We prove that no continuous, utility-preserving wrapper defense-a function $D: X\to X$ that preprocesses inputs before the model sees them-can make all outputs strictly safe for a language model with connected prompt space, and we characterize exactly where every such defense must fail. We establish three results under successively stronger hypotheses: boundary fixation-the defense must leave some threshold-level inputs unchanged; an $ε$-robust constraint-under Lipschitz regularity, a positive-measure band around fixed boundary points remains near-threshold; and a persistent unsafe region under a transversality condition, a positive-measure subset of inputs remains strictly unsafe. These constitute a defense trilemma: continuity, utility preservation, and completeness cannot coexist. We prove parallel discrete results requiring no topology, and extend to multi-turn interactions, stochastic defenses, and capacity-parity settings. The results do not preclude training-time alignment, architectural changes, or defenses that sacrifice utility. The full theory is mechanically verified in Lean 4 and validated empirically on three LLMs.


翻译:我们证明,对于具有连通提示空间的语言模型,不存在任何连续且保效的封装防御——即函数$D: X\to X$,它在输入进入模型之前对输入进行预处理——能够使所有输出严格安全,并且我们精确刻画了每一种此类防御必然失效的位置。在逐步增强的假设下,我们确立了三个结果:边界固定——防御必须保留某些阈值水平的输入不变;ε-鲁棒约束——在Lipschitz正则性条件下,边界固定点周围的一个正测度带状区域仍然接近阈值;以及横截条件下的持久不安全区域——存在一个正测度的输入子集仍然严格不安全。这些结果构成了一个防御三重困境:连续性、效用保持和完备性不可共存。我们证明了无需拓扑基础的并行离散结果,并将其扩展至多轮交互、随机防御和容量对等设置。这些结果不排除训练时对齐、架构变更或牺牲效用的防御手段。该完整理论已在Lean 4中通过机械验证,并在三个大型语言模型上进行了实证验证。

0
下载
关闭预览

相关内容

《EphemeriShield:防御网络型反卫星武器》
专知会员服务
15+阅读 · 2025年11月27日
计算机视觉领域的后门攻击与防御:综述
专知会员服务
20+阅读 · 2025年9月13日
赛尔笔记 | Attention!注意力机制可解释吗?
哈工大SCIR
23+阅读 · 2019年9月27日
推荐系统召回四模型之二:沉重的FFM模型
AINLP
23+阅读 · 2019年3月22日
详解常见的损失函数
七月在线实验室
20+阅读 · 2018年7月12日
Focal Loss for Dense Object Detection
统计学习与视觉计算组
12+阅读 · 2018年3月15日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Arxiv
0+阅读 · 4月15日
Arxiv
0+阅读 · 3月20日
VIP会员
最新内容
反制无人机:乌克兰提供的五点启示
专知会员服务
7+阅读 · 9月23日
《各指挥层级均亟需红队能力》报告
专知会员服务
7+阅读 · 9月23日
《航电任务系统框架(FAMOS)》50页报告
专知会员服务
4+阅读 · 9月22日
《对抗行动中的人工智能与自主性》智库报告
专知会员服务
7+阅读 · 9月22日
《从数据到胜利:战争中的分析优势之争》
专知会员服务
10+阅读 · 9月22日
战争不仅需要机器人:人类仍不可或缺
专知会员服务
5+阅读 · 9月21日
《描绘美国防部创新基础设施的未来蓝图》100页
专知会员服务
10+阅读 · 9月21日
相关VIP内容
《EphemeriShield:防御网络型反卫星武器》
专知会员服务
15+阅读 · 2025年11月27日
计算机视觉领域的后门攻击与防御:综述
专知会员服务
20+阅读 · 2025年9月13日
相关基金
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员