PulseAugur
中
实时 13:24:20
English(EN) The Model Plants the Trigger: Answer-Side Backdoor Attacks in Multi-Turn Large Language Models

新型回答侧后门攻击绕过大语言模型安全协议

研究人员开发了一种针对大语言模型(LLM)的新型后门攻击,该攻击作用于回答侧而非输入侧。这种新颖的方法涉及一个良性的初始提示,导致LLM生成一个特定词语,该词语随后嵌入对话历史中作为触发器。当后续出现有害查询时,模型会识别出自身生成的触发器并绕过安全协议,即使用户的输入是干净的。这种回答侧后门攻击在低中毒率下实现了对多个LLM近乎完美的攻击成功率,规避了当前以输入为中心的防御措施,并凸显了LLM安全对齐方面的一个重大漏洞。 AI

影响 凸显了当前LLM安全对齐方面的一个关键盲点,可能需要新的防御策略。

排序理由 详细介绍针对LLM的新型攻击向量的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.LG 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新型回答侧后门攻击绕过大语言模型安全协议

本文如何被排名

Signal score
7 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
详细介绍针对LLM的新型攻击向量的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, paper
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Same-day
Cluster formed today. Ranking reflects the current source set at time of score.

完整方法见我们的编辑标准。

报道来源 [1]

  1. arXiv cs.LG TIER_1 English(EN) · Yibo Zhang, Tianrong Guan, Liang Lin, Puze Wang, Jin Wang, Qingsong Wen ·

    模型植入触发器:多轮大型语言模型的答案侧后门攻击

    arXiv:2610.07723v1 Announce Type: cross Abstract: Safety alignment in Large Language Models (LLMs) remains vulnerable to backdoor attacks. Existing LLM backdoors are almost all input-centric: activation depends on explicit trigger patterns in the user input, so modern guardrails …