Multi-step Jailbreaking Privacy Attacks on ChatGPT
Haoran Li, Dadi Guo, Wei Fan, Mingshi Xu, Jie Huang, Fanpu Meng,, Yangqiu Song

TL;DR
This paper investigates privacy risks associated with ChatGPT and similar LLMs, demonstrating how multi-step jailbreaking techniques can potentially extract private information and pose new privacy threats in AI-generated content.
Contribution
It introduces novel multi-step jailbreaking methods to reveal privacy vulnerabilities in ChatGPT and related applications, highlighting new privacy concerns in LLM deployment.
Findings
Multi-step jailbreaking can extract private data from ChatGPT.
Application-integrated LLMs pose significant privacy threats.
Extensive experiments support the privacy risk claims.
Abstract
With the rapid progress of large language models (LLMs), many downstream NLP tasks can be well solved given appropriate prompts. Though model developers and researchers work hard on dialog safety to avoid generating harmful content from LLMs, it is still challenging to steer AI-generated content (AIGC) for the human good. As powerful LLMs are devouring existing text data from various domains (e.g., GPT-3 is trained on 45TB texts), it is natural to doubt whether the private information is included in the training data and what privacy threats can these LLMs and their downstream applications bring. In this paper, we study the privacy threats from OpenAI's ChatGPT and the New Bing enhanced by ChatGPT and show that application-integrated LLMs may cause new privacy threats. To this end, we conduct extensive experiments to support our claims and discuss LLMs' privacy implications.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Artificial Intelligence in Healthcare and Education · Topic Modeling
Methods{Dispute@FaQ-s}How to file a dispute with Expedia? · Attention Is All You Need · Linear Layer · Residual Connection · Cosine Annealing · Linear Warmup With Cosine Annealing · Dense Connections · Attention Dropout · 15 Ways to Contact How can i speak to someone at Delta Airlines · Weight Decay
