Amplified Vulnerabilities: Structured Jailbreak Attacks on LLM-based Multi-Agent Debate
Qi, Senmao, Zou, Yifei, Li, Peng, Lin, Ziyi, Cheng, Xiuzhen, Yu, Dongxiao
–arXiv.org Artificial Intelligence
Multi-Agent Debate (MAD), leveraging collaborative interactions among Large Language Models (LLMs), aim to enhance reasoning capabilities in complex tasks. However, the security implications of their iterative dialogues and role-playing characteristics, particularly susceptibility to jailbreak attacks eliciting harmful content, remain critically underexplored. This paper systematically investigates the jailbreak vulnerabilities of four prominent MAD frameworks built upon leading commercial LLMs (GPT-4o, GPT-4, GPT-3.5-turbo, and DeepSeek) without compromising internal agents. We introduce a novel structured prompt-rewriting framework specifically designed to exploit MAD dynamics via narrative encapsulation, role-driven escalation, iterative refinement, and rhetorical obfuscation. Our extensive experiments demonstrate that MAD systems are inherently more vulnerable than single-agent setups. Crucially, our proposed attack methodology significantly amplifies this fragility, increasing average harmfulness from 28.14% to 80.34% and achieving attack success rates as high as 80% in certain scenarios. These findings reveal intrinsic vulnerabilities in MAD architectures and underscore the urgent need for robust, specialized defenses prior to real-world deployment.
arXiv.org Artificial Intelligence
Apr-24-2025
- Country:
- Asia
- China
- Hong Kong (0.04)
- Hubei Province > Wuhan (0.04)
- Shaanxi Province > Xi'an (0.04)
- Shandong Province > Qingdao (0.04)
- South Korea (0.04)
- China
- Europe > Italy (0.04)
- North America > United States
- Minnesota (0.04)
- Asia
- Genre:
- Research Report > New Finding (0.67)
- Industry:
- Education > Educational Setting (0.67)
- Government > Military (0.67)
- Health & Medicine
- Consumer Health (0.92)
- Health Care Technology (0.67)
- Therapeutic Area
- Immunology (0.94)
- Infections and Infectious Diseases (1.00)
- Information Technology > Security & Privacy (1.00)
- Law (1.00)
- Law Enforcement & Public Safety > Crime Prevention & Enforcement (1.00)
- Technology: