AI RESEARCH

FlipAttack: Jailbreak LLMs via Flipping

arXiv CS.AI

ArXi:2410.02832v2 Announce Type: replace-cross This paper proposes a simple yet effective jailbreak attack named FlipAttack against black-box LLMs. First, from the autoregressive nature, we reveal that LLMs tend to understand the text from left to right and find that they struggle to comprehend the text when noise is added to the left side. Motivated by these insights, we propose to disguise the harmful prompt by constructing left-side noise merely based on the prompt itself, then generalize this idea to 4 flipping modes.