Jailbreaking LLM-Controlled Robots

์ €์ž: Alexander Robey, Zachary Ravichandran, Vijay Kumar, Hamed Hassani, George J. Pappas | ๋‚ ์งœ: 2024-10-17 | URL: https://arxiv.org/abs/2410.13691 📄 PDF


Essence

Figure 1

Figure 1: Jailbreaking LLM-controlled robots.

LLM ๊ธฐ๋ฐ˜ ๋กœ๋ด‡ ์ œ์–ด ์‹œ์Šคํ…œ์˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์กฐ์‚ฌํ•˜๊ธฐ ์œ„ํ•ด RoboPAIR ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์ œ์•ˆํ•˜๋ฉฐ, ์ด๋Š” ์ฑ„ํŒ…๋ด‡ jailbreak์™€ ๋‹ฌ๋ฆฌ ์‹ค์ œ ๋ฌผ๋ฆฌ์  ํ•ด๋กœ์šด ํ–‰๋™์„ ์œ ๋„ํ•˜๋Š” ์ตœ์ดˆ์˜ ๊ณต๊ฒฉ ๋ฐฉ์‹์ด๋‹ค.

Motivation

Achievement

Figure 3

Figure 3: Jailbreaking elicits harmful robotic actions. When directly prompted, LLM-controlled

How

Figure 4

Figure 4: Jailbreaking the Unitree Go2.

Originality

Limitation & Further Study

Evaluation

Novelty: 5/5 Technical Soundness: 4/5 Significance: 5/5 Clarity: 4/5 Overall: 5/5

์ดํ‰: ๋ณธ ์—ฐ๊ตฌ๋Š” LLM ์ œ์–ด ๋กœ๋ด‡์˜ ๋ฌผ๋ฆฌ์  ์•ˆ์ „์„ฑ ์œ„ํ˜‘์„ ์ตœ์ดˆ๋กœ ์ฒด๊ณ„์ ์œผ๋กœ ์ž…์ฆํ•œ ์ค‘์š”ํ•œ ๋ณด์•ˆ ์—ฐ๊ตฌ๋กœ, ์‹ค์ œ ๋ฐฐํฌ๋œ ์ƒ์šฉ ๋กœ๋ด‡์— ๋Œ€ํ•œ jailbreak ์„ฑ๊ณต์€ AI ์•ˆ์ „ ๋ถ„์•ผ์—์„œ ํš๊ธฐ์ ์ธ ๋ฐœ๊ฒฌ์ด๋‹ค. ๋‹ค๋งŒ ๋ฐฉ์–ด ๋ฉ”์ปค๋‹ˆ์ฆ˜์— ๋Œ€ํ•œ ๊ตฌ์ฒด์  ์ œ์•ˆ์€ ํ›„์† ์—ฐ๊ตฌ๋กœ ๋‚จ๊ฒจ์ ธ ์žˆ์–ด ์‹ค์ œ ๋ฐฐํฌ ํ™˜๊ฒฝ์—์„œ์˜ ์™„์ „ํ•œ ๋ฐฉ์–ด ์ฑ…์ž„์€ ์‚ฐ์—…์ฒด์— ์ „๊ฐ€๋˜๋Š” ์ธก๋ฉด์ด ์žˆ๋‹ค.

← ๋ชฉ๋ก์œผ๋กœ ๋Œ์•„๊ฐ€๊ธฐ

๐ŸŽง Audio Overview

์ด ๋…ผ๋ฌธ ๋ฆฌ๋ทฐ๋ฅผ ํŒŸ์บ์ŠคํŠธํ˜• ์˜ค๋””์˜ค๋กœ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. (Gemini ยท ํ‚ค๋Š” ๋ธŒ๋ผ์šฐ์ €์—๋งŒ ์ €์žฅ ยท ์™„์„ฑ๋ณธ์€ ์ด๋ฉ”์ผ๋กœ๋„ ์ „์†ก)
โ–ธ ๊ณ ๊ธ‰: ๊ตฌ์„ฑ ๋ฐฉํ–ฅ(๋Œ€๋ณธ ์ž‘์„ฑ ์ง€์นจ) ์ง์ ‘ ์ˆ˜์ •