通过广度搜索提升对抗后缀优化,显著提高越狱攻击成功率。
Breadth Beats Depth: Improving GCG-Based Jailbreak Optimization with Breadth-Oriented Suffix Search

- 采用广度优先策略,避免陷入易突破区域
- 在多个基准上实现更高攻击成功率,且优化时间更短
- 适合希望提升越狱攻击效果的研究者使用
基于优化的越狱攻击如贪婪坐标梯度(GCG)通过在白盒源模型上优化对抗后缀,展现出强大的有效性和迁移性。然而,现有GCG方法依赖平均对抗损失和深度贪婪搜索,容易过度关注易突破行为,忽略后缀空间中潜在的高价值区域。本文提出BOSS框架,一种即插即用的改进方案,通过广度导向的后缀搜索提升优化效果。BOSS引入尾部聚焦对抗损失(TFAL)、标准源损失与行为覆盖率,用于筛选终止后缀,并探索多条短轨迹,选择性延续有潜力的路径。在公开基准上的实验表明,BOSS在多个GCG方法上均提升了攻击成功率,同时降低了优化时间。
原文摘要 · Abstract (English)
Optimization-based jailbreak attacks such as Greedy Coordinate Gradient (GCG) achieve strong effectiveness and transferability by optimizing adversarial suffixes on white-box source models. However, existing GCG-based methods rely on averaged adversarial loss and deep greedy search, which can over-emphasize easy-to-jailbreak behaviors and overlook promising regions of the suffix space. We propose BOSS, a plug-and-play framework that improves GCG-based jailbreak optimization through breadth-oriented suffix search. BOSS uses Tail-Focused Adversarial Loss (TFAL), standard source loss, and behavior coverage to select terminal suffixes, then explores multiple short trajectories and selectively continues promising suffixes. Experiments on public benchmarks show that BOSS improves attack success rates across multiple GCG-based methods while reducing optimization time.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。