Goto

Collaborating Authors

 Large Language Model


Divide and Conquer: A Hybrid Strategy Defeats Multimodal Large Language Models

arXiv.org Artificial Intelligence

Large language models (LLMs) are widely applied in various fields of society due to their powerful reasoning, understanding, and generation capabilities. However, the security issues associated with these models are becoming increasingly severe. Jailbreaking attacks, as an important method for detecting vulnerabilities in LLMs, have been explored by researchers who attempt to induce these models to generate harmful content through various attack methods. Nevertheless, existing jailbreaking methods face numerous limitations, such as excessive query counts, limited coverage of jailbreak modalities, low attack success rates, and simplistic evaluation methods. To overcome these constraints, this paper proposes a multimodal jailbreaking method: JMLLM. This method integrates multiple strategies to perform comprehensive jailbreak attacks across text, visual, and auditory modalities. Additionally, we contribute a new and comprehensive dataset for multimodal jailbreaking research: TriJail, which includes jailbreak prompts for all three modalities. Experiments on the TriJail dataset and the benchmark dataset AdvBench, conducted on 13 popular LLMs, demonstrate advanced attack success rates and significant reduction in time overhead.


Attention Entropy is a Key Factor: An Analysis of Parallel Context Encoding with Full-attention-based Pre-trained Language Models

arXiv.org Artificial Intelligence

Large language models have shown remarkable performance across a wide range of language tasks, owing to their exceptional capabilities in context modeling. The most commonly used method of context modeling is full self-attention, as seen in standard decoder-only Transformers. Although powerful, this method can be inefficient for long sequences and may overlook inherent input structures. To address these problems, an alternative approach is parallel context encoding, which splits the context into sub-pieces and encodes them parallelly. Because parallel patterns are not encountered during training, naively applying parallel encoding leads to performance degradation. However, the underlying reasons and potential mitigations are unclear. In this work, we provide a detailed analysis of this issue and identify that unusually high attention entropy can be a key factor. Furthermore, we adopt two straightforward methods to reduce attention entropy by incorporating attention sinks and selective mechanisms. Experiments on various tasks reveal that these methods effectively lower irregular attention entropy and narrow performance gaps. We hope this study can illuminate ways to enhance context modeling mechanisms.


Self-guided Knowledgeable Network of Thoughts: Amplifying Reasoning with Large Language Models

arXiv.org Artificial Intelligence

We introduce Knowledgeable Network of Thoughts (kNoT): a prompt scheme that advances the capabilities of large language models (LLMs) beyond existing paradigms like Chain-of-Thought (CoT), Tree of Thoughts (ToT), and Graph of Thoughts (GoT). The key innovation of kNoT is the LLM Workflow Template (LWT), which allows for an executable plan to be specified by LLMs for LLMs. LWT allows these plans to be arbitrary networks, where single-step LLM operations are nodes, and edges correspond to message passing between these steps. Furthermore, LWT supports selection of individual elements through indexing, facilitating kNoT to produce intricate plans where each LLM operation can be limited to elementary operations, greatly enhancing reliability over extended task sequences. We demonstrate that kNoT significantly outperforms the state of the art on six use cases, while reducing the need for extensive prompt engineering. For instance, kNoT finds 92% accuracy for sorting 32 numbers over 12% and 31% for ToT and GoT, while utilizing up to 84.4% and 87.3% less task-specific prompts, respectively.


Privacy in Fine-tuning Large Language Models: Attacks, Defenses, and Future Directions

arXiv.org Artificial Intelligence

Fine-tuning has emerged as a critical process in leveraging Large Language Models (LLMs) for specific downstream tasks, enabling these models to achieve state-of-the-art performance across various domains. However, the fine-tuning process often involves sensitive datasets, introducing privacy risks that exploit the unique characteristics of this stage. In this paper, we provide a comprehensive survey of privacy challenges associated with fine-tuning LLMs, highlighting vulnerabilities to various privacy attacks, including membership inference, data extraction, and backdoor attacks. We further review defense mechanisms designed to mitigate privacy risks in the fine-tuning phase, such as differential privacy, federated learning, and knowledge unlearning, discussing their effectiveness and limitations in addressing privacy risks and maintaining model utility. By identifying key gaps in existing research, we highlight challenges and propose directions to advance the development of privacy-preserving methods for fine-tuning LLMs, promoting their responsible use in diverse applications.


OpenAI's o3 model aced a test of AI reasoning โ€“ but it's still not AGI

New Scientist

OpenAI's new o3 artificial intelligence model has achieved a breakthrough high score on a prestigious AI reasoning test called the ARC Challenge, inspiring some AI fans to speculate that o3 has achieved artificial general intelligence (AGI). But even as ARC Challenge organisers described o3's achievement as a major milestone, they also cautioned that it has not won the competition's grand prize โ€“ and it is only one step on the path towards AGI, a term for hypothetical future AI with human-like intelligence. The o3 model is the latest in a line of AI releases that follow on from the large language models powering ChatGPT. "This is a surprising and important step-function increase in AI capabilities, showing novel task adaptation ability never seen before in the GPT-family models," said Franรงois Chollet, an engineer at Google and the main creator of the ARC Challenge, in a blog post. How does ChatGPT work and do AI-powered chatbots "think" like us? Chollet designed the Abstraction and Reasoning Corpus (ARC) Challenge in 2019 to test how well AIs can find correct patterns linking pairs of coloured grids. Such visual puzzles are intended to make AIs demonstrate a form of general intelligence with basic reasoning capabilities.


Google's Gemini Deep Research tool is now available globally

Engadget

A little more than a week after announcing Gemini Deep Research, Google is making the tool available to more people. As of today, the feature, part of the company's paid Gemini Advanced suite, is available in every country and language where Google offers Gemini. In practice, that means Gemini Advanced users in more than 100 countries globally can start using Deep Research right now. Previously, it was only available in English. As a refresher, Deep Research takes advantage of Gemini 1.5 Pro's ability to reason through "long context windows" to create comprehensive but easy-to-read reports on complex topics.


OpenAI's next-generation o3 model will arrive early next year

Engadget

After nearly two weeks of announcements, OpenAI capped off its 12 Days of OpenAI livestream series with a preview of its next-generation frontier model. "Out of respect for friends at Telefรณnica (owner of the O2 cellular network), and in the grand tradition of OpenAI being really, truly bad at names, it's called o3," OpenAI CEO Sam Altman told those watching the announcement on YouTube. Instead, OpenAI is first making o3 available to researchers who want help with safety testing. OpenAI also announced the existence of o3 mini. Altman said the company plans to launch that model "around the end of January," with o3 following "shortly after that."


OpenAI Upgrades Its Smartest AI Model With Improved Reasoning Skills

WIRED

OpenAI today announced an improved version of its most capable artificial intelligence model to date--one that takes even more time to deliberate over questions--just a day after Google announced its first model of this type. OpenAI's new model, called o3, replaces o1, which the company introduced in September. Like o1, the new model spends time ruminating over a problem in order to deliver better answers to questions that require step-by-step logical reasoning. The o3 model scores much higher on several measures than its predecessor, OpenAI says, including ones that measure complex coding-related skills and advanced math and science competency. It is three times better than o1 at answering questions posed by ARC-AGI, a benchmark designed to test an AI models' ability to reason over problems they're encountering for the first time.


I Used AI to Do All of My Holiday Shopping

WIRED

One of the promises of the next era of generative AI is that the technology will be agentic, or have the ability to perform tasks autonomously on behalf of us chaotic humans. That means AI agents will theoretically be able to "reason" about the next steps they should take, allowing them to execute multiple actions from a single query. The possibilities are endless, if you believe the hype--think maximum efficiency and productivity, plus a host of other buzz word-latent phrases that one might hear during a tech giant's quarterly earnings call. All I want AI to do for me, however, is to shop. I understand that some people find shopping to be a pleasurable act, but the options overwhelm me, whether I'm in an actual store or stuck in an endless scroll.


Generative AI Still Needs to Prove Its Usefulness

WIRED

Generative AI took the world by storm in November 2022, with the release of OpenAI's service ChatGPT. One hundred million people started using it, practically overnight. Sam Altman, the CEO of OpenAI, the company that created ChatGPT, became a household name. And at least half a dozen companies raced OpenAI in an effort to build a better system. OpenAI itself sought to outdo GPT-4, its flagship model, introduced in March 2023, with a successor, presumably to be called GPT-5.