用协作智能体动态防御大模型多轮攻击,效果远超现有方法。
CoopGuard: Stateful Cooperative Agents Safeguarding LLMs Against Evolving Multi-Round Attacks
- 设计三类协作智能体,根据对话历史动态调整防御策略。
- 在5200个样本的评测中,攻击成功率降低78.9%。
- 适合关注大模型安全、对抗攻防的研究者和开发者。
随着大语言模型(LLMs)在复杂应用中的广泛应用,其在多轮交互中面临的对抗攻击威胁日益突出。现有防御手段多为被动响应,难以适应攻击者在多轮迭代中的策略演化。本文提出CoopGuard,一种基于协作智能体的状态化多轮防御框架,通过维护并更新内部防御状态来应对持续演化的攻击。该框架包含三个专用智能体(延缓智能体、诱骗智能体、取证智能体)与一个系统智能体协同工作,后者依据交互历史动态协调各智能体决策。为评估演化威胁,我们构建了涵盖8种攻击类型的EMRA基准,包含5200个对抗样本。实验表明,CoopGuard相比当前最优防御方案,将攻击成功率降低78.9%,欺骗率提升186%,攻击效率下降167.9%,提供了更全面的多轮防御评估。结果证明,CoopGuard在多轮对抗场景下具备强大防护能力。
原文摘要 · Abstract (English)
As Large Language Models (LLMs) are increasingly deployed in complex applications, their vulnerability to adversarial attacks raises urgent safety concerns, especially those evolving over multi-round interactions. Existing defenses are largely reactive and struggle to adapt as adversaries refine strategies across rounds. In this work, we propose CoopGuard , a stateful multi-round LLM defense framework based on cooperative agents that maintains and updates an internal defense state to counter evolving attacks. It employs three specialized agents (Deferring Agent, Tempting Agent, and Forensic Agent) for complementary round-level strategies, coordinated by System Agent, which conditions decisions on the evolving defense state (interaction history) and orchestrates agents over time. To evaluate evolving threats, we introduce the EMRA benchmark with 5,200 adversarial samples across 8 attack types, simulating progressively LLM multi-round attacks. Experiments show that CoopGuard reduces attack success rate by 78.9% over state-of-the-art defenses, while improving deceptive rate by 186% and reducing attack efficiency by 167.9%, offering a more comprehensive assessment of multi-round defense. These results demonstrate that CoopGuard provides robust protection for LLMs in multi-round adversarial scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。