REVIEW 2 cited by
A LLM Assisted Exploitation of AI-Guardian
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Large language models (LLMs) are now highly capable at a diverse range of tasks. This paper studies whether or not GPT-4, one such LLM, is capable of assisting researchers in the field of adversarial machine learning. As a case study, we evaluate the robustness of AI-Guardian, a recent defense to adversarial examples published at IEEE S&P 2023, a top computer security conference. We completely break this defense: the proposed scheme does not increase robustness compared to an undefended baseline. We write none of the code to attack this model, and instead prompt GPT-4 to implement all attack algorithms following our instructions and guidance. This process was surprisingly effective and efficient, with the language model at times producing code from ambiguous instructions faster than the author of this paper could have done. We conclude by discussing (1) the warning signs present in the evaluation that suggested to us AI-Guardian would be broken, and (2) our experience with designing attacks and performing novel research using the most recent advances in language modeling.
Forward citations
Cited by 2 Pith papers
-
Evaluating the efficacy of LLM Safety Solutions : The Palit Benchmark Dataset
An evaluation of seven LLM security tools on a new 500-prompt benchmark finds the ChatGPT-3.5-Turbo baseline unusable due to false positives and names Lakera Guard and ProtectAI LLM Guard the best overall tools.
-
RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis
Activation patterns of the final input token across LLM layers separate poisoned from correct RAG responses with high in-distribution accuracy.
Discussion (0). Continue with ORCID to comment.