English

BadGPT-4o: stripping safety finetuning from GPT models

Cryptography and Security 2024-12-10 v1 Machine Learning

Abstract

We show a version of Qi et al. 2023's simple fine-tuning poisoning technique strips GPT-4o's safety guardrails without degrading the model. The BadGPT attack matches best white-box jailbreaks on HarmBench and StrongREJECT. It suffers no token overhead or performance hits common to jailbreaks, as evaluated on tinyMMLU and open-ended generations. Despite having been known for a year, this attack remains easy to execute.

Keywords

Cite

@article{arxiv.2412.05346,
  title  = {BadGPT-4o: stripping safety finetuning from GPT models},
  author = {Ekaterina Krupkina and Dmitrii Volkov},
  journal= {arXiv preprint arXiv:2412.05346},
  year   = {2024}
}