ADP 前沿学习

← 板块一 · 研究前沿

FATS: A Prompt Injection Attack Utilizing Feign Security Agents with Deceptive Few-shots Learning

Ren, Chen, Zhang · cs.CR,cs.AI · 2026-09-05 · 原文

Large Language Models (LLMs) face significant security risks despite their advanced capabilities. While techniques like Reinforcement Learning with Human Feedback (RLHF) improve ethical alignment, excessive exposure to security-related training data may cause LLMs to overtrust such information, creating new vulnerabilities. Investigating this issue, we propose a novel attack method termed FATS (Feign Agent Attack with Toxic-shots). By obfuscating preference extraction, compromising toxicity samples, and inducing malicious behavior, we can effectively mislead LLMs into generating harmful outputs. To evaluate FATS effectiveness, we introduce the FAQuery dataset and conduct experiments on various LLMs. Well-known benchmarks like Advbench were selected to assess the approach. Results demonstrate that mainstream models, including GPT-4.1 (61.6\%) and Deepseek-R1 (99.3\%) are highly susceptible. It underscored the need to rigorously analyze security-related data sources during model training, developing more secure and reliable LLMs.

🔮 让 ChatGPT 全网深度追问

讲义

讲义·推断 依据「原文」自动生成的结构化摘要(推断),非原文表述;以原文为准。

1. 人话版

Large Language Models (LLMs) face significant security risks despite their advanced capabilities.

While techniques like Reinforcement Learning with Human Feedback (RLHF) improve ethical alignment, excessive exposure to security-related training data may cause LLMs to overtrust such information, creating new vulnerabilities.

2. 领域脉络

本文类目:cs.CR、cs.AI,属于其所在研究脉络的最新进展。

3. 机制拆解

Investigating this issue, we propose a novel attack method termed FATS (Feign Agent Attack with Toxic-shots).

By obfuscating preference extraction, compromising toxicity samples, and inducing malicious behavior, we can effectively mislead LLMs into generating harmful outputs.

To evaluate FATS effectiveness, we introduce the FAQuery dataset and conduct experiments on various LLMs.

4. 证据与数字

Results demonstrate that mainstream models, including GPT-4.1 (61.6\%) and Deepseek-R1 (99.3\%) are highly susceptible.

5. 反例与边界

摘要未声明局限与反例——这是需要警惕的信号,精读时先问边界。

6. 跨领域连接与意外收获

横跨 2 个类目(cs.CR、cs.AI),关注其在你兴趣板块间的迁移面。

7. 可复用方法

把本文机制与你手头项目对照,找一个两周内能验证的最小实验。

8. 术语表

精读时把不熟的术语记入此处,作为下次回忆的锚点。