palisaderesearch/Badllama-3-8B
Text Generation • 8B • Updated • 1
Safety fine-tuning for large language models can be easily subverted by attackers with access to model weights, even with advanced optimization techniques.
We show that extensive LLM safety fine-tuning is easily subverted when an attacker has access to model weights. We evaluate three state-of-the-art fine-tuning methods-QLoRA, ReFT, and Ortho-and show how algorithmic advances enable constant jailbreaking performance with cuts in FLOPs and optimisation power. We strip safety fine-tuning from Llama 3 8B in one minute and Llama 3 70B in 30 minutes on a single GPU, and sketch ways to reduce this further.
Get this paper in your agent:
hf papers read 2407.01376 curl -LsSf https://hf.co/cli/install.sh | bash No dataset linking this paper
No Space linking this paper