{"id":6216,"date":"2025-02-10T04:23:00","date_gmt":"2025-02-09T19:23:00","guid":{"rendered":"https:\/\/devneko.jp\/wordpress\/?p=6216"},"modified":"2025-02-10T04:23:00","modified_gmt":"2025-02-09T19:23:00","slug":"overthinking-slowdown-attacks-on-reasoning-llms","status":"publish","type":"post","link":"https:\/\/devneko.jp\/wordpress\/?p=6216","title":{"rendered":"OVERTHINKING: Slowdown Attacks on Reasoning LLMs\u00a0"},"content":{"rendered":"\n<ul class=\"wp-block-list\">\n<li><strong>OVERTHINKING: Slowdown Attacks on Reasoning LLMs&nbsp;<\/strong>[41.7]<br>OVERTHINK\u653b\u6483\u306f\u3001\u63a8\u8ad6\u30e2\u30c7\u30eb\u3092\u64cd\u4f5c\u3059\u308b\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30b3\u30b9\u30c8\u3092\u5897\u5e45\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002 \u6211\u3005\u306f\u3001\u30af\u30ed\u30fc\u30ba\u30c9(OpenAI o1, o1-mini, o3-mini)\u3068\u30aa\u30fc\u30d7\u30f3(DeepSeek R1)\u306e\u91cd\u307f\u4ed8\u3051\u30e2\u30c7\u30eb\u3092\u7528\u3044\u3066\u3001FreshQA\u304a\u3088\u3073SQuAD\u30c7\u30fc\u30bf\u30bb\u30c3\u30c8\u306b\u3088\u308b\u653b\u6483\u3092\u8a55\u4fa1\u3057\u305f\u3002<br><a href=\"http:\/\/arxiv.org\/abs\/2502.02542v1\">\u8ad6\u6587<\/a>&nbsp;&nbsp;<a href=\"https:\/\/fugumt.com\/fugumt\/paper_check\/2502.02542v1\">\u53c2\u8003\u8a33\uff08\u30e1\u30bf\u30c7\u30fc\u30bf\uff09<\/a>&nbsp; &nbsp;(Tue, 04 Feb 2025 18:12:41 GMT)<\/li>\n\n\n\n<li>\u63a8\u8ad6\u52b9\u7387\u3092\u4f4e\u4e0b\u3055\u305b\u308boverthinking\u653b\u6483\u3001\u300cOur experimental results show that OVERTHINK significantly disrupts reasoning efficiency, with attacks on the o1 model increasing reasoning tokens up to 18\u00d7 and over 10\u00d7 on DeepSeek-R1.\u300d\u3068\u306e\u3053\u3068\u3002<\/li>\n\n\n\n<li>\u300cOur attack contains three key stages: (1) picking a decoy problem that results in a large number of reasoning tokens, but won\u2019t trigger safety filters; (2) integrating selected decoys into a compromised source (e g , a wiki page) by either modifying the problem to fit the context (context-aware) or by injecting a general template (context-agnostic), and, (3) optimizing the decoy tasks using an in-context learning genetic (ICL-Genetic) algorithm to select contexts with decoys that provide highest reasoning tokens and maintain stealthiness of the answers to the user.\u300d\u3068\u3044\u3046\u30a2\u30d7\u30ed\u30fc\u30c1\u3002\u8a08\u7b97\u8ca0\u8377\u306e\u9ad8\u3044\u6b63\u898f\u8868\u73fe\u3092\u4f7f\u3046DoS\u3063\u307d\u3044\u3068\u601d\u3063\u3066\u3057\u307e\u3044\u3001\u6709\u52b9\u306a\u653b\u6483\u306b\u306a\u308a\u3048\u305d\u3046\u3002\u3002\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u300cIn rare cases, R1 can get stuck \u201cthinking forever\u201d.\u300d\u3068\u8a18\u8f09\u304c\u3042\u308b\u8ad6\u6587\u3092\u601d\u3044\u51fa\u3057\u305f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PhD Knowledge Not Required: A Reasoning Challenge for Large Language Models\u00a0<\/strong>[43.2]<br>\u4e00\u822c\u77e5\u8b58\u306e\u307f\u3092\u5fc5\u8981\u3068\u3059\u308bNPR\u30b5\u30f3\u30c7\u30fc\u30d1\u30ba\u30eb\u30c1\u30e3\u30ec\u30f3\u30b8\u306b\u57fa\u3065\u304f\u30d9\u30f3\u30c1\u30de\u30fc\u30af\u3092\u63d0\u6848\u3059\u308b\u3002 \u79c1\u305f\u3061\u306e\u7814\u7a76\u306f\u3001\u65e2\u5b58\u306e\u30d9\u30f3\u30c1\u30de\u30fc\u30af\u3067\u306f\u660e\u3089\u304b\u3067\u306a\u3044\u6a5f\u80fd\u30ae\u30e3\u30c3\u30d7\u3092\u660e\u3089\u304b\u306b\u3057\u3066\u3044\u307e\u3059\u3002<br><a href=\"http:\/\/arxiv.org\/abs\/2502.01584v1\">\u8ad6\u6587<\/a>\u00a0\u00a0<a href=\"https:\/\/fugumt.com\/fugumt\/paper_check\/2502.01584v1\">\u53c2\u8003\u8a33\uff08\u30e1\u30bf\u30c7\u30fc\u30bf\uff09<\/a>\u00a0 \u00a0(Mon, 03 Feb 2025 18:10:38 GMT)<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u300cIn rare cases, R1 can get stuck \u201cthinking forever\u201d.\u300d\u3068\u8a18\u8f09\u304c\u3042\u308b\u8ad6\u6587\u3092\u601d\u3044\u51fa\u3057\u305f\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[32,298],"class_list":["post-6216","post","type-post","status-publish","format-standard","hentry","category-arxiv","tag-attack","tag-overthinking"],"_links":{"self":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/6216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6216"}],"version-history":[{"count":0,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/6216\/revisions"}],"wp:attachment":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}