attack paradigm, which uses a "semantic reversal" strategy to craft benign inputs that are opposite in meaning to malicious intent. This strategy induces the models to generate extensive benign content, thereby enabling adversarial reasoning to bypass safety mechanisms. Experiments show that SCP outperforms existing baselines. Remarkably, it achieves an average attack success rate of 87.23% across six LLMs. For defense, we propose Part-of-Speech Defense (POSD), leveraging verb-noun dependencies for syntactic analysis to enhance safety of LLMs while preserving their generalization ability.

大模型安全越狱攻击语义反转防御机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。