发现大模型越狱攻击成功率不稳定,提出新评估与生成框架提升可靠性。
The Great Pretender: A Stochasticity Problem in LLM Jailbreak

- 分析攻击生成与评估中的随机性影响,揭示成功率波动根源。
- 实测同一提示在多次尝试中成功率最高下降30个百分点。
- 提出新框架可恢复因随机性损失的30%成功率,适合安全研究者参考。
‘Oh-Oh, yes, I'm the great pretender’道出了当前越狱攻击研究的困境:尽管某权威机构提出的攻击方法(如Anthropic的BoN或微软研究院的Crescendo)在论文中宣称对工业级大模型具备高攻击成功率(ASR),但实际应用时却表现不稳。例如,针对开源目标模型生成的越狱提示,在10次连续测试中仅成功5次(50%成功率),远低于其宣称的80%理论值。我们发现,攻击成功率(ASR)并非稳定指标,且现有报告数值普遍被高估、难以横向比较。究其原因,源于攻击生成与评估过程中存在的随机性。为此,我们构建了新评估框架CAS-eval与生成框架CAS-gen。CAS-eval显示,当要求提示连续成功时,ASR最高可下降30个百分点;而CAS-gen能有效弥补这一损失,显著提升攻击稳定性。该研究揭示了当前评测体系的根本缺陷,并提供了更可靠的解决方案。
原文摘要 · Abstract (English)
"Oh-Oh, yes, I'm the great pretender. Pretending that I'm doing well. My need is such, I pretend too much..." summarizes the state in the area of jailbreak creation and evaluation. You find this method to generate adversarial attacks proposed by a reputable institution (e.g., BoN from Anthropic or Crescendo from Microsoft Research). However, this method does not deliver on the promise claimed in the paper despite having top ASR scores against industry-grade LLMs. You successfully generate the jailbreak prompts against your target (open) model. However, the generated jailbreak prompt works against the target model with a 50% consecutive success rate (5 out of 10 attempts) despite having an 80% ASR (on paper) on the latest closed-source model (with a guardrail system)! This observation leads us to think. First, Attack Success Rate (ASR), the primary metric for LLM jailbreak benchmarking, is not a stable quantity. Second, published ASR numbers are therefore systematically inflated and incomparable across papers. Therefore, we wonder "Why a successful jailbreak prompt does not perform consistently well against a target model on which the prompts have been optimized?". To answer this question, we study the impact of stochasticity not only during attack evaluation but also during attack generation. Our evaluation includes several jailbreak attacks, models (different sizes and providers), and judges. In addition, we propose a new metric and two new frameworks (CAS-eval and CAS-gen). Our evaluation framework, CAS-eval, shows that an attack can have an ASR drop of up to 30 percentage points when a jailbreak prompt needs to succeed on more than one attempt. Thankfully, our attack generation framework (CAS-gen) improves previous jailbreak methods and helps them recover this loss of 30 percentage points!
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。