Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

What is in Your Safe Data? Identifying Benign Data that Breaks Safety

About

Current Large Language Models (LLMs), even those tuned for safety and alignment, are susceptible to jailbreaking. Some have found that just further fine-tuning an aligned model with benign data (i.e., data without harmful content) surprisingly leads to substantial degradation in safety. We delve into the data-centric aspects of why benign fine-tuning inadvertently contributes to jailbreaking. First, we represent fine-tuning data through two lenses: representation and gradient spaces. Additionally, we propose a bi-directional anchoring method that, during the selection process, prioritizes data points that are close to harmful examples and far from benign ones. Our approach effectively identifies subsets of benign data that are more likely to degrade the model's safety after fine-tuning. Training on just 100 of these seemingly benign datapoints surprisingly leads to the fine-tuned model affirmatively responding to >70% of tested harmful requests, compared to <20% after fine-tuning on randomly selected data. We also observe that the selected data frequently appear as lists, bullet points, or math questions, indicating a systematic pattern in fine-tuning data that contributes to jailbreaking.

Luxi He, Mengzhou Xia, Peter Henderson• 2024

Related benchmarks

TaskDatasetResultRank
Safety EvaluationHarmBench
ASR16.5
148
Safety EvaluationHEX-PHI
Attack Success Rate (ASR)6.55
87
Safety EvaluationDirectHarm 4
Attack Success Rate28.5
87
Jailbreak attack success rateHarmBench
Attack Success Rate (Generated)43
52
Attack Success RateDirectHarm4
Attack Success Rate55.5
48
Attack Success RateHEX-PHI
Attack Success Rate0.69
48
Safety EvaluationCategoricalHarmfulQA Alpaca fine-tuning (test)
ASR Delta (S1-S5)-22
42
Safety EvaluationAdvBench Safety Evaluation
ASR (S1)3.85
42
Safety EvaluationCategoricalHarmfulQA Dolly fine-tuning (test)
ASR (S1)3.45
21
Safety EvaluationHEx-PHI Dolly risk-ranked
S1 ASR19.66
21
Showing 10 of 11 rows

Other info

Follow for update