发现大模型攻击成功率随样本数呈多项式到指数的跃迁现象
Jailbreak Scaling Laws for Large Language Models: Polynomial-Exponential Crossover
- 用统计机制解释攻击成功率为多项式或指数增长
- 注入短提示得幂律增长,长提示则达指数级提升
- 在3B至70B模型上均稳定,适用于多种攻击方法
对抗性攻击可可靠引导安全对齐的大语言模型产生不安全行为。实验发现,通过注入提示,攻击成功率从无注入时的缓慢多项式增长,跃升为与推理样本数呈指数增长。我们首先基于对上下文安全生成分布的少量假设,识别出这两种行为模式的最小统计机制。为进一步解释该现象,提出一种基于自旋玻璃系统的理论生成模型,其在副本对称性破缺下运行,生成物来自关联的吉布斯测度,其中部分低能量、规模偏倚的簇被定义为不安全。分析表明该模型自然满足前述假设。短注入提示相当于弱磁场,指向不安全簇中心,导致幂律增长;长提示即强磁场,则引发指数增长。该现象在参数量3B至70B的大模型中广泛一致,且在GCG、AutoDAN等攻击方法及AdvBench、HarmBench等数据集上趋势保持稳定。
原文摘要 · Abstract (English)
Adversarial attacks can reliably steer safety-aligned large language models toward unsafe behavior. Empirically, we find that adversarial prompt-injection attacks can amplify attack success rate from the slow polynomial growth observed without injection to exponential growth with the number of inference-time samples. We first identify a minimal statistical mechanism for these two regimes by giving a small set of assumptions on the distribution of safe generation across contexts under which both scaling laws follow. To explain this phenomenon further, we propose a theoretical generative model of proxy language in terms of a spin-glass system operating in a replica-symmetry-breaking regime, where generations are drawn from the associated Gibbs measure and a subset of low-energy, size-biased clusters is designated unsafe. We analytically show how this model naturally realizes the minimal assumptions. Short injected prompts correspond to a weak magnetic field aligned towards unsafe cluster centers and yield a power-law scaling of attack success rate with the number of inference-time samples, while long injected prompts, i.e., strong magnetic field, yield exponential scaling. We observe qualitatively consistent behavior across a broad range of large language models, spanning parameter scales from 3B to 70B. In particular, the main trends remain stable across multiple attack methods, such as GCG and AutoDAN, as well as across benchmark datasets such as AdvBench and HarmBench.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。