paper-with-me

홈 › Papers

Denial-of-Service Poisoning Attacks against Large Language Models

2024-10-14 · Kuofeng Gao, Tianyu Pang, Chao Du, Yong Yang, Shu-Tao Xia, Min Lin

Recent studies have shown that LLMs are vulnerable to denial-of-service (DoS) attacks, where adversarial inputs like spelling errors or non-semantic prompts trigger endless outputs without generating an [EOS] token. These attacks can potentially cause high latency and make LLM services inaccessible to other users or tasks. However, when there are speech-to-text interfaces (e.g., voice commands to a robot), executing such DoS attacks becomes challenging, as it is difficult to introduce spelling errors or non-semantic prompts through speech. A simple DoS attack in these scenarios would be to instruct the model to "Keep repeating Hello", but we observe that relying solely on natural instructions limits output length, which is bounded by the maximum length of the LLM's supervised finetuning (SFT) data. To overcome this limitation, we propose poisoning-based DoS (P-DoS) attacks for LLMs, demonstrating that injecting a single poisoned sample designed for DoS purposes can break the output length limit. For example, a poisoned sample can successfully attack GPT-4o and GPT-4o mini (via OpenAI's finetuning API) using less than $1, causing repeated outputs up to the maximum inference length (16K tokens, compared to 0.5K before poisoning). Additionally, we perform comprehensive ablation studies on open-source LLMs and extend our method to LLM agents, where attackers can control both the finetuning dataset and algorithm. Our findings underscore the urgent need for defenses against P-DoS attacks to secure LLMs. Our code is available at https://github.com/sail-sg/P-DoS.

📄 PDF Abstract BibTeX arXiv:2410.10760

Code (1)

sail-sg/p-dos 공식 구현 pytorch

Tasks

16kSpeech-to-Text

Similar Papers 제목 키워드 기반

Defending Against Adversarial Denial-of-Service Data Poisoning Attacks

2021-04-14 · Nicolas M. Müller, Simon Roschmann, Konstantin Böttinger

Data poisoning is one of the most relevant security threats against machine learning and data-driven technologies. Since many applications rely on untrusted training data, an attacker can easily craft malicious samples a…

Anomaly DetectionBIG-bench Machine LearningClusteringData Poisoning

Persistent Pre-Training Poisoning of LLMs

2024-10-17 · Yiming Zhang, Javier Rando, Ivan Evtimov, Jianfeng Chi 외

Large language models are pre-trained on uncurated text datasets consisting of trillions of tokens scraped from the Web. Prior work has shown that: (1) web-scraped pre-training datasets can be practically poisoned by mal…

Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated Learning

2023-04-21 · Hangtao Zhang, Zeming Yao, Leo Yu Zhang, Shengshan Hu 외

Federated learning (FL) is vulnerable to poisoning attacks, where adversaries corrupt the global aggregation results and cause denial-of-service (DoS). Unlike recent model poisoning attacks that optimize the amplitude of…

Federated LearningModel Poisoning

Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning

2026-01-21 · Zhihao Chen, Zirui Gong, Jianting Ning, Yanjun Zhang 외 arxiv

Federated Rank Learning (FRL) is a promising Federated Learning (FL) paradigm designed to be resilient against model poisoning attacks due to its discrete, ranking-based update mechanism. Unlike traditional FL methods th…

Federated Learning

CoAP-DoS: An IoT Network Intrusion Dataset

2022-06-29 · Jared Mathews, Prosenjit Chatterjee, Shankar Banik

The need for secure Internet of Things (IoT) devices is growing as IoT devices are becoming more integrated into vital networks. Many systems rely on these devices to remain available and provide reliable service. Denial…

BIG-bench Machine LearningIntrusion DetectionNetwork Intrusion Detection