Few-shot示例对不同提示防御策略有相反影响,需谨慎使用。
How Few-shot Demonstrations Affect Prompt-based Defenses Against LLM Jailbreak Attacks
- 通过少样本示例强化角色身份,提升角色提示安全率
- 少样本会分散注意力,使任务提示安全率下降21.2%
- 研究结果为实际部署提示防御提供可操作建议
大型语言模型(LLMs)面临日益严重的越狱攻击威胁,此类攻击可绕过安全对齐机制。尽管基于提示的防御方法如角色导向提示(RoP)和任务导向提示(ToP)已证明有效,但少样本示例在这些策略中的作用仍不明确。现有研究认为少样本可能损害安全性,但缺乏对少样本与不同系统提示策略交互关系的深入分析。本文在多个主流LLM上,基于四个安全基准(AdvBench、HarmBench、SG-Bench、XSTest)和六种越狱攻击方法,进行了全面评估。关键发现表明:少样本示例对RoP和ToP产生相反效果——其可将RoP的安全率提升最高4.5%,通过强化角色身份;而使ToP的有效性下降最高21.2%,因分散对任务指令的注意力。基于此,本文为实际应用中部署提示防御提供了具体建议。
原文摘要 · Abstract (English)
Large Language Models (LLMs) face increasing threats from jailbreak attacks that bypass safety alignment. While prompt-based defenses such as Role-Oriented Prompts (RoP) and Task-Oriented Prompts (ToP) have shown effectiveness, the role of few-shot demonstrations in these defense strategies remains unclear. Prior work suggests that few-shot examples may compromise safety, but lacks investigation into how few-shot interacts with different system prompt strategies. In this paper, we conduct a comprehensive evaluation on multiple mainstream LLMs across four safety benchmarks (AdvBench, HarmBench, SG-Bench, XSTest) using six jailbreak attack methods. Our key finding reveals that few-shot demonstrations produce opposite effects on RoP and ToP: few-shot enhances RoP's safety rate by up to 4.5% through reinforcing role identity, while it degrades ToP's effectiveness by up to 21.2% through distracting attention from task instructions. Based on these findings, we provide practical recommendations for deploying prompt-based defenses in real-world LLM applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。