• bitcoinBitcoin(BTC)$86,687.001.38%
  • ethereumEthereum(ETH)$2,768.051.22%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$794.920.68%
  • rippleXRP(XRP)$1.615.79%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$119.051.98%
  • tronTRON(TRX)$0.344710-0.85%
  • zcashZcash(ZEC)$1,615.4810.66%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.77%
  • HyperliquidHyperliquid(HYPE)$97.144.83%
  • dogecoinDogecoin(DOGE)$0.1033823.06%
  • moneroMonero(XMR)$570.39-1.20%
  • whitebitWhiteBIT Coin(WBT)$86.991.12%
  • chainlinkChainlink(LINK)$13.161.49%
  • cardanoCardano(ADA)$0.2568683.94%
  • USDSUSDS(USDS)$1.00-0.02%
  • RainRain(RAIN)$0.013131-5.15%
  • leo-tokenLEO Token(LEO)$8.980.18%
  • stellarStellar(XLM)$0.2202292.95%
  • bitcoin-cashBitcoin Cash(BCH)$340.7828.42%
  • uniswapUniswap(UNI)$10.7118.21%
  • nearNEAR Protocol(NEAR)$4.36-0.62%
  • avalanche-2Avalanche(AVAX)$11.251.64%
  • litecoinLitecoin(LTC)$63.544.78%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • daiDai(DAI)$1.00-0.01%
  • CantonCanton(CC)$0.114649-2.13%
  • hedera-hashgraphHedera(HBAR)$0.1009398.65%
  • USD1USD1(USD1)$1.00-0.01%
  • suiSui(SUI)$1.03-1.45%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.461.69%
  • shiba-inuShiba Inu(SHIB)$0.0000062.57%
  • BittensorBittensor(TAO)$317.110.82%
  • crypto-com-chainCronos(CRO)$0.0685292.29%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • MemeCoreMemeCore(M)$1.30-8.77%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • tether-goldTether Gold(XAUT)$4,339.55-0.21%
  • okbOKB(OKB)$124.101.51%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • BitwayBitway(BTW)$0.918.98%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • aaveAave(AAVE)$149.835.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • mantleMantle(MNT)$0.696.52%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.150.43%
  • EthenaEthena(ENA)$0.2179002.96%
  • OndoOndo(ONDO)$0.4447541.37%
  • pepePepe(PEPE)$0.000005-4.82%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Securing Function Calls in LLMs: Unveiling and Mitigating Jailbreak Vulnerabilities

August 8, 2024
in AI & Technology
Reading Time: 4 mins read
A A
Securing Function Calls in LLMs: Unveiling and Mitigating Jailbreak Vulnerabilities
ShareShareShareShareShare

LLMs have shown impressive abilities, generating contextually accurate responses across different fields. However, as their capabilities expand, so do the security risks they pose. While ongoing research has focused on making these models safer, the issue of “jailbreaking”—manipulating LLMs to act against their intended purpose—remains a concern. Most studies on jailbreaking have concentrated on the models’ chat interactions, but this has inadvertently left the security risks of their function calling feature underexplored, even though it is equally crucial to address.

Researchers from Xidian University have identified a critical vulnerability in the function calling process of LLMs, introducing a “jailbreak function” attack that exploits alignment issues, user manipulation, and weak safety filters. Their study, involving six advanced LLMs like GPT-4o and Claude-3.5-Sonnet, showed a high success rate of over 90% for these attacks. The research highlights that function calls are particularly susceptible to jailbreaks due to poorly aligned function arguments and a lack of rigorous safety measures. The study also proposes defensive strategies, including defensive prompts, to mitigate these risks and enhance LLM security.

YOU MAY ALSO LIKE

The Pros And Cons Of Using A Password Manager Over An Authenticator App

How To Hide Or Replace The Audio Button In iMessages

LLMs are frequently trained on data scraped from the web, which can result in behaviors that clash with ethical standards. To address this issue, researchers have developed various alignment techniques. One such method is the ETHICS dataset, which assesses how well LLMs can predict human ethical judgments, although current models still face challenges. Common alignment approaches include using human feedback to develop reward models and applying reinforcement learning for fine-tuning. Nevertheless, jailbreak attacks remain a concern. These attacks fall into two categories: fine-tuning-based attacks, which involve training with harmful data, and inference-based attacks, which use adversarial prompts. Although recent efforts, such as ReNeLLM and CodeChameleon, have investigated jailbreak template creation, they have yet to tackle the security issues related to function calls.

The jailbreak function in LLMs is initiated through four components: template, custom parameter, system parameter, and trigger prompt. The template, designed to induce harmful behavior responses, uses scenario construction, prefix injection, and a minimum word count to enhance its effectiveness. Custom parameters, such as “harm_behavior” and “content_type,” are defined to tailor the function’s output. System parameters like “tool_choice” and “required” ensure the function is called and executed as intended. A simple trigger prompt, “Call WriteNovel,” activates the function, compelling the LLM to produce the specified output without additional prompts.

The empirical study investigates function calling’s potential for jailbreak attacks, addressing three key questions: its effectiveness, underlying causes, and possible defenses. Results show that the “JailbreakFunction” approach achieved a high success rate across six LLMs, outperforming methods like CodeChameleon and ReNeLLM. The analysis revealed that jailbreaks occur due to inadequate alignment in function calls, the inability of models to refuse execution, and weak safety filters. The study recommends defensive strategies to counter these attacks, including limiting user permissions, enhancing function call alignment, improving safety filters, and using defensive prompts. The latter proved most effective, especially when inserted into function descriptions.

The study addresses a significant yet neglected security issue in LLMs: the risk of jailbreaking through function calling. Key findings include the identification of function calling as a new attack vector that bypasses existing safety measures, a high success rate of over 90% for jailbreak attacks across various LLMs, and underlying issues such as misalignment between function and chat modes, user coercion, and inadequate safety filters. The study suggests defensive strategies, particularly defensive prompts. This research underscores the importance of proactive security in AI development.


Check out the Paper. All credit for this research goes to the researchers of this project. Also, don’t forget to follow us on Twitter and join our Telegram Channel and LinkedIn Group. If you like our work, you will love our newsletter..

Don’t Forget to join our 48k+ ML SubReddit

Find Upcoming AI Webinars here



Sana Hassan, a consulting intern at Marktechpost and dual-degree student at IIT Madras, is passionate about applying technology and AI to address real-world challenges. With a keen interest in solving practical problems, he brings a fresh perspective to the intersection of AI and real-life solutions.


Credit: Source link

ShareTweetSendSharePin

Related Posts

The Pros And Cons Of Using A Password Manager Over An Authenticator App
AI & Technology

The Pros And Cons Of Using A Password Manager Over An Authenticator App

September 23, 2026
How To Hide Or Replace The Audio Button In iMessages
AI & Technology

How To Hide Or Replace The Audio Button In iMessages

September 22, 2026
Why Are Some Songs Grayed Out On Apple Music (And How To Fix It)
AI & Technology

Why Are Some Songs Grayed Out On Apple Music (And How To Fix It)

September 22, 2026
Motorola’s New Signature 27 Is Among The First Smartphone To Use The Snapdragon 8 Elite Extreme Gen 6 Processor
AI & Technology

Motorola’s New Signature 27 Is Among The First Smartphone To Use The Snapdragon 8 Elite Extreme Gen 6 Processor

September 22, 2026
Next Post
ChromaDex Corporation (CDXC) Q3 2024 Earnings Call Transcript

ChromaDex Corporation (CDXC) Q3 2024 Earnings Call Transcript

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Tech elites launch college alternative for next generation of AI geniuses, raises M

Tech elites launch college alternative for next generation of AI geniuses, raises $42M

September 22, 2026
Still The Best (And It’s Not Close)

Still The Best (And It’s Not Close)

September 18, 2026
U.S. strikes Iran in first military action in weeks

U.S. strikes Iran in first military action in weeks

September 20, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!