乱序表格可骗过大模型,暴露其结构敏感缺陷。
The Power of Order: Fooling LLMs with Adversarial Table Permutations

- 用梯度攻击生成破坏性排列,精准扰乱模型输入。
- 多种大模型在乱序表下准确率大幅下降,跨架构普遍失效。
- 提醒开发者:真实场景需构建抗排列干扰的鲁棒模型。
大型语言模型在表格问答等关键应用中表现优异,但其对输入结构的鲁棒性仍存重大隐患。本文揭示现代大模型对表格布局高度敏感:即使仅改变行列顺序(语义不变),也可能导致模型输出错误或不一致。为此,提出基于梯度的对抗性表格排列攻击(Adversarial Table Permutation, ATP),高效生成最易破坏模型性能的排列组合。大量实验表明,ATP显著降低多种大模型性能,涵盖不同规模与架构,包括最新主流模型。该结果暴露当前大模型处理结构化数据的根本弱点,亟需发展具备排列鲁棒性的新模型以保障实际应用可靠性。
原文摘要 · Abstract (English)
Large Language Models have achieved remarkable success and are increasingly deployed in critical applications involving tabular data, such as Table Question Answering. However, their robustness to the structure of this input remains a critical, unaddressed question. This paper demonstrates that modern LLMs exhibit a significant vulnerability to the layout of tabular data. Specifically, we show that semantically-invariant permutations of rows and columns - rearrangements that do not alter the table's underlying information - are sometimes sufficient to cause incorrect or inconsistent model outputs. To systematically probe this vulnerability, we introduce Adversarial Table Permutation, a novel, gradient-based attack that efficiently identifies worst-case permutations designed to maximally disrupt model performance. Our extensive experiments demonstrate that ATP significantly degrades the performance of a wide range of LLMs. This reveals a pervasive vulnerability across different model sizes and architectures, including the most recent and popular models. Our findings expose a fundamental weakness in how current LLMs process structured data, underscoring the urgent need to develop permutation-robust models for reliable, real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。