{"id":3784,"date":"2023-09-15T05:37:00","date_gmt":"2023-09-14T20:37:00","guid":{"rendered":"https:\/\/devneko.jp\/wordpress\/?p=3784"},"modified":"2023-09-15T05:37:00","modified_gmt":"2023-09-14T20:37:00","slug":"baseline-defenses-for-adversarial-attacks-against-aligned-language-models","status":"publish","type":"post","link":"https:\/\/devneko.jp\/wordpress\/?p=3784","title":{"rendered":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models"},"content":{"rendered":"\n<ul class=\"wp-block-list\">\n<li><strong>Baseline Defenses for Adversarial Attacks Against Aligned Language Models&nbsp;<\/strong>[109.8]<br>\u6211\u3005\u306f,\u5927\u898f\u6a21\u8a00\u8a9e\u30e2\u30c7\u30eb\u306b\u5bfe\u3059\u308b\u4e3b\u8981\u306a\u6575\u653b\u6483\u306b\u5bfe\u3059\u308b\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u9632\u885b\u6226\u7565\u3092\u8a55\u4fa1\u3057\u305f\u3002 \u691c\u51fa(\u8907\u96d1\u5ea6\u306b\u57fa\u3065\u304f)\u3001\u5165\u529b\u524d\u51e6\u7406(\u8a00\u3044\u63db\u3048\u3068\u518d\u5e30\u5316)\u3001\u5bfe\u4eba\u8a13\u7df4\u306e3\u7a2e\u985e\u306e\u9632\u885b\u306b\u3064\u3044\u3066\u691c\u8a0e\u3059\u308b\u3002 \u9a5a\u304f\u3079\u304d\u3053\u3068\u306b\u3001\u4ed6\u306e\u30c9\u30e1\u30a4\u30f3\u3067\u4e88\u60f3\u3055\u308c\u308b\u3088\u308a\u3082\u3001\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3084\u524d\u51e6\u7406\u3067\u6210\u529f\u3057\u3066\u3044\u307e\u3059\u3002<br><a href=\"http:\/\/arxiv.org\/abs\/2309.00614v1\">\u8ad6\u6587<\/a>&nbsp;&nbsp;<a href=\"https:\/\/fugumt.com\/fugumt\/paper_check\/2309.00614v1\">\u53c2\u8003\u8a33\uff08\u30e1\u30bf\u30c7\u30fc\u30bf\uff09<\/a>&nbsp; &nbsp;(Fri, 1 Sep 2023 17:59:44 GMT)<\/li>\n\n\n\n<li>LLM\u3078\u306e\u653b\u6483\u306b\u5bfe\u3059\u308b\u5bfe\u5fdc\u306b\u95a2\u3059\u308b\u7814\u7a76\u3001detection (perplexity based), input preprocessing (paraphrase and retokenization), adversarial training\u304c\u5bfe\u8c61<\/li>\n\n\n\n<li>\u300cInterestingly, in this initial analysis, we find much more success with filtering and preprocessing strategies than in the vision domain, and that adaptive attacks against such defenses are non-trivial.\u300d\u300cThe domain of LLMs is appreciably different from \u201cclassical\u201d problems in adversarial machine learning.\u300d\u3068\u3044\u3046\u8a18\u8f09\u304c\u5370\u8c61\u7684\u3002<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[32,108,223],"class_list":["post-3784","post","type-post","status-publish","format-standard","hentry","category-arxiv","tag-attack","tag-defense","tag-llm"],"_links":{"self":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/3784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3784"}],"version-history":[{"count":0,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/3784\/revisions"}],"wp:attachment":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}