广度优于深度:基于广度导向后缀搜索改进基于GCG的越狱优化
Breadth Beats Depth: Improving GCG-Based Jailbreak Optimization with Breadth-Oriented Suffix Search
- School of Information Science and Technology(信息科学与技术学院)
- Guangdong University of Foreign Studies(广东外语外贸大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
该研究针对GCG越狱优化易忽视后缀空间具前景区域的问题,提出即插即用框架BOSS,采用广度导向后缀搜索,提升攻击成功率并缩短优化时间。
AI中文摘要:
基于优化的越狱攻击如贪心坐标梯度(GCG)通过在白盒源模型上优化对抗后缀,实现了强有效性与可迁移性。然而,现有基于GCG的方法依赖平均对抗损失与深度贪心搜索,可能过度强调易越狱行为,忽视后缀空间中具前景的区域。我们提出BOSS,即一种即插即用框架,通过广度导向后缀搜索改进基于GCG的越狱优化。BOSS采用聚焦尾部的对抗损失(TFAL)、标准源损失与行为覆盖度选择终端后缀,随后探索多条短轨迹并选择性延续具前景的后缀。在公开基准上的实验表明,BOSS提升了多种基于GCG方法的攻击成功率,同时减少了优化时间。
英文摘要:
Optimization-based jailbreak attacks such as Greedy Coordinate Gradient (GCG) achieve strong effectiveness and transferability by optimizing adversarial suffixes on white-box source models. However, existing GCG-based methods rely on averaged adversarial loss and deep greedy search, which can over-emphasize easy-to-jailbreak behaviors and overlook promising regions of the suffix space. We propose BOSS, a plug-and-play framework that improves GCG-based jailbreak optimization through breadth-oriented suffix search. BOSS uses Tail-Focused Adversarial Loss (TFAL), standard source loss, and behavior coverage to select terminal suffixes, then explores multiple short trajectories and selectively continues promising suffixes. Experiments on public benchmarks show that BOSS improves attack success rates across multiple GCG-based methods while reducing optimization time.