Competition Report: Finding Universal Jailbreak Backdoors in Aligned LLMs
Javier Rando, Francesco Croce, Kry\v{s}tof Mitka, Stepan, Shabalin, Maksym Andriushchenko, Nicolas Flammarion, Florian, Tram\`er

TL;DR
This paper reports on a competition that tested the vulnerability of aligned large language models to universal jailbreak backdoors, revealing significant security risks and suggesting directions for future research.
Contribution
It introduces a competition framework for discovering universal backdoors in aligned LLMs, highlighting vulnerabilities and proposing new research avenues.
Findings
Universal backdoors can be effectively injected into aligned LLMs.
Current alignment methods are susceptible to poisoning attacks.
The competition identified promising techniques for backdoor detection and mitigation.
Abstract
Large language models are aligned to be safe, preventing users from generating harmful content like misinformation or instructions for illegal activities. However, previous work has shown that the alignment process is vulnerable to poisoning attacks. Adversaries can manipulate the safety training data to inject backdoors that act like a universal sudo command: adding the backdoor string to any prompt enables harmful responses from models that, otherwise, behave safely. Our competition, co-located at IEEE SaTML 2024, challenged participants to find universal backdoors in several large language models. This report summarizes the key findings and promising ideas for future research.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
- 🤗ethz-spylab/poisoned_generation_trojan1model· 109 dl· ♡ 4109 dl♡ 4
- 🤗ethz-spylab/reward_modelmodel· 2 dl· ♡ 52 dl♡ 5
- 🤗ethz-spylab/poisoned_generation_trojan3model· 55 dl· ♡ 155 dl♡ 1
- 🤗ethz-spylab/poisoned_generation_trojan4model· 51 dl· ♡ 151 dl♡ 1
- 🤗ethz-spylab/poisoned_generation_trojan5model· 55 dl· ♡ 155 dl♡ 1
- 🤗ethz-spylab/poisoned_generation_trojan2model· 55 dl· ♡ 155 dl♡ 1
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsLaw, AI, and Intellectual Property · Law, Economics, and Judicial Systems
