Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Journal articles
  4. Single-pass Detection of Jailbreaking Input in Large Language Models
 
research article

Single-pass Detection of Jailbreaking Input in Large Language Models

Candogan, Leyla
•
Wu, Yongtao  
•
Abad Rocamora, Elias  
Show more
February 2025
Transactions on Machine Learning Research

Defending aligned Large Language Models (LLMs) against jailbreaking attacks is a challenging problem, with existing approaches requiring multiple requests or even queries to auxiliary LLMs, making them computationally heavy. Instead, we focus on detecting jailbreaking input in a single forward pass. Our method, called Single Pass Detection SPD, leverages the information carried by the logits to predict whether the output sentence will be harmful. This allows us to defend in just one forward pass. SPD can not only detect attacks effectively on open-source models, but also minimizes the misclassification of harmless inputs. Furthermore, we show that SPD remains effective even without complete logit access in GPT-3.5 and GPT-4. We believe that our proposed method offers a promising approach to efficiently safeguard LLMs against adversarial attacks.

  • Files
  • Details
  • Metrics
Loading...
Thumbnail Image
Name

3682_Single_pass_Detection_of_.pdf

Type

Main Document

Version

Accepted version

Access type

openaccess

License Condition

CC BY

Size

1.59 MB

Format

Adobe PDF

Checksum (MD5)

45e567aaa219bd2eeb8b4ab07f709123

Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés