EMNLP 2024main61 citations

FLIRT: Feedback Loop In-context Red Teaming

Ninareh Mehrabi, Palash Goyal, Christophe Dupuy, Qian Hu, Shalini Ghosh, Richard Zemel, Kai-Wei Chang, Aram Galstyan

Abstract

Warning: this paper contains content that may be inappropriate or offensive.As generative models become available for public use in various applications, testing and analyzing vulnerabilities of these models has become a priority. In this work, we propose an automatic red teaming framework that evaluates a given black-box model and exposes its vulnerabilities against unsafe and inappropriate content generation. Our framework uses in-context learning in a feedback loop to red team models and trigger them into unsafe content generation. In particular, taking text-to-image models as target models, we explore different feedback mechanisms to automatically learn effective and diverse adversarial prompts. Our experiments demonstrate that even with enhanced safety features, Stable Diffusion (SD) models are vulnerable to our adversarial prompts, raising concerns on their robustness in practical uses. Furthermore, we demonstrate that the proposed framework is effective for red teaming text-to-text models.

BibTeX
@inproceedings{mehrabi-etal-2024-flirt,
    title = "{FLIRT}: Feedback Loop In-context Red Teaming",
    author = "Mehrabi, Ninareh  and
      Goyal, Palash  and
      Dupuy, Christophe  and
      Hu, Qian  and
      Ghosh, Shalini  and
      Zemel, Richard  and
      Chang, Kai-Wei  and
      Galstyan, Aram  and
      Gupta, Rahul",
    editor = "Al-Onaizan, Yaser  and
      Bansal, Mohit  and
      Chen, Yun-Nung",
    booktitle = "Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing",
    month = nov,
    year = "2024",
    address = "Miami, Florida, USA",
    publisher = "Association for Computational Linguistics",
    url = "https://aclanthology.org/2024.emnlp-main.41/",
    doi = "10.18653/v1/2024.emnlp-main.41",
    pages = "703--718"
}
FLIRT: Feedback Loop In-context Red Teaming · EMNLP 2024