{"id":"https://openalex.org/W4399837713","doi":"https://doi.org/10.48550/arxiv.2406.12670","title":"Stealth edits for provably fixing or attacking large language models","display_name":"Stealth edits for provably fixing or attacking large language models","publication_year":2024,"publication_date":"2024-06-18","ids":{"openalex":"https://openalex.org/W4399837713","doi":"https://doi.org/10.48550/arxiv.2406.12670"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2406.12670","pdf_url":"http://arxiv.org/pdf/2406.12670","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://arxiv.org/pdf/2406.12670","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5006868406","display_name":"Oliver J. Sutton","orcid":"https://orcid.org/0000-0003-0184-4371"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sutton, Oliver J.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024753869","display_name":"Qinghua Zhou","orcid":"https://orcid.org/0000-0002-3327-0440"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Qinghua","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048093151","display_name":"Wang Wei","orcid":"https://orcid.org/0000-0002-9818-3276"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Wei","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058486589","display_name":"Desmond J. Higham","orcid":"https://orcid.org/0000-0002-6635-3461"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Higham, Desmond J.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058069510","display_name":"Alexander N. Gorban","orcid":"https://orcid.org/0000-0001-6224-1430"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gorban, Alexander N.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088165793","display_name":"Alexander Bastounis","orcid":"https://orcid.org/0000-0002-2867-4635"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bastounis, Alexander","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5052143104","display_name":"Ivan Tyukin","orcid":"https://orcid.org/0000-0002-7359-7966"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tyukin, Ivan Y.","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":83},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9644,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9644,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9643,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5719812},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3377441},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.32315105},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.12861806}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2406.12670","pdf_url":"http://arxiv.org/pdf/2406.12670","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2406.12670","pdf_url":"http://arxiv.org/pdf/2406.12670","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4396701345","https://openalex.org/W4396696052","https://openalex.org/W4395014643","https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2382290278","https://openalex.org/W2376932109","https://openalex.org/W2358668433","https://openalex.org/W2001405890"],"abstract_inverted_index":{"We":[0,15,80],"reveal":[1],"new":[2,20,72,135],"methods":[3],"and":[4,31,70,95,157,239,243,248],"the":[5,19,27,53,57,64,103,113,122,170,206,241],"theoretical":[6,42,127,245],"foundations":[7],"of":[8,29,52,56,66,77,172,205],"techniques":[9],"for":[10,147,251],"editing":[11,68,78,88,252],"large":[12],"language":[13,174,253],"models.":[14,221],"also":[16,168],"show":[17],"how":[18],"theory":[21],"can":[22,158],"be":[23,159,228],"used":[24],"to":[25,32,36,62,83,93,101,106,132,176,183,191,202,218,227],"assess":[26],"editability":[28],"models":[30,254],"expose":[33],"their":[34],"susceptibility":[35],"previously":[37,215],"unknown":[38],"malicious":[39],"attacks.":[40],"Our":[41],"approach":[43],"shows":[44],"that":[45],"a":[46,98,134,140,173,177,180,184,192,212],"single":[47,193],"metric":[48,167],"(a":[49],"specific":[50],"measure":[51],"intrinsic":[54,165],"dimensionality":[55,166],"model's":[58,99,104,114,185,207],"features)":[59],"is":[60,145],"fundamental":[61],"predicting":[63],"success":[65],"popular":[67],"approaches,":[69],"reveals":[71],"bridges":[73],"between":[74],"disparate":[75],"families":[76],"methods.":[79],"collectively":[81],"refer":[82],"these":[84],"approaches":[85],"as":[86],"stealth":[87,178],"methods,":[89],"because":[90],"they":[91],"aim":[92],"directly":[94],"inexpensively":[96],"update":[97],"weights":[100,186],"correct":[102],"responses":[105],"known":[107],"hallucinating":[108],"prompts":[109],"without":[110,116],"otherwise":[111],"affecting":[112],"behaviour,":[115],"requiring":[117],"retraining.":[118],"By":[119],"carefully":[120],"applying":[121],"insight":[123],"gleaned":[124],"from":[125],"our":[126],"investigation,":[128],"we":[129],"are":[130,223,255],"able":[131],"introduce":[133],"network":[136,155],"block":[137,142],"--":[138,143],"named":[139],"jet-pack":[141],"which":[144,187],"optimised":[146],"highly":[148],"selective":[149],"model":[150,175],"editing,":[151],"uses":[152],"only":[153],"standard":[154],"operations,":[156],"inserted":[160],"into":[161],"existing":[162],"networks.":[163],"The":[164],"determines":[169],"vulnerability":[171],"attack:":[179],"small":[181],"change":[182],"changes":[188],"its":[189,244],"response":[190],"attacker-chosen":[194],"prompt.":[195],"Stealth":[196],"attacks":[197],"do":[198],"not":[199],"require":[200],"access":[201],"or":[203],"knowledge":[204],"training":[208],"data,":[209],"therefore":[210],"representing":[211],"potent":[213],"yet":[214],"unrecognised":[216],"threat":[217],"redistributed":[219],"foundation":[220],"They":[222],"computationally":[224],"simple":[225],"enough":[226],"implemented":[229],"in":[230,232],"malware":[231],"many":[233],"cases.":[234],"Extensive":[235],"experimental":[236],"results":[237],"illustrate":[238],"support":[240],"method":[242],"underpinnings.":[246],"Demos":[247],"source":[249],"code":[250],"available":[256],"at":[257],"https://github.com/qinghua-zhou/stealth-edits.":[258]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4399837713","counts_by_year":[],"updated_date":"2025-01-17T05:04:50.648541","created_date":"2024-06-20"}