REVIEW 5 cited by
RigorLLM: Resilient Guardrails for Large Language Models against Undesired Content
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Recent advancements in Large Language Models (LLMs) have showcased remarkable capabilities across various tasks in different domains. However, the emergence of biases and the potential for generating harmful content in LLMs, particularly under malicious inputs, pose significant challenges. Current mitigation strategies, while effective, are not resilient under adversarial attacks. This paper introduces Resilient Guardrails for Large Language Models (RigorLLM), a novel framework designed to efficiently and effectively moderate harmful and unsafe inputs and outputs for LLMs. By employing a multi-faceted approach that includes energy-based training data augmentation through Langevin dynamics, optimizing a safe suffix for inputs via minimax optimization, and integrating a fusion-based model combining robust KNN with LLMs based on our data augmentation, RigorLLM offers a robust solution to harmful content moderation. Our experimental evaluations demonstrate that RigorLLM not only outperforms existing baselines like OpenAI API and Perspective API in detecting harmful content but also exhibits unparalleled resilience to jailbreaking attacks. The innovative use of constrained optimization and a fusion-based guardrail approach represents a significant step forward in developing more secure and reliable LLMs, setting a new standard for content moderation frameworks in the face of evolving digital threats.
Forward citations
Cited by 5 Pith papers
-
JailbreaksOverTime: Detecting Jailbreak Attacks Under Distribution Shift
Jailbreak detection models drift over time, and a weekly self-trained detector plus an unsupervised behavioral monitor can keep false negatives near 0.3 to 0.4 percent at a 0.1 to 1 percent false positive rate.
-
Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain
Misleading health documents in RAG context sharply lower LLM accuracy, and heavily helpful-biased retrieval pools restore it.
-
Smoothed Embeddings for Robust Language Models
RESTA defends LLMs against jailbreak attacks by adding random noise to user-prompt embeddings and aggregating token votes for the first 20 generated tokens.
-
Buster: Implanting Semantic Backdoor into Text Encoder to Mitigate NSFW Content Generation
Buster implants a semantic backdoor in the text encoder of text-to-image models, redirecting NSFW prompts to a benign target prompt while preserving benign generations.
-
Llama Guard 3 Vision: Safeguarding Human-AI Image Understanding Conversations
Llama Guard 3 Vision flags harmful multimodal prompts and responses across 13 hazard categories, reporting an F1 of 0.938 for response classification on an internal test set.
Discussion (0). Continue with ORCID to comment.