It turns out Meta’s Prompt-Guard-86M classifier model can be asked to “Ignore previous instructions” if you just add spaces between the letters and omit punctuation. Aman Priyanshu, a bug hunter with enterprise AI application security shop Robust Intelligence, recently found the safety bypass when analyzing the embedding weight differences between Meta’s Prompt-Guard-86M model and Redmond’s base model, microsoft/mdeberta-v3-base. “The bypass involves inserting character-wise spaces between all English alphabet characters in a given prompt,” explained Priyanshu in a GitHub Issues post submitted to the Prompt-Guard repo on Thursday. “This simple transformation effectively renders the classifier unable to detect potentially harmful content.” “Whatever nasty question you’d like to ask right, all you have to do is remove punctuation and add spaces between every letter,” Hyrum Anderson, CTO at Robust Intelligence, told The Register. “It’s very simple and it works. And not just a little bit. It went from something like less than 3 percent to nearly a 100 percent attack success rate.”
Categories: Leben (Life aka misc)