生成式AI红队百次测试经验(英文版)VIP专享

Lessonsfromredteaming100generativeAIproductsAuthoredby:MicrosoftAIRedTeamAuthorsBlakeBullwinkel,AmandaMinnich,ShivenChawla,GaryLopez,MartinPouliot,WhitneyMaxwell,JorisdeGruyter,KatherinePratt,SaphirQi,NinaChikanov,RomanLutz,RajaSekharRaoDheekonda,Bolor-ErdeneJagdagdorj,EugeniaKim,JustinSong,KeeganHines,DanielJones,GiorgioSeveri,RichardLundeen,SamVaughan,VictoriaWesterhoff,PeteBryan,RamShankarSivaKumar,YonatanZunger,ChangKawaguchi,MarkRussinovich2Lessonsfromredteaming100generativeAIproductsTableofcontents304Abstract07Redteamingoperations09Casestudy#1Jailbreakingavisionlanguagemodeltogeneratehazardouscontent12Lesson4Automationcanhelpcovermoreoftherisklandscape05Introduction08Lesson1Understandwhatthesystemcandoandwhereitisapplied10Lesson3AIredteamingisnotsafetybenchmarking12Lesson5ThehumanelementofAIredteamingiscrucial05AIthreatmodelontology08Lesson2Youdon’thavetocomputegradientstobreakanAIsystem11Casestudy#2AssessinghowanLLMcouldbeusedtoautomatescams13Casestudy#3EvaluatinghowachatbotrespondstoauserindistressLessonsfromredteaming100generativeAIproducts14Casestudy#4Probingatext-to-imagegeneratorforgenderbias14Lesson6ResponsibleAIharmsarepervasivebutdifficulttomeasure15Lesson7LLMsamplifyexistingsecurityrisksandintroducenewones16Casestudy#5SSRFinavideo-processingGenAIapplication17Lesson8TheworkofsecuringAIsystemswillneverbecomplete18ConclusionAbstractInrecentyears,AIredteaminghasemergedasapracticeforprobingthesafetyandsecurityofgenerativeAIsystems.Duetothenascencyofthefield,therearemanyopenquestionsabouthowredteamingoperationsshouldbeconducted.Basedonourexperienceredteamingover100generativeAIproductsatMicrosoft,wepresentourinternalthreatmodelontologyandeightmainlessonswehavelearned:1.Understandwhatthesystemcandoandwhereitisapplied2.Youdon’thavetocomputegradientstobreakanAIsystem3.AIredteamingisnotsafetybenchmarking4.Automationcanhelpcovermoreoftherisklandscape5.ThehumanelementofAIredteamingiscrucial6.ResponsibleAIharmsarepervasivebutdifficulttomeasure7.Largelanguagemodels(LLMs)amplifyexistingsecurityrisksandintroducenewones8.TheworkofsecuringAIsystemswillneverbecompleteBysharingtheseinsightsalongsidecasestudiesfromouroperations,weofferpracticalrecommendationsaimedataligningredteamingeffortswithrealworldrisks.WealsohighlightaspectsofAIredteamingthatwebelieveareoftenmisunderstoodanddiscussopenquestionsforthefieldtoconsider.4Lessonsfromredteaming100generativeAIproducts5IntroductionAsgenerativeAI(GenAI)systemsareadoptedacrossanincreasingnumberofdomains,AIredteaminghasemergedasacentralpracticeforassessingthesafetyandsecurityofthesetechnologies.Atitscore,AIredteamingstrivestopushbeyondmodel-levelsafetybenchmarksbyemulatingreal-worldattacksagainstend-to-endsystems.However,therearemanyopenquestionsabouthowredteamingoperationsshouldbeconductedandahealthydoseofskepticismabouttheefficacyofcurrentAIredteamingefforts[4,8,32].Inthispaper,wespeaktosomeoftheseconcernsbyprovidinginsightintoourexperienceredteamingover100GenAIproductsatMicrosoft.Thepaperisorganizedasfollows:First,wepresentthethreatmodelontologythatweusetoguideouroperations.Second,weshareeightmainlessonswehavelearnedandmakepracticalrecommendationsforAIredteams,alongwithcasestudiesfromouroperations.Inparticular,thesecasestudieshighlighthowourontologyisusedtomodelabroadrangeofsafetyandsecurityrisks.Finally,weclosewithadiscussion...

1、当您付费下载文档后,您只拥有了使用权限,并不意味着购买了版权,文档只能用于自身使用,不得用于其他商业用途(如 [转卖]进行直接盈利或[编辑后售卖]进行间接盈利)。
2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。
3、如文档内容存在违规,或者侵犯商业秘密、侵犯著作权等,请点击“违规举报”。

碎片内容

碳中和
已认证
内容提供者

碳中和

确认删除?
回到顶部
微信客服
  • 管理员微信
QQ客服
  • QQ客服点击这里给我发消息
客服邮箱