Attackers Can Subliminally Implant a Backdoor at Low Sample Count Without Prompt Access

·LessWrong··

Work done at Redwood Research, quick, non-exhaustive update on results from a larger project. Thanks to @SebastianP for the initial pitch and feedback throughout and to @egan for comments on earlier drafts.TL;DRChanging the teacher for only 100 (0.5% of) completions in fine-tuning can allow attackers to covertly implant a backdoor without control of the dataset prompts. This dataset is robust to simple filtering defenses, even when the defender knows the behavior the attacker is training, and le...

Read full article →

Related Articles

Ten advances in mathematics and theoretical computer science
milkshakes · Hacker News · 8h ago
MiniMax H3 Day-0 Support in ComfyUI: Open Weights, Native Audio, and 2K Video
vblanco · Hacker News · 11h ago
AirLLM 70B inference with single 4GB GPU
Anon84 · Hacker News · 13h ago
Rust project goals: Immobile types and guaranteed destructors
paavohtl · Hacker News · 18h ago
Show HN: Shitty – fast terminal. Memory-unsafe and faster than yours
pshirshov · Hacker News · 1d ago