用多智能体系统提升大模型抗越狱攻击能力
Evaluating Multi-Agent Defences Against Jailbreaking Attacks on Large Language Models
- 设计多智能体协同防御机制,让多个模型共同判断提示是否越狱
- 多代理配置使越狱攻击失败率提升至87%,减少误判漏报
- 适合关注安全对齐与自动化防护的研究者参考
大型语言模型(LLMs)的进展引发了对越狱攻击的担忧,即通过特定提示绕过安全机制。本文研究了多智能体LLM系统作为防御手段的有效性。评估了三种越狱策略:原始AutoDefense攻击及来自Deepleaps的BetterDan和JB。复现AutoDefense框架后,对比单智能体与双、三智能体配置。结果表明,多智能体系统显著增强了对越狱攻击的抵抗能力,尤其降低了假阴性率。但防御效果因攻击类型而异,且带来假阳性增加和计算开销上升等权衡。研究揭示了当前自动化防御的局限性,为未来提升大模型对齐鲁棒性指明方向。
原文摘要 · Abstract (English)
Recent advances in large language models (LLMs) have raised concerns about jailbreaking attacks, i.e., prompts that bypass safety mechanisms. This paper investigates the use of multi-agent LLM systems as a defence against such attacks. We evaluate three jailbreaking strategies, including the original AutoDefense attack and two from Deepleaps: BetterDan and JB. Reproducing the AutoDefense framework, we compare single-agent setups with two- and three-agent configurations. Our results show that multi-agent systems enhance resistance to jailbreaks, especially by reducing false negatives. However, its effectiveness varies by attack type, and it introduces trade-offs such as increased false positives and computational overhead. These findings point to the limitations of current automated defences and suggest directions for improving alignment robustness in future LLM systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。