跳到正文
arXiv cs.AI· Seyedarmin Azizi, Erfan Baghaei Potraghloo, Massoud Pedram·· 3 小时前AI 评分46

一个词就能开门:针对作为智能体护栏的类型化决策模型的选项通道攻击

One Word Opens the Gate: The Option-Channel Attack on Typed Decision Models as Agent Guardrails

AI 导读

研究评估七款开放权重模型作为智能体护栏的表现,在提示注入、越狱和有害内容筛查中,允许或阻止决策的准确率仅为 36% 至 72%,而随机水平为 50%。在合成智能体工具调用测试中,六行与策略无关的服务器日志文本可将某护栏的 fail-open 率从 0% 提升至 63%;若给宽松选项起一个误导性名称,四款将标签纳入输入的模型 fail-open 率升至 93% 至 100%。

来源:arXiv cs.AI · arxiv.org