English

Competition Report: Finding Universal Jailbreak Backdoors in Aligned LLMs

Computation and Language 2024-06-07 v2 Artificial Intelligence Cryptography and Security Machine Learning

Abstract

Large language models are aligned to be safe, preventing users from generating harmful content like misinformation or instructions for illegal activities. However, previous work has shown that the alignment process is vulnerable to poisoning attacks. Adversaries can manipulate the safety training data to inject backdoors that act like a universal sudo command: adding the backdoor string to any prompt enables harmful responses from models that, otherwise, behave safely. Our competition, co-located at IEEE SaTML 2024, challenged participants to find universal backdoors in several large language models. This report summarizes the key findings and promising ideas for future research.

Keywords

Cite

@article{arxiv.2404.14461,
  title  = {Competition Report: Finding Universal Jailbreak Backdoors in Aligned LLMs},
  author = {Javier Rando and Francesco Croce and Kryštof Mitka and Stepan Shabalin and Maksym Andriushchenko and Nicolas Flammarion and Florian Tramèr},
  journal= {arXiv preprint arXiv:2404.14461},
  year   = {2024}
}

Comments

Competition Report

R2 v1 2026-06-28T16:02:43.754Z