paper-with-me

홈 › Papers

Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking

2025-04-08 · Yu-Hang Wu, Yu-jie Xiong, Hao Zhang, Jia-Chen Zhang, Zheng Zhou

With the increasingly deep integration of large language models (LLMs) across diverse domains, the effectiveness of their safety mechanisms is encountering severe challenges. Currently, jailbreak attacks based on prompt engineering have become a major safety threat. However, existing methods primarily rely on black-box manipulation of prompt templates, resulting in poor interpretability and limited generalization. To break through the bottleneck, this study first introduces the concept of Defense Threshold Decay (DTD), revealing the potential safety impact caused by LLMs' benign generation: as benign content generation in LLMs increases, the model's focus on input instructions progressively diminishes. Building on this insight, we propose the Sugar-Coated Poison (SCP) attack paradigm, which uses a "semantic reversal" strategy to craft benign inputs that are opposite in meaning to malicious intent. This strategy induces the models to generate extensive benign content, thereby enabling adversarial reasoning to bypass safety mechanisms. Experiments show that SCP outperforms existing baselines. Remarkably, it achieves an average attack success rate of 87.23% across six LLMs. For defense, we propose Part-of-Speech Defense (POSD), leveraging verb-noun dependencies for syntactic analysis to enhance safety of LLMs while preserving their generalization ability.

📄 PDF Abstract BibTeX arXiv:2504.05652

Code (1)

wuyuhang11/chemotherapy 공식 구현

Tasks

Prompt Engineering

Methods 이 논문이 사용한 방법론

Focus 설명 없음

Similar Papers 제목 키워드 기반

CamoDocs: A Poisoning Attack Against Retrieval-Augmented Language Models Using Camouflaged Documents

2026-08-28 · Jaewon Jung, Haizhong Zheng, Hongsun Jang, Jaeyong Song 외 arxiv

Retrieval-augmented generation (RAG) augments LLMs with external documents, but public or user-editable sources expose RAG systems to data poisoning: attackers can inject malicious documents to steer outputs toward targe…

Object-oriented backdoor attack against image captioning

2024-01-05 · Meiling Li, Nan Zhong, Xinpeng Zhang, Zhenxing Qian 외

Backdoor attack against image classification task has been widely studied and proven to be successful, while there exist little research on the backdoor attack against vision-language models. In this paper, we explore ba…

Backdoor AttackImage Captioningimage-classificationImage Classification+1

When Context Bites: Detecting RAG Poisoning via Document-Level Attention Collapse

2026-08-07 · Yingtao Ren, Ziyi Zhao, Yiwei Fu, Xiao Luo 외 hf

Retrieval-augmented generation (RAG) is indispensable for enhancing large language models. However, RAGs are increasingly susceptible to poisoning attacks, in which adversarial documents are injected to manipulate genera…

SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning

2026-05-27 · Jiachen Qian arxiv

Retrieval-Augmented Generation (RAG) mitigates LLM hallucinations but introduces a critical vulnerability: corpus integrity. We present SilentRetrieval, a two-stage data poisoning attack that hijacks RAG systems through …

Natural Questions

DeepPoison: Feature Transfer Based Stealthy Poisoning Attack

2021-01-06 · Jinyin Chen, Longyuan Zhang, Haibin Zheng, Xueke Wang 외

Deep neural networks are susceptible to poisoning attacks by purposely polluted training data with specific triggers. As existing episodes mainly focused on attack success rate with patch-based samples, defense algorithm…